Skip to content

Recent Posts

  • Reset passwords for Active Directory Users
  • Finding Exchange Database hidden mailboxes. ​
  • Setting up ADConnect and PTA (Password auth through) servers agents behind proxy
  • Get Report of Active Directory Locked Accounts and Machine they logged in from
  • Checking and Providing Full and SendAs delegate access on O365 Exchange Online

Most Used Categories

  • Microsoft (82)
    • Microsoft Exchange (39)
      • Exchange 2016 (14)
      • Exchange 2019 (14)
    • Active Directory (25)
  • Office 365 (34)
    • Exchange Online (15)
  • Security (15)
  • Microsoft Azure (15)
  • Powershell (19)
Skip to content

Welcome to Mohammed Hamada's Site

The Troubleshooting Guy

Subscribe
  • Consultation
  • Microsoft
    • DFS
    • KMS
    • Office 365
      • Microsoft ADFS
      • Exchange Online
      • Microsoft Teams
      • Skype for Business
    • Microsoft Azure
      • Microsoft Azure Active Directory Sync
      • Licensing
      • ATP
      • WVD
    • ADMT
  • Virtualization
  • VoIP
    • Lync
    • Asterisk
  • PowerShell Corner
  • Security
    • Auditing
    • Pfsense
  • Contact me
  • Certification and Awards
  • Home
  • Microsoft
  • Active Directory
  • Replication after tombstone life expired

Replication after tombstone life expired

moh10lyNovember 21, 2019January 3, 2020

Replication After Tombstone Life Expired

As I was preparing for Exchange migration from 2010 to 2013 I had two DCs, one of those two DCs was off for about 8 months and has already passed the default tomb stone life so it was not authorized for replication in the forest.

Whenever I try to replicate the server I get the following error

image
image

Active Directory Sites and Services Error

“The following error occurred during the attempt to syncronize naming context CN=Configuration,DC=Domain,DC=Local from Domain Controller AD to Domain Controller AD2; The directory service cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime. This operation will not continue.”

My FSMO roles holder and PDC is the demotesas.local domain so on this DC I will run the following command

W32tm /config /manualpeerlist:time.windows.com,0x1 /syncfromflags:manual /reliable:yes /update

clip_image001

And this

w32time & net start w32time & W32tm /resync /rediscover

clip_image002

On the additional DC

w32tm /config /syncfromflags:domhier /update

w32time & net start w32time & W32tm /resync /rediscover

Force Replication

If the above doesn’t work then I will go ahead and force replication to the tomb stoned DC by using the following command.

repadmin /regkey * +allowDivergent

clip_image003

Now we’ll replicate and see what happens

clip_image004

Problem solved

image

REF:

http://www.techieshelp.com/active-directory-replication-issues-after-timesync-problems/
https://social.technet.microsoft.com/Forums/windowsserver/en-US/893b09d8-636e-4f87-8260-11613a2a4e43/unable-to-replicate-between-2-dcs-error-message-exceeded-the-tombstone-lifetime?forum=winserverDS>

Post navigation

Previous: Prepare Active Directory with powershell
Next: Resetting Usernames and Passwords from text file

Related Posts

Reset passwords for Active Directory Users

December 30, 2022December 31, 2022 moh10ly

Finding Exchange Database hidden mailboxes. ​

December 24, 2022December 27, 2022 moh10ly

Setting up ADConnect and PTA (Password auth through) servers agents behind proxy

December 24, 2022December 24, 2022 moh10ly

24 thoughts on “Replication after tombstone life expired”

  1. Tad Osborn says:
    July 1, 2020 at 2:05 pm

    Thank you for taking the time to post this information. This quickly and easily resolved our replication issues without having to demote a server!

    Reply
    1. moh10ly says:
      July 1, 2020 at 2:09 pm

      Glad it helped you Tad.

      Reply
  2. Andres says:
    July 30, 2020 at 5:40 am

    for two days I had the problem of replication and they did not have a single solution …….. you saved my life, thank you very much

    Reply
    1. moh10ly says:
      July 31, 2020 at 8:54 am

      Glad it worked for you 🙂 I usually have these kind of issues and prefer to troubleshoot than demote or delete.

      Reply
  3. Chris says:
    January 21, 2021 at 8:27 pm

    Thanks so much for the post worked great cheers! 🙂

    Reply
    1. moh10ly says:
      January 21, 2021 at 8:48 pm

      Glad it helped you 🙂 cheers

      Reply
  4. michael ellis says:
    January 29, 2021 at 11:17 pm

    When you force replication using repadmin /regkey * +allowDivergent do you do this on the domain controller that cannot be replicated to or the one you are trying to replicate from?

    Reply
    1. moh10ly says:
      January 30, 2021 at 5:08 pm

      Hi Michael, doesn’t really matter which server because the wildcard will push the replication to all the DCs and will force it on the tombstone DC.

      Please check the construction of the command here
      https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/active-directory-replication-event-id-2042#use-repadmin-to-restart-replication-following-event-id-2042

      Reply
  5. thomas says:
    February 25, 2021 at 12:42 am

    Thank you moh10ly,

    This saves my butt rebuilding.

    Reply
    1. moh10ly says:
      March 12, 2021 at 9:36 pm

      Glad it helped you 🙂

      Reply
  6. Key Hammonds says:
    March 26, 2021 at 1:47 am

    You’re the bomb! Thank you! After days of reading through other sites that seemed to over-complicate everything, your AWESOME article came into my life! 🙂

    Reply
    1. moh10ly says:
      March 26, 2021 at 4:41 pm

      Hi Key, I am very glad this has helped you! If you in anytime had any difficulties please don’t hesitate to contact me directly.
      Regards

      Reply
  7. Raphael Ferreira says:
    May 1, 2021 at 10:30 pm

    VERY useful! Thank you so much! Best, Raphael.

    Reply
    1. moh10ly says:
      May 2, 2021 at 12:43 pm

      You’re very welcome, I am glad it helped

      Reply
  8. ageng says:
    June 4, 2021 at 8:02 am

    dear expert, im very newbie for this. any posibility this step will interupt the other DS? coz my system use for DCS System it should not be interupt the DCS (Digital Control System)

    Reply
  9. Pete M. says:
    July 17, 2021 at 4:37 am

    I can’t thank you enough. That did the trick. Happy that I don’t need to go demoting route. !

    Reply
    1. moh10ly says:
      July 17, 2021 at 12:48 pm

      Glad it helped 🙂 .

      Reply
  10. Luciano Patrao says:
    February 2, 2022 at 6:23 pm

    Thank you this fixed my DCs in my home lab that was powered off for many months.

    Reply
  11. Rob says:
    October 5, 2022 at 1:27 pm

    Super helpful, one of the best documents on the problem, you won’t believe how much time i spent looking for this solution and you managed to help me fix it in like 3 minutes!

    Reply
  12. redzuan says:
    November 22, 2022 at 10:11 am

    Just letting you know you saved my life as well.
    Thank you

    Reply
  13. ACS Mendis says:
    November 23, 2022 at 1:52 pm

    I dont no who you are.. anyway you save my life
    i was struggle with this almost three weeks

    Thank you very very much for sharing your knowledge with us.
    God bless you..

    Reply
  14. Naresh T says:
    February 7, 2023 at 4:32 pm

    Hello,

    Facing DFS replication on additional domain controller after it was turned off for 2 weeks. It has not exceeded tombstone period.

    Tried demoting and promoting ADC but yet we are not seeing shared netlogon sysvol on ADC.

    In event viewer we see messages DFS will not replicate till on ADC stale data is cleared-reason it is not replicated for more than 60days.

    Also tried to install windows freshly and joined to existing domain still it is same problem for DFS replication for netlogon and sysvol shared folders.

    Other replication between both domains is success. Please advise how to fix this issue.

    Reply
  15. Tim says:
    March 28, 2023 at 7:49 am

    Hi Mohammed Hamada,

    Wherever you are in the world, I pray that God will bless you with increase in any aspect of your life.

    You are truly a lifesaver.

    Thank You very much!

    Reply
  16. Les Gray says:
    October 11, 2023 at 1:35 am

    f*ck me!
    thanks dude, just as with the other folks here, you saved me a ton of time with a simple and elegant solution that no-one else seems to have come up with!

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search for something

Recent Posts

  • Reset passwords for Active Directory Users
  • Finding Exchange Database hidden mailboxes. ​
  • Setting up ADConnect and PTA (Password auth through) servers agents behind proxy
  • Get Report of Active Directory Locked Accounts and Machine they logged in from
  • Checking and Providing Full and SendAs delegate access on O365 Exchange Online
  • Retrieving attachments from Exchange mailbox using python
  • 550 relay not permitted distribution group contact
  • Script to delete all DPM 2019 recovery points

Recent Comments

  • B on SoftEther – Fixing connecting to localhost 5555
  • Denise Diaz on Reset passwords for Active Directory Users
  • Les Gray on Replication after tombstone life expired
  • jimmyj on Search and Delete certain Items/Folders from a Mailbox
  • moh10ly on How to Sync Cloud User to On-premises AD ?

Archives

  • December 2022
  • November 2022
  • January 2022
  • December 2021
  • May 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019

Archives

  • December 2022
  • November 2022
  • January 2022
  • December 2021
  • May 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019

Categories

  • Active Directory
  • ADFS
  • ADMT
  • Asterisk
  • ATP
  • Auditing
  • AZURE
  • Cloud
  • Communication
  • CRM Dynamics
  • CrossForest Migration
  • DFS
  • DNS
  • DPM
  • Exchange 2010
  • Exchange 2013
  • Exchange 2016
  • Exchange 2019
  • Exchange Online
  • Google Chat
  • Infrastructure
  • KMS
  • Licensing
  • Linux
  • Lync
  • Mail
  • Microsoft
  • Microsoft AD Group Policy
  • Microsoft ADFS
  • Microsoft Azure
  • Microsoft Azure Active Directory Sync
  • Microsoft Exchange
  • Microsoft Teams
  • Monitoring
  • Networking
  • Office 365
  • Pentest
  • Pfsense
  • PKI
  • Plesk
  • Powershell
  • Python
  • RDS
  • Scripting
  • Security
  • Skype for Business
  • Skype4Business
  • Ubuntu
  • Uncategorized
  • Virtualization
  • VoIP
  • VPN
  • Windows 10
  • Windows Server
  • Windows Server 2019
  • Windows Virtual Desktop
  • WordPress
  • WVD

Meta

  • Register
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
Copyright All Rights Reserved | Theme: BlockWP by Candid Themes.