Errors are logged in the Application log on the MOM agent When you try to monitor MOM 2005 SP1 agents in a remote untrusted forest (910207)



The information in this article applies to:

  • Microsoft Operations Manager 2005 SP1

SYMPTOMS

When you try to monitor Microsoft Operations Manager (MOM) 2005 Service Pack 1 (SP1) agents in a remote untrusted forest, errors that are similar to the following are logged in the Application log on the MOM agent:

An error occurred while executing 'AD Remote Topology Discovery'
Failed to execute the query
'<LDAP:///CN=Configuration,DC=domain name,DC=llc>;(&(objectCategory=Server)(cn=domain name-D C01));adspath,distinguishedName;subtree'.
The error returned was: 'An invalid directory pathname was passed ' (0x80040E37)
0x80040E37 Domain: domain name Computer: DC Name Time: datetime
Type: Warning
Provider Name: Script-generated Data
Event Number: 21000
Provider Type: Generic Provider
Source: AD Remote Topology Discovery
Category:
Raises Alert: True
Consolidated:
Frm:
To:


Description:
The script 'AD Replication Partner Count' failed to initialize correctly.
The error returned was: 'Object required' (0x80000000)
Name: Script Based Test Failed to Complete
Severity: Warning Resolution State: New
Domain: domain name
Computer: DC Name
Time of First Event: datetime
Time of Last Event: datetime
Alert latency: 1 sec
Problem State: Investigate
Repeat Count: 10
Age:
Source: AD Replication Partner Count
Alert Id: a44151ad-8377-46f8-9b2e-d6951a3ee256


Description: The script 'AD Replication Monitoring' encountered a runtime error.
Failed to bind to 'LDAP:///RootDSE'.
The error returned was: '' (0x80005000)
Name: Script Based Test Failed to Complete
Severity: Warning
Resolution State: New
Domain: domain name
Computer: DC Name
Time of First Event: datetime
Time of Last Event: datetime
Alert latency: 1 sec
Problem State: Investigate
Repeat Count: 20
Age:
Source: AD Replication Monitoring
Alert Id: 3268a163-655d-49d5-928e-7471f0c99d29
Rule (enabled): Microsoft Windows Active Directory\Active Directory Windows 2000 and Windows Server 2003 \Active Directory - General\Script Based Test Failed to Complete

CAUSE

This issue occurs because MOM 2005 SP1 cannot use the Active Directory Management Pack to monitor domain controllers that are in untrusted domains.

WORKAROUND

To work around this issue, install a separate MOM management group in each untrusted forest.

Note This issue has been known to be partially resolved by the following method. First, apply MOM 2005 SP1. Then, use the Active Directory Topology Discovery script to enable the server fully qualified domain names (FQDNs) to be added to the Computer table. However, when you use this method, most of the scripts will continue to log errors.

STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

Modification Type:MajorLast Reviewed:12/20/2005
Keywords:kbBug kberrmsg kbprb KB910207 kbAudITPRO kbAudDeveloper