RE: DCpromo error; Policy problem ??
From: Nwtest (anonymous_at_discussions.microsoft.com)
Date: 04/14/04
- Next message: Kashif Mughal: "How to restrict a domain user to logon on multiple machines at the same time"
- Previous message: Martin: "default GPO not aplied to client admin logon."
- In reply to: Tom Ausburne: "RE: DCpromo error; Policy problem ??"
- Messages sorted by: [ date ] [ thread ]
Date: Wed, 14 Apr 2004 01:03:08 -0700
Hi Tom,
Thanks for being there. I tried the following you mention
especially adding the Enterprise DC, Everyones group in
my default domain controllers policy. restarted all the DC
to make sure that netlogon and secedit applied successfuly
no errors in all of them in event viewer. I then try to
run dcpromo in my member server and I HAVE SAME Problem!
I called our entrprise admins to try the EA account in my
test DC and it works in my child domain.
I dont want to call him every time I want to add a DC.. Is
there any other workaround you know?
Thanks.
NWtest
>-----Original Message-----
>I know you have tried several things so here are a few
far fetched
>ones that I have seen:
>
>Make sure all of your existing domain controllers are
actually in the
>Domain Controllers OU in Active Directory and not in the
Computers OU.
>
>Make sure that the Default Domain Controllers policy is
actually
>linked to the Domain Controllers OU. If not link it and
use secedit
>to push the policy to all DC's in the domain.
>
>Make sure that the computer account for the machine you
are tring to
>promote is actually in the Computers OU.
>
>Add the Everyone Group to the "Enable Computer and User
Accounts to
>be trusted for Delegation" Default Domian Controllers
group policy.
>You might also make sure that Administrators, Domain
Admins and the
>Enterprise Domain Controllers group is added as well.
>
>
>Tom Ausburne (MSFT)
>Windows 2000 Directory Services
>This posting is provided "AS IS" with no warranties, and
confers no
>rights.
>
>
>.
>
- Next message: Kashif Mughal: "How to restrict a domain user to logon on multiple machines at the same time"
- Previous message: Martin: "default GPO not aplied to client admin logon."
- In reply to: Tom Ausburne: "RE: DCpromo error; Policy problem ??"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|