Robert's profileRobert's WorldPhotosBlogListsMore Tools Help

Blog


August 14

Data Protection Manager (DPM) 2007 issue on Domain Controllers

August 13

 

Data Protection Manager (DPM) 2007 issue on Domain Controllers

Be very careful when deploying DPM to multiple domain controllers in an environment.

Lesson Learned:

When installing Data Protection Manager (DPM) agents onto Active Directory Domain Controllers (DC), the following needs to occur.

1. Agent MUST be installed on each DC, ONE AT A TIME.

2. After EACH installation, you MUST run replication using the repadmin /syncall command to force replication

3. Failure to do this will cause major issues….

Why:

When the agent is installed on a domain controller it creates two Domain Local Security Groups in the Users Organizational Unit (OU): DPMRADCOMTrustedMachines and DPMRADmTrustedMachines. If you do not replicate after EACH DC Agent installation, the SID’s on these groups get hosed. This can be checked by going into the Members of these groups and determining if the DPM Servername has been changed to DUPLICATE$. If you see this, life just got quite a bit uglier.

How to Fix it:

1. Remove the DPM Agent using Add/Remove programs

2. Remove the above Security groups from Active Directory

3. Using the DPM Console, remove the Domain Controllers using the remove agent utility. You will get a pop up stating that the system in question does not appear to have the agent installed and would you like to remove it from the DPM Database. Yes, you do.

4. At this point, you may resume installing your DC’s. One at a time, as directed above.

Recommendation:

Always install the Domain Controller DPM agents first. Otherwise, you get to spend your nights uninstalling ALL the Agents from every server in the DPM environment and starting over… that’s not my definition of fun.

By the way, it appears that at this point in time none of this information is addressed in the Installation and Configuration guide. Searching for resolutions to this issue, there isn’t a lot out there for DPM 2007 so be aware!

 

Comments (1)

Please wait...
Sorry, the comment you entered is too long. Please shorten it.
You didn't enter anything. Please try again.
Sorry, we can't add your comment right now. Please try again later.
To add a comment, you need permission from your parent. Ask for permission
Your parent has turned off comments.
Sorry, we can't delete your comment right now. Please try again later.
You've exceeded the maximum number of comments that can be left in one day. Please try again in 24 hours.
Your account has had the ability to leave comments disabled because our systems indicate that you may be spamming other users. If you believe that your account has been disabled in error please contact Windows Live support.
Complete the security check below to finish leaving your comment.
The characters you type in the security check must match the characters in the picture or audio.

To add a comment, sign in with your Windows Live ID (if you use Hotmail, Messenger, or Xbox LIVE, you have a Windows Live ID). Sign in


Don't have a Windows Live ID? Sign up

No namewrote:
I've also run into this problem after installing the agent simultanious on two DC's (W2K8). When trying to start the DPM agent on my DC I got this error in my log;

"The DPMRA service terminated with service-specific error 1788 (0x6FC)"

This was related to the issue discribed here by Robert. After uninstalling the agent, deleting the (four) AD groups and reinstalling the agent, DPM could communicate with the DC's.

Thanks Robert! This saved me al lot of time and pain!

Regard,

Rogier
Sept. 11

Trackbacks

The trackback URL for this entry is:
http://robertburleson.spaces.live.com/blog/cns!3A99FE1F00B816F9!290.trak
Weblogs that reference this entry
  • None