gibit Posted February 25, 2009 Posted February 25, 2009 Hello everybody, i got a problem which is drivin me crazy... hope somebody can help, The domain is w2003 native, with 2 DCs on one single site, and about 150 users. 50 of them are connected locally, the rest is using vpn or authenticating only against the mail server. There'a a GPO applied (i believe correctly) at domain level which sets password lenght and maximum age (60 days) for all the domain users. The problem is when i reboot a DC many users cannot login anymore, and i have to reset the passwords to give them access again. Odd thing is that doesn't happen any time i reboot the server (but it already happened twice), and that only part of the users are affcted (say 50 out of 150). I couldnt find anything useful in the logs, and i cant see any common characteristics between the locked out users... any idea? Thanks very much Marco
kmount Posted February 25, 2009 Posted February 25, 2009 I suppose I'd ask whether the DC stayed up longer than 60 days between incidents?
Michael Posted February 25, 2009 Posted February 25, 2009 You have two domain controllers - are they both hosting AD with DNS integrated and DHCP? If they are, another thing I would check is whether File Replication is working (AD Sites and Services). You could also try manually stopping and starting the File Replication Service on each DC. I suspect the users affected are the users who are logging on when you're rebooting a domain controller. I presume the users affected are always different?
FN-GM Posted February 25, 2009 Posted February 25, 2009 I would check replication is playing. Does anything show up in the event log?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now