Export (0) Print
Expand All
Expand Minimize
0 out of 3 rated this helpful - Rate this topic

AD DS: This domain controller must advertise as an LDAP server for the domain in its local site

Published: April 23, 2009

Updated: August 31, 2012

Applies To: Windows Server 2008 R2, Windows Server 2012

This topic is intended to address a specific issue identified by a Best Practices Analyzer scan. You should apply the information in this topic only to computers that have had the Active Directory Domain Services Best Practices Analyzer run against them and are experiencing the issue addressed by this topic. For more information about best practices and scans, see Best Practices Analyzer (http://go.microsoft.com/fwlink/?LinkId=122786).

 

Operating System

Windows Server 2008 R2

Windows Server 2012

Product/Feature

Active Directory Domain Services (AD DS)

Severity

Error

Category

Configuration

The "LdapAtSite" DNS service (SRV) resource record that advertises this domain controller as an available LDAP server for the domain in its local site is not registered. All writeable domain controllers and read-only domain controllers (RODCs) must register this record.

This issue can be caused by incorrect Netlogon settings in Group Policy or in the registry. It can also be caused by a failure in the Domain Name System (DNS) registration process. So that other member servers and domain controllers in the same site can locate this domain controller as a writeable Lightweight Directory Access Protocol (LDAP) server in the domain in a particular site, the correct set of DNS service (SRV) resource records must be registered by domain controller Locator (DC Locator).

Other member computers and domain controllers in the domain or forest will not be able to locate this domain controller in the local site as an LDAP server. This domain controller will not be able to provide a full suite of services.
Ensure that "LdapAtSite" is not configured in the “DnsAvoidRegisteredRecords” list, either through Group Policy or through the registry. Restart the Netlogon service. Verify that the DNS service (SRV) resource record "_ldap._tcp.<<Site name of the local site>>_sites.<<DnsDomainName of the local DC>>", pointing to the local domain controller "<<FQDN of local DC>>", is registered in DNS.

To resolve this issue, complete the following tasks:

  • Locate the DNS record: Determine whether the "_ldap._tcp.<<Site name of the local site>>_sites.<<DnsDomainName of the local DC>>" DNS service (SRV) resource record that points to the fully qualified domain name (FQDN) of the local domain controller "<<FQDN of local DC>>" is not registered in DNS.

  • Verify Group Policy Settings: If the "_ldap._tcp.<<Site name of the local site>>_sites.<<DnsDomainName of the local DC>>" DNS service (SRV) resource record is not registered in DNS, verify that LdapAtSite is not included in the list of mnemonics that are specified for the Group Policy setting DC Locator DNS records not registered by the DCs.

    noteNote
    The mnemonics that are specified for the DC Locator DNS records not registered by the DCs Group Policy setting correspond to the DNS records that are not to be registered by this domain controller.

  • Verify registry settings: If the "_ldap._tcp.<<Site name of the local site>>_sites.<<DnsDomainName of the local DC>>" DNS service (SRV) resource record is not registered in DNS, verify that LdapAtSite is not included in the list of mnemonics that are specified for the multivalued registry key DnsAvoidRegisterRecords.

    noteNote
    The mnemonics that are specified for the DnsAvoidRegisterRecords registry key correspond to the DNS records that are not to be registered by this domain controller.

  • Restart the Netlogon service, and verify that the "_ldap._tcp.<<Site name of the local site>>_sites.<<DnsDomainName of the local DC>>" DNS service (SRV) resource record has been registered in DNS.

noteNote
You can use the Dcdiag tool to further investigate and resolve a continuing failure to register this record. For more information, see DCDiag and NetDiag in Windows 2000 Facilitate Domain Join and DC Creation (http://go.microsoft.com/fwlink/?LinkID=136425) and Dcdiag Overview (http://go.microsoft.com/fwlink/?LinkID=130605).

Membership in Domain Admins, or equivalent, is the minimum required to complete these procedures. Review details about using the appropriate accounts and group memberships at Local and Domain Default Groups (http://go.microsoft.com/fwlink/?LinkId=83477).

  1. Open the DNS Manager snap-in. To open DNS Manager, click Start, click Administrative Tools, and then click DNS.

  2. In the console tree, expand the applicable forward lookup zone, expand the <<DnsDomainName of the local DC>> node, expand _sites, expand <<Site name of the local site>>, and then click _tcp.

  3. In the details pane, locate the _ldap record.

  1. Open the Group Policy Management snap-in. To open Group Policy Management, click Start, click Administrative Tools, and then click Group Policy Management.

  2. To determine if the Group Policy setting DC Locator DNS records not registered by the DCs is set by one or more Group Policy objects (GPOs), in Group Policy Management, right-click Group Policy Results, and then click Group Policy Results Wizard. Run the Group Policy Results Wizard for this domain controller.

    If the Group Policy setting DC Locator DNS records not registered by the DCs is set, it appears in the generated Group Policy results in the Group Policy Management snap-in.

  3. In the Group Policy Management console tree, expand Group Policy Results, and then select the generated results report.

  4. To view the list of mnemonics that correspond to the DNS records that should not be registered by this domain controller, in the details pane, expand Administrative Templates, and then expand System/ Net Logon/ DC Locator DNS Records.

Membership in System Admins, or equivalent, is the minimum required to complete this procedure. Review details about using the appropriate accounts and group memberships at Local and Domain Default Groups (http://go.microsoft.com/fwlink/?LinkId=83477).

  1. Open the Registry Editor snap-in. To open Registry Editor, click Start, click Run, and then type regedit.

  2. Navigate to HKEY_LOCAL_MACHINE\ SYSTEM\CurrentControlSet\Services\Netlogon\Parameters.

  3. To view or edit the list of mnemonics that correspond to the DNS records that should not be registered by this domain controller, double-click the DnsAvoidRegisterRecords multivalued registry key.

For more information, see DNS Support for Active Directory Tools and Settings (http://go.microsoft.com/fwlink/?LinkID=136428).

Did you find this helpful?
(1500 characters remaining)
Thank you for your feedback

Community Additions

ADD
Show:
© 2014 Microsoft. All rights reserved.