Lemonde
  • Lemonde
  • 100% (Exalted)
  • Advanced Member Topic Starter
2 years ago
We have recently had to dcpromo /forceremoval for a couple of DCs

Is this a temporary failure or does it indicate damage or corruption to the ACtive Directory?

Log Name: Directory Service
Source: Microsoft-Windows-ActiveDirectory_DomainService
Date: 16/12/2020 22:32:59
Event ID: 1411
Task Category: DS RPC Client
Level: Error
Keywords: Classic
User: ANONYMOUS LOGON
Computer: 00DC2.Domain.local
Description:
Active Directory Domain Services failed to construct a mutual authentication service principal name (SPN) for the following directory service.

Directory service:
6a23053d-de41-40a1-b53e-d48219f2ac87._msdcs.Domain.local

The call was denied. Communication with this directory service might be affected.

Additional Data
Error value:
8589 The DS cannot derive a service principal name (SPN) with which to mutually authenticate the target server because the corresponding server object in the local DS database has no serverReference attribute.
Event Xml:



1411
0
2
22
0
0x8080000000000000

44610


Directory Service
00DC2.Domain.local



6a23053d-de41-40a1-b53e-d48219f2ac87._msdcs.Domain.local
The DS cannot derive a service principal name (SPN) with which to mutually authenticate the target server because the corresponding server object in the local DS database has no serverReference attribute.
8589


Sponsor

Want to thank us? Use: Patreon or PayPal or Bitcoins: 12G4A52Znm5s35buKDEmKU2p2vQY69Nsyo

All opinions expressed within these pages are sent in by members of the public or by our staff in their spare time, and as such do not represent any opinion held by sircles.net Ltd or their partners.


sirclesadmin
2 years ago
If it ceases after four hours then it is just due to replication of the force removed DC replicating around the domain.