Comments on: Using a Non-Exchange Server as an Exchange Database Availability Group File Share Witness Practical Office 365 News, Tips, and Tutorials Tue, 25 May 2021 21:35:46 +0000 hourly 1 By: Mike R Tue, 25 May 2021 21:35:46 +0000 This article help me resolve a problem with OWA and ECP authentication after adding servers to a DAG. The witness server did not have the Exchange Trusted Subsystem as local admin. I followed the procedure and resolved my issue. thanks!

By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Paul Cunningham</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_35462'); = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_35462"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Paul Cunningham</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> Thu, 02 Feb 2017 04:13:08 +0000 In reply to APP.

I think the correct answer is no. But even if you could, there’s no advantage, and it only adds complexity (now you’ve got a DFS share to manage instead of just a regular file share).

The FSW itself doesn’t need to be 100% available. You can patch and reboot the server, for example, without harming the DAG. It’s only required when the cluster needs to make a decision about quorum.

By: APP Wed, 01 Feb 2017 08:53:34 +0000 Can I put DAG witness folder on DFS Share?
Any recommended redundancy option for DAG witness server?

By: Kavindu Wed, 08 Jun 2016 07:39:34 +0000 One of my client has two Exchange 2013 CU 9 nodes and a DAG configured. But they have used only single network adapter for each server for server communication and Mailbox replication. They are planing to go for a DR site and we have installed Additional Domain Controller & One Exchange 2013 CU 9 server in DR Site. This is a different IP Subnet and this is separated from PR in Active Directory Sites and services. ALL PR and DR servers are virtual servers (Hyper-V). In DR Exchange server also we have used only one network adapter.

But when we trying to add new Exchange 2013 (DR ) Node to the DAG, it gave below error.

A server-side database availability group administrative operation failed. Error The operation failed. CreateCluster errors may result from incorrectly configured static addresses. Error: An error occurred while attempting a cluster operation. Error: Cluster API failed: “AddClusterNode() (MaxPercentage=100) failed with 0x5b4. Error: This operation returned because the timeout period expired”. [Server:]

Then after a lot of research i have disabled below parameters from all network adapters. (Hosts & guests)

IPv4 Checsum Offload Disabled
Large Send Offload Ver. 2 (ipV4) Disabled
Large Send Offload Ver. 2 (ipV6) Disabled
TCP Checksum Offload (ipv4) Disabled
TCP Checksum Offload (ipv6) Disabled
UDP Checksum Offload (ipv4) Disabled
UDP Checksum Offload (ipv6) Disabled

I have configured a witness server and a share in primary site and secondary witness server in DR site and also a additional IP for DR.

Now when we trying to add new Exchange 2013 node it will successfully added to the DAG but show as “not operational”. (DAG settings) and also it will dismount the only database in the server.

Please help me to sort this out.


By: Jamie Sun, 10 Apr 2016 03:14:54 +0000 Hi Paul,

I’m running Exchange 2013 CU 11 on 2012 R2 as is my DC which I’m hosting my File Share Witness on. I’ve tried creating the DAG and configuring FSW through the EAC and EMS and I get the same errors when I take a MBX server offline.

File share witness resource ” failed to arbitrate for the file share ‘\homelab-dc01.homelab.localAR-EXCHDAG.homelab.local’. Please ensure that file share ‘\homelab-dc01.homelab.localAR-EXCHDAG.homelab.local’ exists and is accessible by the cluster.

The FSW shows online in my Failover Cluster Manager. I’ve assigned the Administrators group and the AR-EXCHDAG object Full Access on NTFS and Share permissions. Confirmed the Exchange Trusted Sub System is a member of Administrators as well. I’m not sure what else may be happening.

By: Wade wellborn Wed, 24 Feb 2016 23:12:39 +0000 In reply to Paul Cunningham.

It was exchange 2013 Version 15.0 (Build 1076.9). cu 8
I then installed CU 11 on both nodes and still have the same problem.
The error code was ‘0x533’ (‘This user can’t sign in because this account is currently disabled.’). when I try to bring the witness server online using Set-DatabaseAvailabilityGroup or through the failover cluster manager snap in.
It was working before the witness server failed and had to be replaced.
IT was set up same as the first time. Do you have any suggestions.

Also by the way great article.

By: Paul Cunningham Wed, 24 Feb 2016 03:56:14 +0000 In reply to Wade wellborn.

Which version and CU of Exchange?

By: Wade wellborn Tue, 23 Feb 2016 18:21:22 +0000 I am having the exact issues as Josh is having. We have two exchange servers and a witness server. The witness server failed and was replaced. Now when I try to reset the witness using set-databaseavailabilitygroup we also get 0x533 error this user cant sign in because the account is currently disabled. We haven’t been able to bring the witness and quorum back online due to this. Any feed back greatly appreciated.

By: Josh Mon, 04 Jan 2016 06:23:25 +0000 Paul,

I’m really happy to see this article is helping lots to many people out there and you continue to monitor the replies.
I have a DAG setup with 2 Exchange servers. I have a separate non-exchange server as the FSW. However I’m getting this error:

This user can’t sign in because this account is currently disabled.

I’ve added the Exchange Trusted Subsystem to the Local Administrators group on the FSW server. I’ve checked the Share for the Exchange servers and it’s pointing to the share on the FSW.

I have just found one oddity however:

[PS] C:Windowssystem32>cluster res
Listing status for all available resources:

Resource Group Node Status
——————– ——————– ————— ——
Cluster IP Address Cluster Group EXCHANGE01 Online
Cluster Name Cluster Group EXCHANGE01 Online
File Share Witness (\ Cluster Group EXCHANGE01 Failed

[PS] C:Windowssystem32>cluster /quorum
Witness Resource Name Path Type
——————— ——————————————— ——–
(Node Majority) Majority

[PS] C:Windowssystem32>

[PS] C:Windowssystem32>cluster res “File Share Witness” /priv

System error 5007 has occurred (0x0000138f).
The cluster resource could not be found.

[PS] C:Windowssystem32>

The cluster /quorum should return more information than that I’m guessing?

I’m hoping for any assistance you can offer.


By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Paul Cunningham</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_16624'); = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_16624"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Paul Cunningham</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> Wed, 30 Dec 2015 20:34:13 +0000 In reply to Kevin.

Any Windows file share should work, but I see no benefit in clustering the FSW. It doesn’t need to be highly available, and it only adds complexity if you have to manage a cluster for it.
