Creating / Editing GPO ... not from the expected DC ?!?

D

David J.

Hi, this is my first post :)

I'm having weird issue with my 2000 AD domain.

here is the topo :

domain adroot with two DCs.
dcroot1 in site1
dcroot2 in site4 (gc .. global catalog server)

domain dom.intra with four DCs
dc1 in site1
dc2 in site2 (gc)
dc3 in site3 (gc)
dc4 in site4 (gc)

I just add dc2 in site4 and everything is fine except for one thing
(that I am aware off :)) )

Here's my problem :

When I connect to the AD Users and Computers Snap-in (I've
double-check that I am really connect to the good DC) to create or
edit a Group Policy (gpo) ... It does not create / edit the GPO
locally in its own SYSVOL folder. Instead it does create it in the
SYSVOL folder of the dc1 in site1. Then it replicates it to other
SYSVOL folder (including the one at dc4).

I've tested that situation with my other DCs with no problem at all.
GPO creating locally then replicating to others, not creating remotely
then replicating.

The weirder thing is that if I connect to remotely to this dc4 with Ad
Users and computers from antoher dc, and create GPO, it still creates
it in the SYSVOL folder of the dc1............

I'm not sure if I am clear. If you need any more informations, please
advice.

I want to thank you all in advance since this is driving me nuts...

David J.
 
D

Derek Melber [MVP]

David,

That is very perceptive and some great work tracking that down! This is by
design. DC1 is also running a FSMO called the PDC Emulator. The PDC emulator
is the DC that is updated when any GPO is modified, then all changes are
replicated from this DC. You can change this behavior in a GPO, but I would
not. I like knowing where all GPO changes start from, it makes it easy to
troubleshoot.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top