Re: Group Policy issue and Solution?

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 01/24/05


Date: Mon, 24 Jan 2005 17:55:07 -0600

First I am a bit confused as you say "2 DCs, one of which is a domain
controller" which is contradictory. Anyhow it is possible that one of the
domain controllers was not properly registered in dns or dns was not working
for some reason [dns service hung or stopped], again I am a bit confused
about the setup. Normally you want the first domain controller [ pdc fsmo]
to point to itself and the other domain controller to point to the first dc
and then itself in it's list of preferred dns servers. It is very hard to
say exactly what happened without seeing it before fixing it. At the time of
the problem, running netdiag and dcdiag on both domain controllers would
probably have pinpointed the problem..

I don't know of a way to prevent a user to logon if Group Policy is not
applied but if you have disabled "cached" logons they will not be able to
logon if a domain controller can not be found to authenticate the user.
Group Policies are actually applied to a computer/user based on last logon
if Group Policy can not be refreshed at startup/logon. Any Group Policy
changes since last successful application of Group Policy would not be
implemented of course. --- Steve

"Arby" <XXroger@Blacktech-inc.XXcom> wrote in message
news:usRMDGlAFHA.2104@TK2MSFTNGP14.phx.gbl...
> Hello,
> I recently had an issue with win2000 group policy. I have a customer who
> has 2 DCs, one of which is a domain controller, and both are DNS servers,
> and server1 is also a terminal server ( I know that they should not have
> this config, but they have no choice). Everything was working, but I
> noticed that server1 had a wrong DNS entry, so it was changed to point to
> server 2 (they are both AD integrated DNS). The customer made the change,
> but didn't reboot the server. Shortly thereafter, terminal server users
> started getting Eventid 1000 errors (their group policy was not getting
> applied). It seems the GP could not be found. I also could not edit the
> GP. I rebooted server2, and then everything came back. The GP was
> applied,
> and I could edit it. The confusing issue is that this setup was working
> until we correctly changed the DNS. What in DNS could have caused the GP
> to
> become inaccessible on ALL domain controllers?
>
> The second part of my question is this...is there a setting that I can
> change to NOT allow logons if group policies are not applied? This
> situation caused quite a security issue, and I would like to take the
> necessary precautions. Thanks in advance.
>
> Roger
>
>



Relevant Pages

  • RE: Strange Irregular DNS/Networking Problems
    ... Never heard about this kind of problem with IPv6, but think this is because it is not used so much until now. ... What i heard is that firefox or some other not MS browsers and addons make problems with DNS resolving after changing DNS servers. ... After resetting the domain controller and booting up things are back ...
    (microsoft.public.windows.server.dns)
  • Re: Event Viewer Anomoly
    ... Please give some more infos about the kind of server, Domain controller DNS DHCP etc. and how they are located. ... The topology information in the Active Directory for this replica ... performed with one or more critical servers in order for changes to ...
    (microsoft.public.win2000.networking)
  • Remote Branch DC wont Replicate With Corporate DC
    ... Active Directory could not resolve the following DNS host name of the source ... domain controller to an IP address. ... 'Event' is not recognized as an internal or external command, ... operable program or batch file. ...
    (microsoft.public.windows.server.dns)
  • Re: new domain setup
    ... DCs DNS servers. ... The only services that I usually allow to run on my DCs are DNS and DHCP... ... > Domain Controller for now until I can go get the other machines. ... Boot from CD and do base install. ...
    (microsoft.public.windows.server.setup)
  • Re: Upgrade disaster - I hate that sick in the stomach feeling.
    ... I think your new plan is spot on, espcially with the DNS. ... I have a plethora of servers that refence the IP address of DC1 for DNS ... I test a user and it can't map a drive to the DFS Root share. ... could not be read from the domain controller". ...
    (microsoft.public.windows.server.active_directory)