Jump to content

Recommended Posts

Posted

I have a problem where I have users who, when logging into their PC's are being logged off immediately, before even reaching their desktop. This is only affecting users who have roaming profiles and not the local admin account etc and it is not every user of the PC which is affected at anyone time.

 

The user with the problem on one PC can go to another PC which they may have used before and machines which they have never logged on to and the problem may or may not occur there.

 

So far I have removed the local copy of their AD roaming profiles from the PC's affected at the time, however, in X time frame, ranging from hours to days to weeks, the problem re-occurs.

 

Network AD profiles have also be recreated, I.E, brand new AD accounts and the problem still persists.

 

This is occurring on Windows XP SP2 and 3 machines. All have up to date anti-virus and have all be scanned and are clean. Some are brand new OS installations both by hand and from a RAS image as well as older machines which haven't been rebuilt for a while.

 

Has anyone else come across this? My suspicion is a dodgy WSUS update, however, for all the goggling I have done, there seems to be very little information out there about this and what there is, is asking the same question without resolution.

 

 

Thanks,

Posted
@acrobson:

 

How are you removing the local profiles from the PCs (Dumb question I know but there is a motive in asking)?

 

The local AD profiles have been removed both through 'System Properities' > 'Advanced System Settings' > 'User Profiles' as well as by deleting the users profile folder in C:\documents and settings\

 

As for the event logs, there is nothing displayed within there that points to anything of use.

 

Machines hhave been removed and re-added to AD to re-gain trust with the domain as well as a /force update being ran for the GPO.

 

GPO's have been checked, however nothing has changed in recent months in line with this happening, as well as that, not all machines are affected at the same time, it is totally random, with some machines being affected 5-6 times in the same day and others 1-2 times every few weeks.

Posted

Hi

 

I assume you cant reproduce the issue?

Just thinking here, if it was a WSUS update, it would happen on every machine? The only common scenario is that it happens for users with roaming profiles. So if you have a domain user without a profile I assume all work?

 

Sukh

Posted
Hi

 

I assume you cant reproduce the issue?

Just thinking here, if it was a WSUS update, it would happen on every machine? The only common scenario is that it happens for users with roaming profiles. So if you have a domain user without a profile I assume all work?

 

Sukh

 

Failed to replicate the issue to date, local users can logon fine, however, domain user with or without a profile/homedrive seem to be those affected.

Posted

How is the domain user accessing the WIndows XP PC? Interactive logon or across the network.

 

I can only reproduce this issue for a domain user if accessing the a Windows XP machine over the network even if they are in the Remote Desktop users group.

 

Sukh

Posted
How is the domain user accessing the WIndows XP PC? Interactive logon or across the network.

 

I can only reproduce this issue for a domain user if accessing the a Windows XP machine over the network even if they are in the Remote Desktop users group.

 

Sukh

 

Yeah, it's across the network.

Posted

Is your domain user a member of the RDP Desktop users group on the taget machine? Is the domain user a member of the RDP Desktop Users group on a PC which is working?

Still not convinced at this stage, think we have 2 different scenarios's

 

Sukh

Posted
Is your domain user a member of the RDP Desktop users group on the taget machine? Is the domain user a member of the RDP Desktop Users group on a PC which is working?

Still not convinced at this stage, think we have 2 different scenarios's

 

Sukh

 

Not too sure, I shall check on Monday when I'm back in the office. If nothing has changed, why would this suddenly occur?

Posted

Not sure at this stage. Also, even though I cann reproduce the issue, I haven't got a resolution for it.

 

When your user login fails, do you get the applying settings etc...then logging off user....?

 

Sukh

Posted
Not sure at this stage. Also, even though I cann reproduce the issue, I haven't got a resolution for it.

 

When your user login fails, do you get the applying settings etc...then logging off user....?

 

Sukh

 

When the users login, 'Loading Personal Settings' is displayed and then fails to get to 'Applying Personal Settings', the user is then returned to the CTRL-ALT-DEL screen. Cannot be 100% if it displays 'Logging Off' or not as it is that quick. I will double check that on Monday also.

  • 2 months later...
Posted

I had this issue in one of my site, but the culprit was a third party application.

We are using Deep Freeze (from Faronics) and I had it set to reboot the workstation when the user logout.

I don't know if this is a bug or a feature, but it reboots the workstation only when the next user logon and not when login out as intended.

Posted
Sounds like the user is not authenticated to log on to the machine using their domain account. Check the local computer groups and check the users folder to see if your domain\domain users is in there.
Posted
We have had something similar to this, the user may get logged off a blue screen or even the machine restarted. We kept getting winlogon errors when an admin logged into the machine of when the problem occured, we find out it was to do with group policy and we had to recreate the internet settings in gpo this fixed the issue for us - memory a bit vauge will have a look at gpo tomorrow to what we did if you need me to.
Posted
A bit info to my last post I right clicked Internet explorer maintainace under user config in group policy editor and "reset browser settings" and then reented them all again and this seemed to work for us but this was directly related to winlogon errors similar to what you describe. Hope this helps.
Posted
Is your profile server antivirus/malware software on access scanner picking up a problem when loading the profile of the user and then possibly denying access to the affected profile folder? Possibly a setting in the antivirus software to deny access to network shares for that user when a problem is detected?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...