edie209 Posted September 11, 2007 Posted September 11, 2007 I have just noticed that I am having a random GPO problem. It seems that sometimes the GPO is not applying allowing the user full access to the pc they are logged on to. But if they log off and log on again it can apply the GPO as it should do. I have two domain controllers one has two errors in event viewer Event ID 13 and Edvent ID 2089 (warning) On the second domain controllerI have 3 errors Event ID 1030, 1058 and 2089. I had these errors back around March time and cured them but there must be another reason for them to come back. This second DC hosts Exchange. I have thought about demoting the exchange server, but I understand that this will break exchange. Have you any ideas on why the GPOs are appling randomly
Lithium Posted September 11, 2007 Posted September 11, 2007 Do you allow the computer to carry on being usable? I acn't remeber the name of the policy oject, but there's one which lets you logon before security settings have taken effect - allowing people access to stuff that GPO's disallow... but this gets removed when the object applies in the background... I thought you were supposed to run Exchange & DC's on seperate machines... but maybe it's me.. Does the Microsoft Help and Support section give any more info on those errors... they usually solve it for me... not that I ever check server event logs................. EDIT: Have you checked the computer that is effected for any GPO Timeouts? or if it says a policy is corrupt? if a policy is corrupt, it'll abort the rest of it... leaving the user unrestricted...
witch Posted September 11, 2007 Posted September 11, 2007 If you find out, let me know as 3 of mine did just that last week - only one error though
timbo343 Posted September 11, 2007 Posted September 11, 2007 i could be that your dcs arent synchronising correctly. MS have a piece of software called ultrasound, and it checks that the sysvol is been applied to all DCs.
Guest Guest Posted September 11, 2007 Posted September 11, 2007 ? I acn't remeber the name of the policy oject, but there's one which lets you logon before security settings have taken effect Dont know where it is exactly but its something like; "Wait for network before logon" or maybe "Allow syncronase logon" You ran dcdiag? Id start with your DNS records. Go through looking for any old/incorrect entries and get rid.
maniac Posted September 11, 2007 Posted September 11, 2007 There is a policy called 'always wait for network' somewhere in computer settings which ensures all group policys are applied before the user shell is loaded. Makes a slower login, but 100% reliable. Mike.
edie209 Posted September 12, 2007 Author Posted September 12, 2007 Ok thanks guys I think the policy always wait for network needs to be the first thing I look at then I think I will try those MS tools that timbo mentions. But any other views are most welcome
edie209 Posted September 12, 2007 Author Posted September 12, 2007 After spending the morning looking into this error I have I think found the problem. Event Type: Error Event Source: Userenv Event Category: None Event ID: 1058 Date: 11/09/2007 Time: 17:47:00 User: NT AUTHORITY\SYSTEM Computer: I13-01 Description: Windows cannot access the file gpt.ini for GPO cn={7AFFBCDB-7598-40C9-B18D-82D173A27C39},cn=policies,cn=system,DC=school,DC=lea,DC=sch,DC=uk. The file must be present at the location <\\school.lea.sch.uk\SysVol\school.lea.sch.uk\Policies\{7AFFBCDB-7598-40C9-B18D-82D173A27C39}\gpt.ini>. (Configuration information could not be read from the domain controller, either because the machine is unavailable, or access has been denied. ). Group Policy processing aborted. Edit update on looking at the above location I have 2 unknown accounts in security could someone have a look at the security of their policies folder and post it here I am wondering if it is a security issue Edit 2 I have spoke to someone at another school and compared the settings I have also removed the 2 unknown accounts and it seems like all is working fine, the afternoon will tell.
edie209 Posted September 14, 2007 Author Posted September 14, 2007 I think I have finally sorted it out, after loads of surfing the net I finally found a reference to the same problem as I was having. Two things (I think) caused this Problem one was DFS had stopped on domain controller 2 Problem two was in sysvol I found two extra folders called "scripts_NTFRS_02208728" and "policies_NTFRS_020557a8" on DC2 and on DC1 one extra folder called "NTFRS_PreExisting_See_EventLog" I removed these directories (kept them safe just in case) and then forced replication, so far it seems that all the policy issues have gone. As for Event ID 13 thats is to do with certificate services
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now