They must have setup each workstation with a static IP manually, and put the DNS info in manually too. Would it be replicating if he only has 1 server? it should be an official fallacy. The domain admin password was changed recently so i THINK it has something to do with this, if that's the cause then i can't figure out what app or service on have a peek here

Complete Step by Step Guideline to Remove an Orphaned Domain controller (including seizing FSMOs, running a metadata cleanup, and more) http://msmvps.com/blogs/acefekay/archive/2010/10/05/complete-step-by-step-to-remove-an-orphaned-domain-controller.aspx Hope this helpsBest Regards, Sandesh Dubey. The Primary DNS of a client computer should always be the IP of a Domain Controller.

The computer then started normally. We were not using certificates on the domain, so we exported the certificate for the invalid CA and all errors disappeared. As for the 40960 error: Is "DC1" as you originally posted as holding all FSMO roles, the 2008 DC or the 2008 R2 DC?Were the new DCs built from scratch

We were not using certificates on the domain, so we exported the certificate for the invalid CA and all errors disappeared. This seems to have solved the console properties display issue, but I have 2 clients that have been unable to log onto the domain and rejoin.

The fix was changing the DNS settings to point to a Win2k DNS which was tied into Active Directory. I have not received any more errors since doing this.

SIDs were re-created upon deployment. Event Id 40960 Lsasrv Windows 7 The code was 0xc0000064 (Error code 0xC0000064) = "User does not exist".

In the SBS 2008 console, the client PCs are shown without their properties listed (OS, RAM, etc) and there's a message "No DNS entry for this computer". Event Id 40960 Lsa Hope this helpsBest Regards, Sandesh Dubey. The Security System Detected An Authentication Error For The Server Cifs/servername Boss says it started immediately after the installation.

This was happening on a server that used to be a domain controller for an old domain but had AD removed and then reinstated as a domain controller for a new domain. Download PsExec.exe from http://technet.microsoft.com/en-us/sysinternals/bb897553.aspx and copy it to C:\Windows\System32. Each DC / DNS server points to its private IP address as primary DNS server and other remote/local DNS servers as secondary in TCP/IP properties. Event Id 40960 Buffer Too Small

In our case users who would vpn in using CheckPoint Secureclient were having issues with domain authentication not working. Contact your ISP and get valid DNS IPs from them and add it in to the forwarders, Do not set public DNS server in TCP/IP setting of DC. It turned out that there was a disconnected terminal services session still open on the server for an account that had been deleted.

Let the parent and child domain controllers replicate the changes. See ME193888 for details on how to do this".

Another symptom was that "net time /set" was generating "Access denied" errors.

However, Kerberos authentication with SBS 2003 domain was impossible. Event ID: 40960 Source: LSASRV http://www.eventid.net/display.asp?eventid=40960&eventno=8508&source=LSASRV&phase=1 Hope this helpsBest Regards, Sandesh Dubey. Restart the computer. Note Steps 1 and 2 reset both directions of the trust.

They were being logged in with cached credentials. The problem was that the Regional Settings for this one server were GMT Monrovia and the rest of the servers were GMT UK.Changing the setting resolved the issues. If you are able to limit the lockouts with reducing the GPOs, then add them to the OU one at time to find the one that is part of the cause. On a clean Windows 2003 installation, promoted to a DC, with IIS installed, I needed to make W32Time (Windows Time Service), NtFrs (File Replication Service), and SMTPSVC (Simple Mail Transfer Protocol

To register this URL, please use the following steps, Note: We recommend that first backup your registry settings.