Howto: Delegate “replicate now” without “Replication Access was denied”
Howto: Delegate “replicate now” without “Replication Access was denied”
The following error occurred during the attempt to synchronize naminc context domain.tld from Domain Controller DC1 to Domain Controller DC2: Replication Access was denied. This Operation will not continue.
So we figured out which rights are necessary to use that function on a delegated group:
- Open Adsiedit
- Connect to the following five partitions
DC=ForestDnsZones,DC=domain,DC=tld
DC=DomainDnsZones,DC=domain,DC=tld
CN=Schema,CN=Configuration,DC=domain,DC=tld
CN=Configuration,DC=domain,DC=tld
DC=domain,DC=tld
(We used an account that was Domain Admin, Enterprise Admin and Schema Admin) - At each of this partitions do a right klick at the root and open Properties
- At security -> advanced klick add, type in the group that should get the delegated right and klick OK
- Ensure that “Apply to” is set to “This object and all descendant objects”
- Search for “Replication synchronization” at the list below and
- Klick OK twice
You are done if you did this in five three mentioned partitions!