Domain policy difference in Primary/Secondary Domain Controller

%3CLINGO-SUB%20id%3D%22lingo-sub-1163334%22%20slang%3D%22en-US%22%3EDomain%20policy%20difference%20in%20Primary%2FSecondary%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1163334%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20guys%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20faced%20this%20issue%20whereby%20i%20am%20designing%20the%20same%20domain%20policy%20for%20both%20primary%20and%20secondary%20domain%20controller.%20But%20what%20i%20see%20is%20that%20only%20primary%20domain%20controller%20is%20applying%20the%20policy%20that%20i%20setup%2C%20only%20partial%20policies%20applied%20in%20secondary%20domain%20controller%20(password%20and%20account%20policy%20is%20not%20applied%20to%20secondary%20domain%20controller).%20I%20have%20checked%20on%20domain%20policy%20management%20and%20saw%20both%20domain%20controller%20status%20are%20showing%20green%20tick.%20My%20understanding%20is%20that%20file%20replication%20are%20working%20fine.%20I%20have%20also%20did%20domain%20policy%20modelling%20on%20both%20domain%20controllers%20and%20i%20can%20see%20the%20result%20are%20applied%20even%20to%20secondary%20DC.%20However%20when%20i%20issue%20command%20for%20GPupdate%2Fforce%20it%20shows%20successful%20with%20no%20password%20policy%2F%20account%20policy%20applied.%20Any%20advice%20to%20further%20troubleshooting%20the%20issue%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWorth%20to%20note%20that%20both%20domain%20controllers%20are%20using%20Windows%20Server%202016.%20They%20are%20able%20to%20ping%20each%20other.%20I%20also%20simulate%20to%20create%20a%20new%20domain%20account%20and%20it%20does%20replicate%20to%20secondary%20domain%20controller.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1163334%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EActive%20Directory%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1164122%22%20slang%3D%22en-US%22%3ERe%3A%20Domain%20policy%20difference%20in%20Primary%2FSecondary%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1164122%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F551330%22%20target%3D%22_blank%22%3E%40K-Ang%3C%2FA%3EDaft%20question%2C%20your%20DNS%20Client%20settings%2C%20on%20DC1%20do%20you%20have%20DC2%20as%20its%20primary%20address%20and%20on%20DC2%20do%20you%20have%20DC1%20as%20its%20primary%3F%20They%20should%20have%20their%20own%20address%20as%20secondary.%20Also%20ensure%20that%20the%20IPv6%20address%20isn't%20%3A%3A1%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20sounds%20like%20replication%20issue%20but%20you%20are%20getting%20account%20creation%20replicated%20across.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAre%20you%20editing%20the%20default%20domain%20policy%20for%20the%20password%20settings%3F%20It's%20worth%20noting%20that%20only%20one%20GPO%20can%20do%20the%20password%20policy%20on%20a%20domain%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1166189%22%20slang%3D%22en-US%22%3ERe%3A%20Domain%20policy%20difference%20in%20Primary%2FSecondary%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1166189%22%20slang%3D%22en-US%22%3E%3CP%3EDear%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F213341%22%20target%3D%22_blank%22%3E%40Mark%20Lewis%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYes%20i%20have%20setup%20DC1%20to%20have%20DC2%20ip%20address%20as%20primary%2C%20same%20goes%20to%20DC2%20as%20well.%20I%20could%20have%20just%20disable%20ipv6%20but%20may%20i%20know%20why%20it%20cannot%20be%20%3A%3A1%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20default%20domain%20policy%20for%20password%20settings%20but%20in%20that%20case%20i%20can't%20have%20kerberos%20policy%20setup%20because%20default%20domain%20policy%20is%20assigned%20to%20domain%20computer.%20May%20i%20know%20if%20i%20setup%202%20policies%20with%20password%20policies%20inside%20and%20assigned%20separately%20will%20it%20work%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1166516%22%20slang%3D%22en-US%22%3ERe%3A%20Domain%20policy%20difference%20in%20Primary%2FSecondary%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1166516%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F551330%22%20target%3D%22_blank%22%3E%40K-Ang%3C%2FA%3EI've%20had%20all%20sorts%20of%20odd%20issues%20when%20the%20DNS%20client%20address%20has%20been%20%3A%3A1.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20don't%20believe%20you%20can.%20What%20you%20need%20to%20be%20looking%20at%20are%20Fine%20Grained%20Password%20Policies%20for%20running%20multiple%20policies.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1168458%22%20slang%3D%22en-US%22%3ERe%3A%20Domain%20policy%20difference%20in%20Primary%2FSecondary%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1168458%22%20slang%3D%22en-US%22%3E%3CP%3EDear%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F213341%22%20target%3D%22_blank%22%3E%40Mark%20Lewis%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESorry%20for%20providing%20wrong%20information.%20There%20is%20only%20one%20domain%20policy%20that%20contains%20password%20policy%2C%20account%20policy%2C%20kerberos%20policy%20and%20security%20options.%20They%20are%20in%20default%20domain%20policy.%20However%20we%20have%20additional%20policies%20that%20defines%20rules%20other%20than%20the%20mentioned%20policies%20above.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1168836%22%20slang%3D%22en-US%22%3ERe%3A%20Domain%20policy%20difference%20in%20Primary%2FSecondary%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1168836%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F551330%22%20target%3D%22_blank%22%3E%40K-Ang%3C%2FA%3ESo%2C%20is%20the%20issue%20with%20other%20policies%20that%20set%20options%20other%20than%20password%20and%20kerberos%20not%20replicating%3F%20Things%20like%20Only%20use%20NTLMv2%3F%20Who%20can%20log%20on%2C%20drive%20mapping%20via%20preferences%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1169017%22%20slang%3D%22en-US%22%3ERe%3A%20Domain%20policy%20difference%20in%20Primary%2FSecondary%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1169017%22%20slang%3D%22en-US%22%3EThose%20are%20replicated%20fine.%20Only%20password%20policy%20and%20account%20lockout%20policy%20is%20not%20applying.%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hi guys,

 

I faced this issue whereby i am designing the same domain policy for both primary and secondary domain controller. But what i see is that only primary domain controller is applying the policy that i setup, only partial policies applied in secondary domain controller (password and account policy is not applied to secondary domain controller). I have checked on domain policy management and saw both domain controller status are showing green tick. My understanding is that file replication are working fine. I have also did domain policy modelling on both domain controllers and i can see the result are applied even to secondary DC. However when i issue command for GPupdate/force it shows successful with no password policy/ account policy applied. Any advice to further troubleshooting the issue?

 

Worth to note that both domain controllers are using Windows Server 2016. They are able to ping each other. I also simulate to create a new domain account and it does replicate to secondary domain controller.

6 Replies
Highlighted

@K-AngDaft question, your DNS Client settings, on DC1 do you have DC2 as its primary address and on DC2 do you have DC1 as its primary? They should have their own address as secondary. Also ensure that the IPv6 address isn't ::1

 

It sounds like replication issue but you are getting account creation replicated across.

 

Are you editing the default domain policy for the password settings? It's worth noting that only one GPO can do the password policy on a domain

Highlighted

Dear @Mark Lewis ,

 

Yes i have setup DC1 to have DC2 ip address as primary, same goes to DC2 as well. I could have just disable ipv6 but may i know why it cannot be ::1?

 

I have default domain policy for password settings but in that case i can't have kerberos policy setup because default domain policy is assigned to domain computer. May i know if i setup 2 policies with password policies inside and assigned separately will it work?

Highlighted

@K-AngI've had all sorts of odd issues when the DNS client address has been ::1.

 

I don't believe you can. What you need to be looking at are Fine Grained Password Policies for running multiple policies.

Highlighted

Dear @Mark Lewis,

 

Sorry for providing wrong information. There is only one domain policy that contains password policy, account policy, kerberos policy and security options. They are in default domain policy. However we have additional policies that defines rules other than the mentioned policies above. 

Highlighted

@K-AngSo, is the issue with other policies that set options other than password and kerberos not replicating? Things like Only use NTLMv2? Who can log on, drive mapping via preferences?

Highlighted
Those are replicated fine. Only password policy and account lockout policy is not applying.