Event ID - 16395

Event Id16395
SourceSAM
DescriptionA fatal error occurred trying to transfer the SAM account database into the directory service. A possible reason is the SAM account database is corrupt.
Event InformationAccording to Microsoft :
Cause :
This event is logged when a fatal error occurred trying to transfer the SAM account database into the directory service.
Resolution :
Retry promotion to a domain controller
A fatal error occurred when the Security Accounts Manager (SAM) database was undergoing conversion to Active Directory Domain Services (AD DS). The SAM database may be corrupt.
To perform these procedures on a computer joining an existing domain, you must have membership in Domain Admins or you must have been delegated the appropriate authority.
To perform these procedures on a computer creating a new domain in an existing forest, you must have membership in Enterprise Admins or you must have been delegated the appropriate authority.
To perform these procedures on a computer creating a new forest, you must have membership in Adminstrators or you must have been delegated the appropriate authority.
Restart the computer and try running the Active Directory Domain Services Installation Wizard.
To run the Active Directory Domain Services Installation Wizard:
  1. Click Start. In Start Search, type dcpromo, and then press ENTER. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
  2. Follow the directions in the Active Directory Domain Services Installation Wizard.
Verify :
To perform these procedures, you must have membership in Domain Admins, or you must have been delegated the appropriate authority. Perform all procedures on the computer that is logging the event.
Note : Before you stop the NTDS service, consider temporarily disabling the password-protected screen saver, if it is enabled. If the password-protected screen saver starts while the NTDS service is stopped, you will have to restart the computer to log in.
To check the integrity of the database:
  1. On the domain controller on which you want to verify the integrity of the Active Directory database, open a command prompt as an administrator. To open a command prompt as an administrator, click Start. In Start Search, type Command Prompt. At the top of the Start menu, right-click Command Prompt, and then click Run as administrator. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
  2. Stop the Active Directory database process: at the command prompt, type net stop ntds, and then press ENTER.
  3. To stop dependent services, type y, and then press ENTER.
  4. Type ntdsutil, and then press ENTER.
  5. Type activate instance ntds, and then press ENTER.
  6. Type semantic database analysis, and then press ENTER.
  7. Type go, and then press ENTER.
  8. Type quit, and then press ENTER twice. The command prompt appears.
  9. At the command prompt, type esentutl /mh c:\windows\ntds\ntds.dit, and then press ENTER. If the ntds.dit file is stored on a different volume and folder, enter that path instead of c:\windows\ntds.
  10. Next, run the command esentutl /g c:\windows\ntds\ntds.dit. Modify the path to the ntds.dit file as necessary. If there are no errors reported, the Active Directory database integrity is intact.
  11. Type net start ntds and press ENTER.
  12. Type quit, and then press ENTER. The command prompt disappears.
If you disabled the password-protected screen saver, you may enable it after the NTDS service starts.
Reference LinksEvent ID 16395 from Source SAM

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.