Jason1975 Posted September 30, 2016 Posted September 30, 2016 Hi everyone. I have a frustrating GPO issue that I am running out of ideas to fix. I would greatly appreciate any advice. Here is a breakdown. I use a GPO to specify what software students are allowed to run. This has worked flawlessly the last 3 years. Yesterday I added 2 new applications, which is now only running on some computers. So here is what happens: Test Student logs onto PC 1 in class - Software does not work. Test Student logs onto PC 2 in class - Software works. I then place the test student into the teacher group, log into PC 1 and the software works. This seems to imply that the software is working fine. I have tried the usual gpupdates on client and server, and I have also tried leaving and joining the domain, renaming etc. In terms of trying to work out if this is GPO related: 1. Faulty GPO - PC 2 would not run the software if the Student GPO was faulty. 2. Faulty PC account - This seems unlikely due to the rename and rejoin with fresh credentials. We have 2 DC's - Originally it seemed like the software was only failing when computers validated against the second DC, but I found the same issue on DC 1 as well. The real kicker is that one pc that was failing with the error yesterday now works. (BTW the error is just the standard 'the operation has been cancelled due to restrictions on this computer) Any help would be appreciated! Thanks Jason
Steve21 Posted September 30, 2016 Posted September 30, 2016 Have you run a rsop on the affected computer/user to see what's applying and any errors? Steve
Jason1975 Posted September 30, 2016 Author Posted September 30, 2016 Hi Steve Thanks for the reply. Been researching if I can run RSOP under the admin account but for student user and it does not seem like one can. I can't run RSOP under student accounts as they have the cmd prompt locked down and when I tried to add CMD.exe to the GPO I have the same issue where the permission is not making it to the client PC. An interesting thing I saw earlier is that when the computer reboots (the one that has been renamed and rejoined a few times) it now shows the last username that has been logged on. Our Policy should apply to show as a blank windows login page without any prior usernames being displayed. Curious...
Steve21 Posted September 30, 2016 Posted September 30, 2016 You can. Run MMC, add RSOP in that way as a snapin and it'll ask for computer/user you want to run it under Sounds like it's losing a few GPOs, run the rsop and it should show better Steve 2
Jason1975 Posted September 30, 2016 Author Posted September 30, 2016 (edited) Ah Steve, great tip. I did not know that. Right I have run RSOP for the student username and it is indeed not getting the additions to the GPO I have added yesterday or today. Taking into consideration this is happening on more than one PC I assume it is Server/GPO related. Any more pearls of wisdom? Many thanks for the help so far Steve *Edit* I have tried gpupdate /force already *Edit 2* The changes are replicating to the secnd DC, just not the clients Edited September 30, 2016 by Jason1975
Jason1975 Posted September 30, 2016 Author Posted September 30, 2016 So some developments. I logged onto some of our N Computing terminals after installing the software n the server. The software works on the terminals as well as another test machine. So the conclusion is: This issue is potentially restricted to a single room. I then tried to manually refresh the GPO for that room. Some of the computers accept the policy refresh, but about half fail after an RPC error. The RPC server is unavailable The remote procedure call was cancelled This error occurs even with the firewall off and I can confirm the server info DNS/DHCP for the problematic computers is accurate. HOWEVER, even the computers that don't fail still don't run the new software and still do not show the software in the GPO after investigating the user with RSOP.
3s-gtech Posted September 30, 2016 Posted September 30, 2016 How many DCs do you have? Is the sysvol replicating correctly if you have multiple? 2
Jason1975 Posted September 30, 2016 Author Posted September 30, 2016 So, just to test I went to a different room without terminals just to be thorough. Installed the software on 2 computers. Using gpresult /r I saw that the computers hit the 2 different servers. The software runs on the one and not the other. There seems to be no correlation between the fault and the 2 servers. Sometimes the clients hits DC1 and works, others hit DC1 and don't work. Same with DC2 So it seems to look like the GPO is not fully making it onto the pc - It gets the old settings but no new ones I made over the last 2 days. The firewall was on on both clients (even the one where the software works) but I tried turning it off anyway with no success. I am really running out of ideas! Only other software that may block traffic is Avast but I doubt it would be that, although I may try and eliminate that as a potential problem just in case! Will double check Sysvol replication
LeMarchand Posted September 30, 2016 Posted September 30, 2016 Only other software that may block traffic is Avast but I doubt it would be that, although I may try and eliminate that as a potential problem just in case! If it is Avast, have you set the reams of "recommended" exceptions? Though you would have thought if it blocks on one, it should block on all. 1
Jason1975 Posted September 30, 2016 Author Posted September 30, 2016 mmmmmm Ok, I think I am getting to the root of the issue. I checked the event viewer and have found numerous errors from the 24 Sep until today. Here are a few The DFS Replication service failed to recover from an internal database error on volume C:. Replication has been stopped for all replicated folders on this volume. Additional Information: Error: 9214 (Internal database error (-1605)) Volume: AD3FE7DF-06CA-11E4-80B5-806E6F6E6963 Database: C:\System Volume Information\DFSR -------------------- The DFS Replication service stopped replication on volume C:. This failure can occur because the disk is full, the disk is failing, or a quota limit has been reached. This can also occur if the DFS Replication service encountered errors while attempting to stage files for a replicated folder on this volume. Additional Information: Error: 9014 (Database failure) Volume: AD3FE7DF-06CA-11E4-80B5-806E6F6E6963 ------------------ The DFS Replication service has detected an unexpected shutdown on volume C:. This can occur if the service terminated abnormally (due to a power loss, for example) or an error occurred on the volume. The service has automatically initiated a recovery process. The service will rebuild the database if it determines it cannot reliably recover. No user action is required. Additional Information: Volume: C: GUID: AD3FE7DF-06CA-11E4-80B5-806E6F6E6963
techy32 Posted October 1, 2016 Posted October 1, 2016 RPC server is unavailable means the PC can not be contacted. Check on the effected pc if file and print sharing and WMI filter is enabled on your firewall. Also Can you ping the PC with name or IP? 1
3s-gtech Posted October 1, 2016 Posted October 1, 2016 DFS errors are what I feared. You need that working before checking anything else - it will have wide ranging effects as time goes on. 1
Jason1975 Posted October 1, 2016 Author Posted October 1, 2016 Thanks for taking the time to answer this on a Saturday guys. I can ping the client using name and IP - Firewall is switched off. I wonder if an easier workaround is trying to restore this PC to a date just priory to the error starting. It is a virtual Machine so it may be faster that trying to fix the actual error.
Jason1975 Posted October 3, 2016 Author Posted October 3, 2016 Well I have decided against the restore for now, as rolling back DC to two weeks will almost certainly have unpredictable results and cause further headaches. Been 'Googling' these error messages but most of what I find applies to Server 2008. If anyone knows of a site that has good info on fixing DFS replication it would be appreciated! Thanks in advance.
3s-gtech Posted October 3, 2016 Posted October 3, 2016 If one DC is playing up (and you have two or more) the best thing to do is to demote that DC, transfer any roles it may have, and re-promote (usually best with a clean build too).
Jason1975 Posted October 3, 2016 Author Posted October 3, 2016 Going to be tricky to do in a live environment, but will bear that in mind if I cant find a solution. Thanks
3s-gtech Posted October 3, 2016 Posted October 3, 2016 Not as bad as you think - try to do it in quieter times if possible though.
Benjiboy87 Posted October 9, 2016 Posted October 9, 2016 Hey This sounds like the two DC's are having replication trouble which could cause of the following scenarios: 1. The GP differs on 1 DC so when the PC authenticates against this DC it doesn't see that the software is allowed. 2. The security group membership of the user is different on 1 PC because its DC hasn't updated. Check repladmin 1
Jason1975 Posted October 10, 2016 Author Posted October 10, 2016 Got this error fixed using information from another site to perform a manual authoritative sync between the 2 DC's The solution actually caused a larger problem initially as the forced replication somehow deleted the contents of the sysvol folder, so all the GPO's were empty. Thankfully I had taken a copy of the sysvol folder, which I was able to copy and paste back onto the DC. A gpupdate /force sorted the rest out. My advice would be to always take a sysvol folder copy before working on a problem like this. Without it the fix would have been far more tedious. Thanks to everyone for their help and input.
Oaktech Posted October 10, 2016 Posted October 10, 2016 Glad you've got it fixed, but just for future reference before you try too many things, I've had significant success with replication issue firstly by using the command dcdiag /showrepl from each DC which can often give a more helpful error than the one that gets logged in events. I've then run an error check on the drive containing sysvol (which I set as a separate drive so it'll run while the server is still live). Sometimes this is enough to fix it. I've also run an SFC /scannow, but I'm uncertain how useful this is. I've also then previously rebooted the server into either safe mode with CMD or recovery console, and run dism /online /cleanup-image /restorehealth Occasionally I've had to do a force replication Force sysvol replication – windowstricks.in The secret with this is to make sure the source is your working DC. It sounds like you may have rep'd a broken/blank sysvol and then restored it from a backup which then successfully rep'd. Very rarely I've had to get this far, but I've then dipped into this document to troubleshoot specific issues... https://technet.microsoft.com/en-us/library/cc949120%28v=ws.10%29.aspx?f=255&MSPPError=-2147217396
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now