leco Posted August 18, 2010 Posted August 18, 2010 I'm trying to write a new policy for redirecting staff documents etc. but I'm getting an error and the policy is not being applied. (See attached for details) I'm not sure what I should do about it.
leco Posted August 22, 2010 Author Posted August 22, 2010 (edited) I ran RSoP on the server to try to identify the issue. The following users cannot be found - IWAM_Server and IUSR_Server. I am assuming that the second bit of the name (Server) is the name of the containing server, is that right? These may have been deleted when uninstalling and clearing Exchange. Question: What do I now need to do as this error is on the Default Domain Controller policy? I need some help here as I'm way out of my depth and comfort zone. I've learnt an awful lot since my new DC crashed and burned but now feeling the heat as the new term looms. ps if there are any mods/admins around this thread should more correctly now be in the Windows Server 2008 forum, as the DC under investigation is not R2. Thanks Edited August 22, 2010 by leco added ps
witch Posted August 22, 2010 Posted August 22, 2010 Moved the thread but can't help with the issue I'm afraid. What makes you think that the missing users are causing the error?
leco Posted August 22, 2010 Author Posted August 22, 2010 Thanks Witch. The event viewer prompted me to look for Cannot Find Users, which listed IWAM and IUSR. It went on to give instructions for finding which policy these lost users were in. Hence Default Domain Controller policy. In RSoP the parts of the Policy that are affected are shown with a red cross against them. I could just remove them from the Policy but I'm not sure what they do exactly. Like I said slightly out of my depth here and sadly my external support is on holiday
mb2k01 Posted August 22, 2010 Posted August 22, 2010 It's a pure guess as I've never had anything like this before, but it looks like some corruption or misconfiguration of the TerminalServer-server policy. Do you have a backup of that adml file that you can restore to? If not, could you remove any links to it and create a new polcicy from scratch?
littlehoughton Posted August 22, 2010 Posted August 22, 2010 I agree with mb2k01, the adm template appears to have got messed up. Go to group policy and look under the administrative templates section and see if it is there, if not you will need to add it back in and look at what settings have been changed. Removing an admin template doesnt undo any settings and you will need the original template to amend those settings in group policy. The alternative is to create another policy and disable that one.
leco Posted August 22, 2010 Author Posted August 22, 2010 It's a pure guess as I've never had anything like this before, but it looks like some corruption or misconfiguration of the TerminalServer-server policy. Do you have a backup of that adml file that you can restore to? If not, could you remove any links to it and create a new polcicy from scratch? Any backup I might have had went with the loss of the original Master DC and other machines. Completely new territory for me here so could you be kind and give me instructions on exactly what to do please?
leco Posted August 22, 2010 Author Posted August 22, 2010 I agree with mb2k01, the adm template appears to have got messed up. Go to group policy and look under the administrative templates section and see if it is there, if not you will need to add it back in and look at what settings have been changed. Removing an admin template doesnt undo any settings and you will need the original template to amend those settings in group policy. The alternative is to create another policy and disable that one. Which admin template am I looking for in which branch of Group Policy? Given that I think this is the default domain controller policy how do I know what has been or should be set on it?
mb2k01 Posted August 22, 2010 Posted August 22, 2010 (edited) Any backup I might have had went with the loss of the original Master DC and other machines. Completely new territory for me here so could you be kind and give me instructions on exactly what to do please? The error message seems to suggest it is just the Terminal Server policy at fault (unless you get multiple error messages with different adml names?) It might be that it is applied at domain level, but doesn't look like it is the "domain policy". What Server OS are you running? Edited August 22, 2010 by mb2k01
leco Posted August 22, 2010 Author Posted August 22, 2010 I don't think I've got a Terminal Server policy, well not one that I've made anyway. I guess that doesn't necessarily mean there isn't one though. I've looked at the domain controller policy which is where the red crosses are. This server is running 2008, there is another DC that's still on 2003, which is I think the named server in the Cannot find message. Thanks, I'll have a look when I get to work in the morning.
mb2k01 Posted August 23, 2010 Posted August 23, 2010 On your 2008 server go to Administrative Tools > Group Policy Management. When it opens you familiar(ish) AD tree down the left hand side. Expand your domain and click on the Group Policy Objects folder, you shoudl then see a list of every policy for your domain. If you notice the TerminalServer policy in there, click on it and it will show you the OU's that it is linked to. From there it is your choice whether you choose to delete, disable or unlink from the individual OU's to test/see whether it gets rid of your errors
littlehoughton Posted August 23, 2010 Posted August 23, 2010 You will need to check each policy in your GPMC, adm templates are irrelevant to the policy name so you need to check what adm templates you have under each administrative templates in your GP's. You can right click and select add/remove tempates and see if you can spot the adm template or alternatively do a search for *.adm templates or look in %systemroot%\inf or the adm template may already be added just dig under that administrative template branch. Also adm templates do not replicate around your domain controllers so if you manage your GP's from multiple servers you will have to search each one. It is best to designate a server you will use for adding templates then they are all in one place. Also you can usually spot when something is a miss with admin templates when looking at the settings in each GP via the GPMC, under the administrative template section if it cannot read the settings from a adm there is usually a GUID instead of what it should read in plain English. 1
leco Posted August 23, 2010 Author Posted August 23, 2010 I did as far as I recall, consolidate all the .adms into a central store. Unfortunately this was on the now defunct Master DC. However, I think I copied them all to the 2008 server also. I'll do a search tomorrow and see what I can find. Thanks
Firefox Posted August 24, 2010 Posted August 24, 2010 Do you have the PolicyDefinitions folder normally located \\FQDN\SYSVOL\FQDN\policies For some reason on our 2008 box it created a folder at this location called PolicyUpdates.....and we had loads of errors with GPO's under we created the missing definitions folder
mb2k01 Posted August 24, 2010 Posted August 24, 2010 I did as far as I recall, consolidate all the .adms into a central store. Unfortunately this was on the now defunct Master DC. However, I think I copied them all to the 2008 server also. I'll do a search tomorrow and see what I can find. Thanks Sorry for not replying yesterday - I'm in the middle of a complete network rebuild in a primary school.... fun! I'm curious - was the defunct DC 2003 by any chance? If it was non-R2 i've seen compatability issues before when people have tried copying/importing them in to a newer server.
leco Posted August 24, 2010 Author Posted August 24, 2010 Yes the PolicyDefinitions folder is there. I think the PolicyUpdates folder is if you have AGPM - Policies can be checked in and out from the folder.
leco Posted August 24, 2010 Author Posted August 24, 2010 Update: After some digging around and a lot of searching - this is a known issue, oh why am I not surprised? Windows 7 and Windows Server 2008R2 admin templates cannot be managed from anything older than those OS's. So because I had earlier copied the files from the R2 DC to the 2k8 DC some of the templates are newer than 2k8 can cope with. Well not the OS but to be more precise the GPMC of 2k8. I can, however, manage the policies from a Windows 7 workstation if I install RSAT. Oh and incidentally, I have also discovered some unresolved SIDs in my travels around the policies. I am left to wonder how many years it's going to take to be rid of the fallout from a destroyed master DC.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now