jj99 Posted December 10, 2010 Posted December 10, 2010 I'm hoping im being really dumb here! We are having trouble installing stuff as the network administrator on all 2008 severs (2003 are fine). Login as Local admin and everything installs fine! Am I missing a GP or a group membership???
gl3nnym Posted December 10, 2010 Posted December 10, 2010 Never used 2008 yet but does User Account Control run on there? Might be blocking it in the background. Any errors?
jj99 Posted December 10, 2010 Author Posted December 10, 2010 UAC is disabled, its odd cos there is no issue on our 4 2008 R2 DC's!!
Bezwick Posted December 10, 2010 Posted December 10, 2010 is your network admin account a member of the local administrators group, if not just add it and that should solve your problem?
jj99 Posted December 10, 2010 Author Posted December 10, 2010 Its already in there, that's set by GP, that was my first thought!
Bezwick Posted December 10, 2010 Posted December 10, 2010 Is the software you are installing on a remote server? Could it be a problem with Zones?
Bezwick Posted December 10, 2010 Posted December 10, 2010 In the past we have had problems with executing certain files on our systems due to Internet Zone settings and UAC. In other words ensure that the Intranet Zone settings are not set too high on your network adminsitrator account for that machine. The other thing to watch out for is that the permissions on the directory you are trying to install to as set correctly too. ie does your network account have admin privledges where you are installing the software?. if it aint either of those two I'm stumped.
jj99 Posted December 10, 2010 Author Posted December 10, 2010 UAC is disabled, so I cant see that being the issue, permission are fine, like I said its member of the local admin which have full access to all drives.
jamesfed Posted December 10, 2010 Posted December 10, 2010 What accualy happens when you try to install the application? I'd renable UAC because if you don't have enough permissions to install the application it'll pop up and ask for a admin account.
gl3nnym Posted December 10, 2010 Posted December 10, 2010 I agree with jamesfed, re-enable UAC as this will give you the option of adding extra credentials and should provide any relevant error messages.
DMcCoy Posted December 10, 2010 Posted December 10, 2010 If you have software restriction policy enabled, SIMs updates by copying a file into temp and running from there, I've had to add an exception for it here.
jj99 Posted December 10, 2010 Author Posted December 10, 2010 With UAC enabled, you get the same error's except with the UAC prompt before it. I cannot install sql 2008 (Unknown error 30). MS System Centre fails to even load setup with unknown error. Add wsus as a roll (an unknown error has occurred - relating to sql permissions on web), .net 3.5, 4 fail to install (You guessed it unknown error). SQL MMC fails to load as well as network admin but loads fine for local admin! I still think its a GP, in that I have missed some box to allow but cant prove it!
jamesfed Posted December 10, 2010 Posted December 10, 2010 Have you tried running group policy modeling in your active directory to see what is being applied to the server in question?
DMcCoy Posted December 10, 2010 Posted December 10, 2010 Does the network admin have any redirected folders or appdata?
jj99 Posted December 13, 2010 Author Posted December 13, 2010 I have found the problem, but not a solution yet! On all server 2008 standard the regional options Current format is set to Arabic (Saudi Arabia)!!! not as the Group Policy specifies which is English (united Kingdom). However all windows 7 2003 and server 2008 r2 regional options are set to English (UK)! Nothing on web, any ideas people?
jamesfed Posted December 13, 2010 Posted December 13, 2010 I have found the problem, but not a solution yet! On all server 2008 standard the regional options Current format is set to Arabic (Saudi Arabia)!!! not as the Group Policy specifies which is English (united Kingdom). However all windows 7 2003 and server 2008 r2 regional options are set to English (UK)! Nothing on web, any ideas people? Are your time zones setup correctly? While it would be a weird error if the time zone is out (because of the regional options being out) it should affect user logins (although it should stop them compleately). Also if the server is a DC it wouldn't be getting group policy from default domain top level but from the domain controlers policy (look for its OU in group policy management).
shibz Posted December 16, 2010 Posted December 16, 2010 (edited) I have found the problem, but not a solution yet! On all server 2008 standard the regional options Current format is set to Arabic (Saudi Arabia)!!! not as the Group Policy specifies which is English (united Kingdom). However all windows 7 2003 and server 2008 r2 regional options are set to English (UK)! Nothing on web, any ideas people? It's because your British (I'm serious, hear me out). There is a bug in Windows Server 2008 that forces the "current format" to "Arabic (Saudi Arabia)" and prevents you from making any changes to it if you set the regional options to English (any country other than US) in the group policy. It appears that this affects Windows Server 2008 R1 machines (and maybe Vista too) running under a Windows Server 2008 R2 domain. Edit: I'm told that you may have to not only remove the offending group policy setting, but also delete the affected user profiles. After the user logs in again, it should be back to normal. You may want to do some testing before you delete anything though =P Edited December 16, 2010 by shibz
Bruce123 Posted December 23, 2010 Posted December 23, 2010 I would *suspect* a Group Policy setting is to blame (possibly a "local security" policy setting). And since it effects all of your 2008 servers it must be set in a GPO (that presumably is applied to the domain), rather than locally on each 2008 non-DC server. There is a seperate default GPO policy which applies to DCs (Default Domain Controllers Policy). Running a RSOP might assist here, and compare this with running the tool on your 2003 servers. I would also run the local security policy editor to see if there is anything obviously wrong there. I would also delete all your locally stored profiles on these servers for the jpc\administrator account. Thanks, Bruce.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now