Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi Guys and Gals,

 

First post so I thought Id start with a really annoying problem. Recently got a suite of 32 Windows 7 professional HP machines which I've installed software etc used sysprep then cloned with clonezilla now using the exact same method I also did 35 Toshiba laptops. Now after joining the domain and using gpupdate /force and gpresults / rsop.msc everything is fine on the laptops however on the PCs I receive "Group Policy Infrastructure failed due to the error listed below. Access is denied. "

 

Searching the net found lots of ideas including check DNS, ensure I can resolve the domain name from the clients I can. Ping works fine etc.

 

NIC - disabled IPv6, disabled power saving.

 

Replication errors - Servers both replicating sysvol, 1 being 2003 other 2008. No error messages there.

 

Only difference between the laptops and the workstations is the different organisational units within AD - have tried changing the workstations into other OU no effect.

 

Any ideas would be appreciated so much!

Posted

Hi, thanks for the reply,

 

the forest domain level is 2003 - Am I right in thinking this is what you were asking for?

 

As for the event id ill have to get that Monday but when I googled it nothing really came up. The event id from the event logs on the client yeh?

 

Cheers

Posted

Hi

 

Yes that's right. Just need to know more about the error. Event ID on the client and the server if it exisits.

 

Thanks

Sukh

Posted

I think the event is id:1030 with the description just saying basically group policy failed will try next refresh, however just before this event, 40961 occurs claiming "The security System could not establish a secured connection with the server ldap/servername.domain.net/[email protected]. No authentication protocol was available" also unsure what this means, looks like its related as its 1second before the 1030 error.

 

Cheers!

Posted
OK - on further investigation (messing with a spare PC) turns out according to gpresult user configuration is applied fine but computer configuration fails because "access is denied" on the PC the event id is 1055 for grouppolicy with an error code of 5. "name resolution failure on the current domain controller" nslookup works fine, ping also, dns records are updated correctly. or " Active directory replication latency" the user account is old as in over a year and the computer account is over a month old and both are replicated fine on either server. Also I created a new user in active directory and logged straight into the PC with that account.
Posted

Hi

 

Sorry for the delay, a few unexpected issues came up. Can you please enable GPO operational logging if not already enabled. See steps below.

 

Enable Group Policy Operational Log on Windows 7 if disabled.

 

 

 

a) Open registry editor, navigate to HKLM\Software\Microsoft\Windows NT\CurrentVersion

 

b) Right click CurrentVersion->New->Key

 

c) Rename the newly created key to Diagnostics

 

d) Right click on Diagnostics->New->DWORD(32-bit)value, rename the new DWORD entry to GPSvcDebugLevel and set the value as 0x30002 (hexadecimal)

 

e) After you modified the registry, please run the command gpupdate /force at command prompt to refresh the policy. Reboot the computer to reproduce the issue. The log file is written to the %SystemRoot%\Debug\UserMode folder.

 

 

 

Reboot the workstation and reproduce the issue

 

Please send the log to me (PM) or post online. Generally code 5 means access denied which we are seeing here.

 

Thanks

Sukh

Posted

Hi

 

Many thanks - I did the registry change and noticed on RSOP.msc properties for Computer Configuration the reason for it not being applied had changed this time the message stated "logon failure: unknown user name or bad password" which is confusing as I can log in to both servers with my login and as far as I can tell replication is working fine. DCDIAG reports no errors and AD users are replicated almost instantly. In this log its first of all the problem with Logon failure followed by the usual Access Denied failure.

 

- Couldn't find how to attach in PM so iv posted here. gpsvc.txt

Posted

Hi

 

How many DC have you got?

How many of them are running DNS?

On the client machine can you connect to \\yourdomain.com\sysvol\yourdomain.com?

Can you run netdiag and check for errors?

 

Thanks

Sukh

Posted

Hi

 

Can you also, remove one PC from the domain and delete the computer account associated with that from AD. Then rename the PC and join it to the domain with a new computer name and let me know the results.

 

Thanks

Sukh

Posted

Hi,

 

Got 2 DCs one of them running windows server 2003 the other server 2008.

 

Both are running DNS - is this incorrect?

 

Client can connect to the sysvol folder - typing that command opens up the sysvol folder in windows explorer.

 

Ran netdiag on the server running 2003 and all tests passed. Unsure of a 2008 alternate.

 

Tried removing one PC from the domain deleted account from AD, added it, same problem. Did it again but this time didn't move it in AD left it in the computers OU. Same problem. Tried deleting profiles in registry as well as from Users folder on the client. same problem.

 

Thanks

Posted (edited)

Hi

 

You can have DNS running on both servers that's fine.

 

Can you run GPRESULT /H GPReport.html on the problem PC and send/post the result?

 

Can you also send/post the Group Policy Operation Logs from Event Viewer.

 

Thanks

Sukh

Edited by sukh
Can you also send/post the Group Policy Operation Logs from Event Viewer.
Posted

Hi

 

I did gpresult on 1 of the machines that I've left completely alone to find that it has decided the error has now changed? Iv attached this as gpresult.

On another machine from the suite I have re-imaged it and once it had rejoined the domain first GPO sync was error free however after running gpupdate /force I once again have the same error that the whole suite is having attached as gpresultfromnew. gpresults.zip

 

Cheers

Posted

Hi

 

While I look at the logs, can you confirm when you removed the PC from the domain, did you delete the computer account, wait for replication so it doesn't exist. Then RENAME the computer to a different NAME completely and then join to domain?

 

Thanks

Sukh

Posted

Hi,

 

Sorry for the delay. Yes once I removed it from the domain I deleted it from AD - replicated almost instantly and it was given a totally different, new name. As for the PC that has now decided to receive GP updates again I've attached its GPO operational events. Can't understand why one minute its receiving them fine and the next minute isn't. I do know though it will stop receiving them!

 

 

GPO_Op.zip

Posted

Hi

 

As a test can you disable the WSUS GPO, then run gpupdate /force.

 

Also, just to confirm is this issue on all the PC's you imaged?

 

Thanks

Sukh

Posted

Hi,

 

Imaged 33 computers running windows 7 pro - all experiencing this problem - intermittently. At the same time also made an image for 35 windows 7 pro laptops so both have the exact same software installed on educational software and office only difference is the laptops use the Windows 7 pro install that requires an existing licence so it was a clean install whereas the PCs which I am having problems with used Windows 7 pro already installed by HP. Could this be the issue? However I can't make either PC now repeat the error but this has happened before last week. Do you believe the WSUS GPO has errors?

 

Thanks

Posted (edited)

Hi

 

Can you configure the following on the GPO and assign to the computer which is having the issue. You may want to create a Test OU and move the the problem computer into this OU and then apply the policy to this Test OU. It seems like most of your settings are in the default domain policy. If this is the case, as many settings as you can and then assign. Set the value to 45s

 

AS A TEST, IT MAY BE BETTER TO ENTER THIS KEY ON THE REG OF THE PROBLEM PC. SEE THE REG KEY BELOW. Create the key if it doesn't exist.

 

Policy Location: Computer Configuration > Policies > Admin Templates > System > Group Policy

Setting Name: Startup policy processing wait time

 

Registry Key: HKLM\Software\Policies\Microsoft\Windows\System!GpNetworkStartTimeoutPolicyValue

 

Thanks

Sukh

Edited by sukh
45s
Posted

Hi

 

I dont believe it has anything to do with the WSUS GPO. I just wanted to rule out GPO's.

 

The Operational Logs indicate connectivity issues.

 

If you run the gpupdate /force, are you able to reproduce?

 

Also, did you try the REG key?

 

Thanks

Sukh

Posted

Hi,

 

Sorry again for the delay. I placed the PC that iv just re-imaged in a test OU along with a GPO that had the setting for the policy wait time and it appears to be working - however it could just be temporary. however I did gpupdate /force and reboot a couple of times and it stayed able to receive the policies.

 

As for the images, sorry its two separate images but the setup of both is identical in terms of software etc on the devices. With the laptops working fine with no issues with receiving GPOs which are the same GPOs as those trying to be sent to the PCs which are not working.

 

Thanks again for all the help!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...