TwistedHelixis Posted February 16, 2017 Posted February 16, 2017 I have some random characters listed as users on 2 settings within my default domain controller policy. I assume they are old orphaned accounts that have been deleted. Could some post up the accounts listed under these to sections, so I can check them against mine. default domain controller policy///Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights\Assignment\Access this computer from the network and default domain controller policy///Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights\Assignment\Deny access to this computer from the network Many thanks for your time
Fazza Posted February 16, 2017 Posted February 16, 2017 I have some random characters listed as users on 2 settings within my default domain controller policy. I assume they are old orphaned accounts that have been deleted. Sounds like you're seeing a SID but without a screenshot I can't say for sure. If it is a SID you're seeing then you are correct in saying they are old/orphaned/deleted account that have been deleted. 1
TwistedHelixis Posted February 16, 2017 Author Posted February 16, 2017 I will re install my test vm server and post a screen shot
TwistedHelixis Posted February 16, 2017 Author Posted February 16, 2017 These are the random characters. Thanks
LeMarchand Posted February 16, 2017 Posted February 16, 2017 Looks like deleted accounts to me. Here's mine (Domain covered up). No idea what the "Deny" one is - there's no such user!
TwistedHelixis Posted February 16, 2017 Author Posted February 16, 2017 Thanks. I will delete the random characters accounts from them both.
HPlum78 Posted February 16, 2017 Posted February 16, 2017 Best practice is to leave the default XXX GPO's alone, MS provide tools to recreate the default GPO's for those who do not take note of the best practice! here is one https://technet.microsoft.com/en-us/library/hh875588(v=ws.11).aspx I think that there are some caveats if you are running Exchange.
Fazza Posted February 16, 2017 Posted February 16, 2017 Yeah, they're definitely SID's of accounts that no longer exist. 1
TwistedHelixis Posted February 16, 2017 Author Posted February 16, 2017 (edited) Best practice is to leave the default XXX GPO's alone, MS provide tools to recreate the default GPO's for those who do not take note of the best practice! here is one https://technet.microsoft.com/en-us/...(v=ws.11).aspx I think that there are some caveats if you are running Exchange. I took over these servers from the local authority and the default XXX policies are full of changes onj not MS recommended in anyway. Doing the fix from your link would reset the policies, something that does need doing, but not at this moment as the fallout could be time consuming. Originally I was getting this error when running AD best practice analyzer - The Active Directory Domain Services Best Practices Analyzer (AD DS BPA) is not able to collect data about Group Policy Results setting "Access this computer from the network" from the domain controller. When I delete the random characters from my test vm dc and run BPA its reports all fine. What do you think, am I safe to delete them on the live server???? Edited February 16, 2017 by TwistedHelixis
HPlum78 Posted February 16, 2017 Posted February 16, 2017 Yeah they can just go, if they cannot be resolved to an account that still exists then that's a whole different set of issues right there! I had already guessed that you would not have been the perpetrator as you seem to be the one left holding the baby and the questions! good luck @TwistedHelixis 1
TwistedHelixis Posted February 22, 2017 Author Posted February 22, 2017 Out of interest what do others have listed as the user in default domain controller policy///Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights\Assignment\Deny access to this computer from the network LeMarchand has SUPPORT_ which is a user not listed on the server I have random numbers from a deleted account Just interested what it should actually be. Cheers
HPlum78 Posted February 22, 2017 Posted February 22, 2017 (edited) hmmm, I have just looked in 3 domains here and none of them have any deny access setting set! Edited February 22, 2017 by HPlum78 1
TwistedHelixis Posted February 27, 2017 Author Posted February 27, 2017 (edited) Well something may have gone very BAD. I deleted the 2 accounts that no longer exist from 'Access this computer' default domain policy from the network at 2 schools without any problems but just done the same thing at a third and after running the best practice analyzer I am getting a load of errors. I stupidly did not run BPA before removing the orphaned accounts so not 100% sure if these errors have always been around but worried just in case they are new errors cause by me removing the orphaned accounts. Hope someone can help as the list is overwhelming and I don't know where to start. AD BPA Results Information This domain controller must advertise as a KDC for the domain in its local site Configuration Information This domain controller must advertise itself as a Kerberos server for the domain in its local site Configuration Information This domain controller must advertise as a global catalog server for the forest in its local site Configuration Information This domain controller must advertise as an LDAP server for the domain Configuration Information This domain controller must advertise as a KDC for the domain Configuration Information This domain controller must register its Rfc1510Kdc DNS record to advertise itself as Kerberos Server for the domain Configuration Information This domain controller must register an alias (CNAME) resource record with its DsaGuid for the forest Configuration Information This domain controller must register its Rfc1510UdpKpwd DNS record to advertise itself as Kerberos Server for the domain Configuration Information This global catalog server must register its host (A/AAAA) resource records for the forest Configuration Information This domain controller must advertise as a PDC for the domain Configuration Information The schema master role and the domain naming master role should be owned by the same domain controller in the forest Configuration Information This domain controller must register its DNS host A/AAAA records Configuration Information The value of MaxPosPhaseCorrection on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should be equal to 48 hours Configuration Information The PDC emulator master (SERVER)-vm-dc-01.(DOMAIN).lain this forest should be configured to correctly synchronize time from a valid time source Configuration Warning All OUs in this domain should be protected from accidental deletion Configuration Information The directory partition DC=(SERVER),DC=lan on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should have been backed up within the last 8 days Configuration The directory partition CN=Schema,CN=Configuration,DC=(SERVER),DC=lan on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should have been backed up within the last 8 days Configuration Information The directory partition DC=DomainDnsZones,DC=(SERVER),DC=lan on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should have been backed up within the last 8 days Configuration Information No user accounts and trusts for the domain (DOMAIN).lan are configured for DES only Configuration Information All trusted services within the domain (DOMAIN).lan have registered SPNs Configuration Information The Default Domain Controllers Policy is applied to all OUs that contain domain controllers Configuration Information Domain controller (SERVER)-vm-dc-01.(DOMAIN).lan must have "Enable computer and user accounts to be trusted for delegation" granted to the Builtin Administrators security group Configuration Information Domain controller (SERVER)-vm-dc-01.(DOMAIN).lan must have "Access this Computer from the Network" granted to the appropriate security principals Configuration Information No service accounts that are trusted for delegation in the domain (Domain).lan have duplicate SPNs Configuration Warning The domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should comply with the recommended best practices guidelines because it is running on a VM Configuration Information The directory partition DC=ForestDnsZones,DC=(SERVER),DC=lan on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should have been backed up within the last 8 days Configuration Information The directory partition CN=Configuration,DC=(SERVER),DC=lan on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should have been backed up within the last 8 days Configuration Information The KCC should be enabled in each site in the forest (DOMAIN).lan Configuration Information The resultant backup lifetime in this forest should be equal to or greater than 180 days Configuration Information The value of MaxNegPhaseCorrection on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should be equal to 48 hours Configuration Information Strict replication consistency should be enabled on all domain controllers in this forest Configuration Information The RID master role and the PDC emulator master role should be owned by the same domain controller in the domain Configuration Warning All domains should have at least two domain controllers for redundancy Operation Information This domain controller must advertise itself as a generic global catalog server for the forest Configuration Information This domain controller must advertise as the global catalog server for the forest Configuration Information This domain controller must register its Rfc1510Kpwd DNS record to advertise itself as Kerberos Server for the domain Configuration Information This domain controller must register its Rfc1510UdpKdc DNS record to advertise itself as Kerberos Server for the domain Configuration Information This server must advertise itself as a domain controller for the domain Configuration Information This domain controller must register a DNS SRV resource record, which is required for replication to function correctly Configuration Information This domain controller must register its DNS host (A or AAAA) resource records for the domain Configuration Information This domain controller must advertise itself as a generic global catalog server for the forest in its local site Configuration Information This server must advertise itself as a domain controller for the domain in its local site Configuration Information This domain controller must advertise as an LDAP server for the domain in its local site Configuration Edited February 27, 2017 by TwistedHelixis
TwistedHelixis Posted February 27, 2017 Author Posted February 27, 2017 UPDATE - Just fired up a VM backup of the DC on my test host server and did the same thing (deleted the random characters from the GP) but this time it has not got any errors. Hmmm not sure what to do now as I have nothing to fix on my test VM. I could just restore the VM DC onto the live host tonight. Actually would have been more of a help if the test vm had the same issues.
TwistedHelixis Posted February 27, 2017 Author Posted February 27, 2017 Does it make a difference that most if the issues above are Information and not Warning? Think I might start another post just about this issue.
TwistedHelixis Posted February 28, 2017 Author Posted February 28, 2017 Can relax a bit, I just went in to the logs and it has been having the same errors forever, not something I have caused.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now