DNS Error 4000/4007 and AD connection problems

Matteo Tenconi 1 Reputation point
2022-01-10T13:54:45.12+00:00

Hi all, i have some problems with an AD Server apparently after applying the updates on december 27, 2021.
It is a single AD Server environment, so no replication processes, running on Windows Server 2019.
I have DNS error 4000 and 4007, i cannot open DNS Manager, it returns "Access was denied. Would you like to add it anyways?"
163651-image.png

163599-image.png

I've tried resetting netdom password with no results, both with kdc service on and off.
163600-image.png

Testing the AD Services with dcdiag /fix it returns this, it cannot resolve the IP address cause of the problems mentioned before.
163661-image.png

It seems like a loop problem, the DNS Server doesn't work because AD isn't working and vise versa.
Can anyone help me?
Thanks a lot!

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,453 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,843 questions
Windows DHCP
Windows DHCP
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.DHCP: Dynamic Host Configuration Protocol (DHCP). A communications protocol that lets network administrators manage centrally and automate the assignment of Internet Protocol (IP) addresses in an organization's network.
1,021 questions
0 comments No comments
{count} votes

8 answers

Sort by: Most helpful
  1. Dave Patrick 426.1K Reputation points MVP
    2022-01-10T14:00:16.833+00:00

    Maybe this one.
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/dns-zones-do-not-load-event-4000-4007

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  2. Matteo Tenconi 1 Reputation point
    2022-01-10T14:07:56.393+00:00

    @Dave Patrick please check the third image posted, i've tried with the kdc service on/off and got two different errors


  3. Dave Patrick 426.1K Reputation points MVP
    2022-01-10T14:32:30.417+00:00

    for the network profile, it's getting "Private" now

    Try restarting the Network Location Awareness (NLA) service.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


  4. Dave Patrick 426.1K Reputation points MVP
    2022-01-10T15:09:37.713+00:00

    Please run;

    Dcdiag /v /c /d /e /s:%computername% >C:\dcdiag.log
    repadmin /showrepl >C:\repl.txt
    ipconfig /all > C:\dc1.txt
    ipconfig /all > C:\dc2.txt

    then put unzipped text files up on OneDrive and share a link.


  5. Dave Patrick 426.1K Reputation points MVP
    2022-01-10T15:33:32.233+00:00

    Might check that all Auto start services have started up, failing that you may need to restore from a backup. Also going forward its always recommended to have at least two domain controllers for high availability and disaster mitigation (which could have helped here)

    --please don't forget to upvote and Accept as answer if the reply is helpful--