Issue
In a windows 2008 mixed Active Directory environment, the DCDIAG reports the following error:
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=ForestDnsZones,DC=santhosh,DC=lab
Cause/Resolution
You will see this error message when you promote a Windows Server 2008 domain controller in a Windows Server 2003 domain without preparing the AD Schema for RODC (read-only domain controller) using adprep /rodcprep command. If you do not plan to add an RODC to the forest, you can safely ignore this error message. Otherwise, run adprep /rodcprep to update the AD schema.
http://technet.microsoft.com/en-us/library/cc754463(WS.10).aspx