Re: Userenv 1030 + 1006



I have run the gpotool on the server and it brought back a list of DCs and
then a list of GPOs that are applied to the DCs...I assume thats all it is
meant to do. Does that proove anything?

Thanks

"ChrisW (MCP)" wrote:

Hi,

I have checked the SYSVOL share and it does have GUID named folders, I will
try running the tool from the resource kit and see what that shows me

Cheers

"Dave Britt" wrote:

Have you used the GPOTool utility from the resource kit to see if the
SYSVOL's are consistant accross the domain ? Good way to confirm that all of
the policies are available on all DC SYSVOLS.

Dave Britt
Blog: http://davebritt.blogspot.com

"ChrisW (MCP)" <ChrisWMCP@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:9F48FD12-9101-4D02-B636-5829BC11C860@xxxxxxxxxxxxxxxx
Im pretty sure its up all the time, had a new router put in a few days ago
with a better line but the errors have been occuring for ages.

"Darren Mar-Elia (MVP)" wrote:

Could make a difference. Is the VPN up all the time? If not, you may be
experiencing some issues where the DC is not staying in sync with the
rest
of the domain.

--
Darren Mar-Elia
MS-MVP-Windows Server--Group Policy
Check out http://www.gpoguy.com -- The Windows Group Policy Information
Hub:
FAQs, Whitepapers and Utilities for all things Group Policy-related
And, the Windows Group Policy Guide is out from Microsoft Press!!! Check
it
out at http://www.microsoft.com/mspress/books/8763.asp
GPOGUY Blog: http://blogs.dirteam.com/blogs/gpoguy



"ChrisW (MCP)" <ChrisWMCP@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:683A8ED6-6527-42C2-9EB8-1F49C235F291@xxxxxxxxxxxxxxxx
I will check tomorrow, the DC is at a remote site (near to where we are
based
in the UK) that links via VPN to the domain based in Austria. Dont know
if
that makes a difference at all. I'll let you know what I find on the
SYSVOL
directories, cheers.

"Darren Mar-Elia (MVP)" wrote:

Ok. So the DC itself cannot process GP and gets binding errors? Yikes.
That
doesn't sound good. If the DC can't bind to itself that sounds bad.
Are
you
getting any other errors in the AD log or System log? Have you checked
that
SYSVOL is properly shared on that DC? If you look under
SYSVOL\<domain>\policies, do you see a bunch of guid-named folders?



--
Darren Mar-Elia
MS-MVP-Windows Server--Group Policy
Check out http://www.gpoguy.com -- The Windows Group Policy
Information
Hub:
FAQs, Whitepapers and Utilities for all things Group Policy-related
And, the Windows Group Policy Guide is out from Microsoft Press!!!
Check
it
out at http://www.microsoft.com/mspress/books/8763.asp
GPOGUY Blog: http://blogs.dirteam.com/blogs/gpoguy



"ChrisW (MCP)" <ChrisWMCP@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F5992B34-82F9-4B86-93FE-33526C8DBBDB@xxxxxxxxxxxxxxxx
When you say "the client" I dont understand as these errors are
happening
on
one of the DCs and not on any clients as far as I know. I think in
the
1006
event it says windows could not bind to the domain.

Thanks,
Chris

"Darren Mar-Elia (MVP)" wrote:

Chris-
The "manage passwords" thing sounds a bit spurious, if you ask me.
Anyway,
there are probably several things that could cause this, including
firewall
between client and DC, improper DNS config on the client, invalid
machine
account on client. What is the error message in the 1006 event?

Darren

--
Darren Mar-Elia
MS-MVP-Windows Server--Group Policy
Check out http://www.gpoguy.com -- The Windows Group Policy
Information
Hub:
FAQs, Whitepapers and Utilities for all things Group Policy-related
And, the Windows Group Policy Guide is out from Microsoft Press!!!
Check
it
out at http://www.microsoft.com/mspress/books/8763.asp
GPOGUY Blog: http://blogs.dirteam.com/blogs/gpoguy



"ChrisW (MCP)" <ChrisWMCP@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message
news:BA42B896-850C-4F97-8224-FDC5E4AB3A14@xxxxxxxxxxxxxxxx
Hi All,

On one of our DCs we are constantly getting these errors in the
event
log
saying that windows cannot query for GP updates or bidn to the
domain.
I
have
read other posts about this and have researched it and the thing
that
seems
to fix everyones problem is to remove cached credentials from the
"manage
passwords" section of control panel. I have done this and the
server
has
been
rebooted but we still get the errors. Anyone think of anything
else
to
try?

Thanks,
Chris












.



Relevant Pages

  • Re: Userenv 1030 + 1006
    ... If the DC can't bind to itself that sounds bad. ... the Windows Group Policy Guide is out from Microsoft Press!!! ... between client and DC, improper DNS config on the client, invalid machine ...
    (microsoft.public.windows.group_policy)
  • Re: Userenv 1030 + 1006
    ... the Windows Group Policy Guide is out from Microsoft Press!!! ... GPOGUY Blog: http://blogs.dirteam.com/blogs/gpoguy ... between client and DC, improper DNS config on the client, invalid ...
    (microsoft.public.windows.group_policy)
  • Re: Userenv 1030 + 1006
    ... I have checked the SYSVOL share and it does have GUID named folders, ... the Windows Group Policy Guide is out from Microsoft Press!!! ... between client and DC, improper DNS config on the client, invalid ...
    (microsoft.public.windows.group_policy)
  • Re: Userenv 1030 + 1006
    ... the Windows Group Policy Guide is out from Microsoft Press!!! ... between client and DC, improper DNS config on the client, invalid machine ... On one of our DCs we are constantly getting these errors in the event ...
    (microsoft.public.windows.group_policy)
  • Re: 1030
    ... next step...how about enabling verbose userenv logging on that client? ... Then force a gpupdate to capture the processing cycle and see what messages ... The new Windows Group Policy Guide from Microsoft Press!!! ... >> It sounds like the client is having a hard time talking LDAP to the DCs. ...
    (microsoft.public.windows.group_policy)