Hello,
We were wondering what is the easiest way to stop the following error logs that are coming from the Directory Service event log list. We have recently demoted and removed two
servers from AD, which may be causing these events to occur.
Active Directory failed to construct a mutual authentication service principal name (SPN) for the following domain controller.
Domain controller:
4bdd8238-8407-4c7f-ba7c-1c8ba78bf52e._msdcs.fsb.com
The call was denied. Communication with this domain controller might be affected.
Additional
Data
Error value:
8589 The DS cannot derive a service principal name (SPN) with which to mutually authenticate the target
server because the corresponding server object in the local DS database has no serverReference attribute.