Jump to content

Recommended Posts

Posted

I have just noticed that I am having a random GPO problem. It seems that sometimes the GPO is not applying allowing the user full access to the pc they are logged on to. But if they log off and log on again it can apply the GPO as it should do.

 

I have two domain controllers one has two errors in event viewer

Event ID 13 and Edvent ID 2089 (warning)

 

On the second domain controllerI have 3 errors Event ID 1030, 1058 and 2089. I had these errors back around March time and cured them but there must be another reason for them to come back.

 

This second DC hosts Exchange. I have thought about demoting the exchange server, but I understand that this will break exchange.

 

Have you any ideas on why the GPOs are appling randomly

Posted

Do you allow the computer to carry on being usable?

 

I acn't remeber the name of the policy oject, but there's one which lets you logon before security settings have taken effect - allowing people access to stuff that GPO's disallow... but this gets removed when the object applies in the background...

 

I thought you were supposed to run Exchange & DC's on seperate machines... but maybe it's me..

 

Does the Microsoft Help and Support section give any more info on those errors... they usually solve it for me... not that I ever check server event logs.................

 

 

EDIT: Have you checked the computer that is effected for any GPO Timeouts? or if it says a policy is corrupt? if a policy is corrupt, it'll abort the rest of it... leaving the user unrestricted...

Posted
?

 

I acn't remeber the name of the policy oject, but there's one which lets you logon before security settings have taken effect

 

 

Dont know where it is exactly but its something like;

 

"Wait for network before logon" or maybe "Allow syncronase logon"

 

 

You ran dcdiag?

 

Id start with your DNS records. Go through looking for any old/incorrect entries and get rid.

Posted

There is a policy called 'always wait for network' somewhere in computer settings which ensures all group policys are applied before the user shell is loaded. Makes a slower login, but 100% reliable.

 

Mike.

Posted

Ok thanks guys I think the policy always wait for network needs to be the first thing I look at then I think I will try those MS tools that timbo mentions.

 

But any other views are most welcome

Posted

After spending the morning looking into this error I have I think found the problem.

 

Event Type: Error

Event Source: Userenv

Event Category: None

Event ID: 1058

Date: 11/09/2007

Time: 17:47:00

User: NT AUTHORITY\SYSTEM

Computer: I13-01

Description:

Windows cannot access the file gpt.ini for GPO cn={7AFFBCDB-7598-40C9-B18D-82D173A27C39},cn=policies,cn=system,DC=school,DC=lea,DC=sch,DC=uk. The file must be present at the location <\\school.lea.sch.uk\SysVol\school.lea.sch.uk\Policies\{7AFFBCDB-7598-40C9-B18D-82D173A27C39}\gpt.ini>. (Configuration information could not be read from the domain controller, either because the machine is unavailable, or access has been denied. ). Group Policy processing aborted.

 

Edit update on looking at the above location I have 2 unknown accounts in security could someone have a look at the security of their policies folder and post it here I am wondering if it is a security issue

 

Edit 2 I have spoke to someone at another school and compared the settings I have also removed the 2 unknown accounts and it seems like all is working fine, the afternoon will tell.

Posted

I think I have finally sorted it out, after loads of surfing the net I finally found a reference to the same problem as I was having.

 

Two things (I think) caused this

 

Problem one was DFS had stopped on domain controller 2

 

Problem two was in sysvol I found two extra folders called "scripts_NTFRS_02208728" and "policies_NTFRS_020557a8" on DC2 and on DC1 one extra folder called "NTFRS_PreExisting_See_EventLog"

 

I removed these directories (kept them safe just in case) and then forced replication, so far it seems that all the policy issues have gone.

 

As for Event ID 13 thats is to do with certificate services

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...