Forum Discussion
Gly
Sep 07, 2020Brass Contributor
Warning - validation error
Hello, For a while now I have been getting a warning every time I open a distribution group or mail-enabled security group in the on-prem admin center. "The object removed has been corrupted...
Gly
Sep 07, 2020Brass Contributor
ChristianBergstrom
I checked the Ad permissions for the domain now, and it's not yielding any errors either.
VickVega
Sep 07, 2020Brass Contributor
Have you considered re-running:
setup.exe /preparead
https://docs.microsoft.com/en-us/exchange/plan-and-deploy/prepare-ad-and-domains?view=exchserver-2016
- MarcoLFranciscoJan 20, 2023
Microsoft
Do you use LAPS by any chance?
Try the following:
1- Create a New OU in AD
2- Disable inheritance for that OU
3- Open the Properties of the OU, Security, and remove all permissions except for Exchange Permissions and System; Apply exit and refresh AD view;
4- Go again to the OU Properties, to Security, then Advanced button to doublecheck if everything not System or Exchange is really really gone. If you see anything not System or Exchange remove;
5- Place a problematic DL in that OU;
6- Go to ECP, check if you have error, you may not have.
7- Run AD sync to Azure and check again for the error.
If you do not get an error, add the rest of the groups to the permissions one by one and check for the error. If you use LAPS start with that one. If you find it just create a new group for the same purpose and with the same permission on the OU and you should be fine. - MarcoLFranciscoJan 19, 2023
Microsoft
Did you check the security permissions of the OU where the problematic objects remain? And compare with the security permissions for an OU that does not sync to Azure.
Also you can try to resolve the SID with psgetsid:
C:\PSTools>.\PsGetsid.exe a8df73ef-c5ea-11d1-bbcb-0080c76670c0
https://learn.microsoft.com/en-us/sysinternals/downloads/psgetsid - blozza77Jan 19, 2023Copper Contributor
MarcoLFrancisco no we never did, we just live with warning. It’s doesn’t appear to cause any issues, changes still apply to objects when you ignore the message.
I still think it’s a legacy schema object artefact somewhere. We’ve had exchange in our AD since version 5.x and retired many child domains.
- MarcoLFranciscoJan 19, 2023
Microsoft
Did you manage to fix this?