2012 R2 DC crashes when user account is renamed using RSAT Tools on Windows 7


hello everyone,

we have forest , domain both running in 2003 native mode. have mixture of domain controllers running 2003 and 2008 r2 , deployed 2 new domain controllers running 2012 r2. 2012 r2s configured global catalogs not hold additional fsmo roles.

unfortunately have strange issue 2 new 2012 r2 dcs:

we have installed domain management tools on the 2012 r2 domain controllers. when managing our domain using locally installed tools on dcs ok. dsa.msc shows version 6.3.9600.16384. have number of admin workstations running windows 7 enterprise 64 bit service pack 1. have rsat tools windows 7 sp1 (windows6.1-kb958830-x64-refreshpkg.msu) installed on these machines. dsa.msc shows version 6.1.7601.17514. whenever try rename user account win7 computers, 2012 r2 dc targeted shows message saying reboot within 60 seconds - , that. on client see message saying

"windows cannot complete rename operation on <name> because: server not operational. name related properties on object might out of sync."

the server logs two errors in application log:

1. event id 1000, application error:

faulting application name: lsass.exe, version: 6.3.9600.16384, time stamp: 0x5215e25f
faulting module name: ntdsai.dll, version: 6.3.9600.16421, time stamp: 0x524fcaed
exception code: 0xc0000005
fault offset: 0x000000000019e45d
faulting process id: 0x214
faulting application start time: 0x01cefa6743edbeec
faulting application path: c:\windows\system32\lsass.exe
faulting module path: c:\windows\system32\ntdsai.dll
report id: d4cd7581-665c-11e3-80d7-005056984a2b
faulting package full name:
faulting package-relative application id:

2. event id 1015, source wininit:

a critical system process, c:\windows\system32\lsass.exe, failed status code c0000005.  machine must restarted.

these issues not occur if target admin workstations use 1 of our older 2008 r2 dcs. have idea? appreciated!

regards

harry

i found thread, seemingly unrelated, similar issue
http://social.technet.microsoft.com/forums/en-us/9f3a1f57-38bd-480c-aa17-719a635f4086/changing-zone-replication-lsassexe-crashing-and-dc-rebooting?forum=winserver8gen

they suggest turning off auditing, tried that, , no longer crashes.  i'm in process of getting microsoft ticket opened, thought i'd share.

i created ou under dc ou, , put 2012r2 dcs in ou, ou has 1 gpo turn off auditing (i'll go , fine tune little when system being used less) forced gp update, , tried renaming again.

steve




Windows Server  >  Directory Services



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL