Jump to content

Cannot open the 'AD Users and Computers' Administrative Tool


Recommended Posts

Posted

Hi all

 

Had the message shown in the attachment - since the other day - appear when trying to open Active Directory Users and Computers from ANY machine [including the server(s)].

 

I've restarted the DC in a hope that this will fix it - but it hasnt :(

 

I havent changed any group policy settings for a while - especially ones that would stop me running the AD Users and computers.

 

I can still open the Group Policy Management tool however.

 

Any ideas?? This isnt helping my RIS setting up hehe

 

Cheers

Nath

march_helpmepls.jpg

Posted

Have you installed MMC 3 on any machine and then opened that snap-in?

I know I've had trouble when its updated a snapin to MMC3 and then I've opened the same one on the original MMC2 you get with XP & 2000 Server.

Posted

I have used the same version of the adminpak.msi throughout [not sure the exact ver number but its SP1 - i.e. for compatibility with Server 2003 SP1 ;)

 

Dont use Server 2000 here [except the Bromcom server - on a different domain entirely].

 

I havent intentionally installed MMC 3 anywhere that I know of - I've only installed the adminpak [for 2003 sp1/XP SP2] and the GPMC SP1 previously.

 

I could try reinstalling it on the server I guess.

 

Maybe a recent hotfix has "broke" it hehe I wonder if there is a newer version of the adminpak on the MS website - shall have a look.

 

Bit of a tricky one.

 

Cheers

Nath

Posted

Might be a long shot, and not even entirely sure its in any way relative to the problem, but you could try editing the registry at ...

 

HKcurrentuser\software\policies\microsoft\mmc

 

and changing the restricttopermittedsnapins value from 1 to 0

 

As I say, might not be the same thing, but I had a similar problem with my group policy snapin once and this solved it.

Posted
I had the same thing happen with my Group Policy management snapin as well I just had to reinstall it.

 

Do you mean the adminpak which is what you uninstalled and reinstalled?

 

If not, how do i do that?

 

HKcurrentuser\software\policies\microsoft\mmc

 

The server doesnt appear to have that registry key there - shoulf I create it and create the restricttopermittedsnapins at value 0?

 

Regards

Nath

  • 1 month later...
Posted

bump ^^

 

Chris - what dud you mean?

 

How did you reinstall the snap-in?

 

Did you get the error message throughout the system?

 

I get it on every computer - both server and desktop - meaning that I cant make any changes to the AD User & computers structure.

 

This is getting to be a problem as I cant setup the new laptops that will be arriving soon and they are already tamping because I was off work for so long :(

 

Any thoughts?

 

Nath

Posted

lol sarcasm?

 

look at the begining of the thread's date ;) ...and the fact that it happens on every machine I try it on.

 

/sarcastic response over

 

But seriously.... I wish it was that simple.

 

*cries*

 

....Nath.

Posted
Every machine that you log onto? Does it do the same with different users? Might be worth removing your profile if it doesn't. Its a PITA but should sort it.
Posted

hehe I await a flood of flaming but....

 

It on the administrator account. There are no other administrator accounts.

 

I had a thought that it could be to do with the administrator profile so here's my two ideas:

 

1) create a new account - called admin or something - and add it to the administrators group and use that and see if it works...

 

or

 

2) clear the profile directory of the administrator account and see what destruction is caused

 

Any suggestions on what to try first?

 

Has anyone ever tried number 2 and has it caused them any problems?

 

Regards

Nath.

Posted

If you go to My Computer > Tools > Folder Options and click the File Types tab, what program are *.MSC files associated with? On my machine it is associated with the MMC console.

 

I presume you have checked to see that dsa.msc does exist in C:\WINDOWS\system32? I've attached the file which is from my XP SP2 workstation (if you want to try manually copying the file). Rename the file to dsa.msc The .msc file extension isn't allowed on EduGeek so I renamed it to dsc.doc :)

dsa.doc

Posted

@Michael:

lol nice idea with the file types but nothing to do with that - the error message is too specific for one thing.

 

If you look at most of my posts in the thread, you'll notice that I said it happens on both the workstations and the servers [and the adminpak is installed on them all]

 

 

@all:

 

Sorted it :)

 

By clearing out the administrator profile :)

 

Simple as that - thanks Norphy for reactivating my brain to remember to try that - and a pint for all you too [if you are/I am at the conf - dont think it would travel in the post hehe].

 

Cheers

Nath

  • 1 month later...
Posted
Are u using mstsc (microsoft terminal services client) to connect to the servers, if so by default it only allows two conections. So u must have two connections to the server already. If you log in to the server again using this method (mstsc) and then log the administrator out by the usual method you should find that it will allow connection. Hope this remedies the fault. also you can go into the terminal services on the server and set the connections to unlimited if you want but i wouldn't condone this action for safety reasons. :)
Posted

bossman & buzzard:

 

Thanks guys, but its not that i.e. I'm not using the microsoft terminal services client.

 

Its just bog-standard loading it up on the server and loading it up on the client workstations - The same version but somewhere along the line, it corrupts the profile and the rest is history i guess hehe

 

Easily solved with a quick wipe of the MMC part of the profile - but strange how I never had that problem until recently [start of the thread date-ish].

 

I now cant reset a user's password now lol when going to reset password using the AD U&C console. I get:

 

Windows cannot complete the password change for user because:

 

Access is denied

 

hehe How does that make sense? I'm the administrator hehe

 

It does work however, by not being on the domain [my machine i use is not attached to the domain yet hehe] and installing the adminpak and using the AD C&U console - then connecting to the domain.

 

That works.

 

I think it must be my roaming profile on the administrator account ]no laughing now lol]

 

Cheers

Nath

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...