Jump to content

Recommended Posts

Posted

Hi everyone.

 

I have a frustrating GPO issue that I am running out of ideas to fix. I would greatly appreciate any advice.

 

Here is a breakdown.

 

I use a GPO to specify what software students are allowed to run. This has worked flawlessly the last 3 years. Yesterday I added 2 new applications, which is now only running on some computers.

 

So here is what happens:

 

Test Student logs onto PC 1 in class - Software does not work.

Test Student logs onto PC 2 in class - Software works.

 

I then place the test student into the teacher group, log into PC 1 and the software works. This seems to imply that the software is working fine.

 

I have tried the usual gpupdates on client and server, and I have also tried leaving and joining the domain, renaming etc.

 

In terms of trying to work out if this is GPO related:

 

1. Faulty GPO - PC 2 would not run the software if the Student GPO was faulty.

2. Faulty PC account - This seems unlikely due to the rename and rejoin with fresh credentials.

 

We have 2 DC's - Originally it seemed like the software was only failing when computers validated against the second DC, but I found the same issue on DC 1 as well.

 

The real kicker is that one pc that was failing with the error yesterday now works.

 

(BTW the error is just the standard 'the operation has been cancelled due to restrictions on this computer)

 

Any help would be appreciated!

 

Thanks

Jason

Posted

Hi Steve

 

Thanks for the reply.

 

Been researching if I can run RSOP under the admin account but for student user and it does not seem like one can.

 

I can't run RSOP under student accounts as they have the cmd prompt locked down and when I tried to add CMD.exe to the GPO I have the same issue where the permission is not making it to the client PC.

 

An interesting thing I saw earlier is that when the computer reboots (the one that has been renamed and rejoined a few times) it now shows the last username that has been logged on.

 

Our Policy should apply to show as a blank windows login page without any prior usernames being displayed.

 

Curious...:confused:

Posted

You can. Run MMC, add RSOP in that way as a snapin and it'll ask for computer/user you want to run it under :p

 

Sounds like it's losing a few GPOs, run the rsop and it should show better :)

 

Steve

  • Thanks 2
Posted (edited)

Ah Steve, great tip. I did not know that.

 

Right I have run RSOP for the student username and it is indeed not getting the additions to the GPO I have added yesterday or today.

 

Taking into consideration this is happening on more than one PC I assume it is Server/GPO related.

 

Any more pearls of wisdom? :)

 

Many thanks for the help so far Steve

 

*Edit* I have tried gpupdate /force already

 

*Edit 2* The changes are replicating to the secnd DC, just not the clients

Edited by Jason1975
Posted

So some developments.

 

I logged onto some of our N Computing terminals after installing the software n the server.

 

The software works on the terminals as well as another test machine.

 

So the conclusion is: This issue is potentially restricted to a single room.

 

I then tried to manually refresh the GPO for that room.

 

Some of the computers accept the policy refresh, but about half fail after an RPC error.

 

The RPC server is unavailable

The remote procedure call was cancelled

 

This error occurs even with the firewall off and I can confirm the server info DNS/DHCP for the problematic computers is accurate.

 

 

HOWEVER, even the computers that don't fail still don't run the new software and still do not show the software in the GPO after investigating the user with RSOP.

Posted

So, just to test I went to a different room without terminals just to be thorough.

 

Installed the software on 2 computers.

 

Using gpresult /r I saw that the computers hit the 2 different servers.

 

The software runs on the one and not the other.

 

There seems to be no correlation between the fault and the 2 servers. Sometimes the clients hits DC1 and works, others hit DC1 and don't work. Same with DC2

 

So it seems to look like the GPO is not fully making it onto the pc - It gets the old settings but no new ones I made over the last 2 days.

 

The firewall was on on both clients (even the one where the software works) but I tried turning it off anyway with no success.

 

I am really running out of ideas!

 

Only other software that may block traffic is Avast but I doubt it would be that, although I may try and eliminate that as a potential problem just in case!

 

Will double check Sysvol replication :)

Posted
Only other software that may block traffic is Avast but I doubt it would be that, although I may try and eliminate that as a potential problem just in case!

 

If it is Avast, have you set the reams of "recommended" exceptions? Though you would have thought if it blocks on one, it should block on all.

  • Thanks 1
Posted

mmmmmm Ok, I think I am getting to the root of the issue.

 

I checked the event viewer and have found numerous errors from the 24 Sep until today.

 

 

 

 

 

Here are a few

 

The DFS Replication service failed to recover from an internal database error on volume C:. Replication has been stopped for all replicated folders on this volume.

 

Additional Information:

Error: 9214 (Internal database error (-1605))

Volume: AD3FE7DF-06CA-11E4-80B5-806E6F6E6963

Database: C:\System Volume Information\DFSR

 

--------------------

The DFS Replication service stopped replication on volume C:. This failure can occur because the disk is full, the disk is failing, or a quota limit has been reached. This can also occur if the DFS Replication service encountered errors while attempting to stage files for a replicated folder on this volume.

 

Additional Information:

Error: 9014 (Database failure)

Volume: AD3FE7DF-06CA-11E4-80B5-806E6F6E6963

 

------------------

The DFS Replication service has detected an unexpected shutdown on volume C:. This can occur if the service terminated abnormally (due to a power loss, for example) or an error occurred on the volume. The service has automatically initiated a recovery process. The service will rebuild the database if it determines it cannot reliably recover. No user action is required.

 

Additional Information:

Volume: C:

GUID: AD3FE7DF-06CA-11E4-80B5-806E6F6E6963

Posted
RPC server is unavailable means the PC can not be contacted. Check on the effected pc if file and print sharing and WMI filter is enabled on your firewall. Also Can you ping the PC with name or IP?
  • Thanks 1
Posted

Thanks for taking the time to answer this on a Saturday guys.

 

I can ping the client using name and IP - Firewall is switched off.

 

I wonder if an easier workaround is trying to restore this PC to a date just priory to the error starting.

 

It is a virtual Machine so it may be faster that trying to fix the actual error.

Posted

Well I have decided against the restore for now, as rolling back DC to two weeks will almost certainly have unpredictable results and cause further headaches.

 

Been 'Googling' these error messages but most of what I find applies to Server 2008.

 

If anyone knows of a site that has good info on fixing DFS replication it would be appreciated!

 

Thanks in advance.

Posted
If one DC is playing up (and you have two or more) the best thing to do is to demote that DC, transfer any roles it may have, and re-promote (usually best with a clean build too).
Posted

Hey

 

This sounds like the two DC's are having replication trouble which could cause of the following scenarios:

 

1. The GP differs on 1 DC so when the PC authenticates against this DC it doesn't see that the software is allowed.

2. The security group membership of the user is different on 1 PC because its DC hasn't updated.

 

Check repladmin :)

  • Thanks 1
Posted

Got this error fixed using information from another site to perform a manual authoritative sync between the 2 DC's

 

The solution actually caused a larger problem initially as the forced replication somehow deleted the contents of the sysvol folder, so all the GPO's were empty.

 

Thankfully I had taken a copy of the sysvol folder, which I was able to copy and paste back onto the DC.

 

A gpupdate /force sorted the rest out.

 

My advice would be to always take a sysvol folder copy before working on a problem like this. Without it the fix would have been far more tedious.

 

Thanks to everyone for their help and input.

Posted

Glad you've got it fixed, but just for future reference before you try too many things, I've had significant success with replication issue firstly by using the command dcdiag /showrepl from each DC which can often give a more helpful error than the one that gets logged in events.

 

I've then run an error check on the drive containing sysvol (which I set as a separate drive so it'll run while the server is still live). Sometimes this is enough to fix it. I've also run an SFC /scannow, but I'm uncertain how useful this is. I've also then previously rebooted the server into either safe mode with CMD or recovery console, and run dism /online /cleanup-image /restorehealth

 

Occasionally I've had to do a force replication Force sysvol replication – windowstricks.in

 

The secret with this is to make sure the source is your working DC. It sounds like you may have rep'd a broken/blank sysvol and then restored it from a backup which then successfully rep'd.

 

Very rarely I've had to get this far, but I've then dipped into this document to troubleshoot specific issues...

 

https://technet.microsoft.com/en-us/library/cc949120%28v=ws.10%29.aspx?f=255&MSPPError=-2147217396

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...