Active Directory cannot delete the access control entry (ACE) for the domain Domain Controllers security group on a newly created application directory partition Rule

Run As Profiles

Name
Default

Alert Details

Message Priority Severity
Active Directory cannot delete the access control entry (ACE) for the domain Domain Controllers security group on a newly created application directory partition Medium Warning

Rule Knowledgebase

Summary

The Active Directory® service was unable to delete the access control entry (ACE) for the Domain Controllers security group for the domain on the newly created application directory partition. This ACE gave the Domain Controllers security group the Replication Get Changes All right for the following newly created application directory partition.

Application directory partition: %3

Additional Data

Error value: %1 %2

Causes
This rule does not contain any causes.
Resolutions

Review the access control list (ACL) on the newly created application directory partition. Ensure that the right Replication Get Changes All is given to the Enterprise Domain Controllers security group, and then remove that right from the Domain Controllers security group for the domain.

External References

For more information, see:

See Also for Active Directory (AD) Monitoring Management Pack


Downloads for Active Directory (AD) Monitoring Management Pack

AZURE OPTIMIZATION ASSESSMENT GET STARTED
MIGRATION TO AZURE GET STARTED
SYSTEM CENTER MIGRATION TO AZURE GET STARTED
MIGRATION TO AZURE FOR SQL AND WINDOWS 2008 GET STARTED