Re: GPO testing




Hi Florian,

To answer Toni's question, I did log in as one of the users in the test OU. There are lots of messages in the event log but they are all information messages (no errors).

This output is from the tail of the userenv.log :

USERENV(e4.90) 16:55:07:843 MyRegUnLoadKey: Hive unload for S-1-5-21-4033885032-1064338026-362975531-500 failed due to open registry key. Windows will try unloading the registry hive once a second for the next 60 seconds (max).
USERENV(e4.90) 16:56:07:859 MyRegUnLoadKey: Windows was not able to unload the registry hive.
USERENV(e4.90) 16:56:07:859 MyRegUnLoadKey: Failed to unmount hive 5
USERENV(e4.90) 16:56:07:859 UnloadUserProfile: Didn't unload user profile <err = 5>
USERENV(e4.90) 16:56:07:859 DumpOpenRegistryHandle: 2 user registry Handles leaked from \Registry\User\S-1-5-21-4033885032-1064338026-362975531-500
USERENV(e4.90) 17:03:02:515 Profile was loaded but the Ref Count is 1 !!!
USERENV(e4.90) 17:09:14:875 MyRegUnLoadKey: Hive unload for S-1-5-21-4033885032-1064338026-362975531-500 failed due to open registry key. Windows will try unloading the registry hive once a second for the next 60 seconds (max).
USERENV(e4.90) 17:10:14:875 MyRegUnLoadKey: Windows was not able to unload the registry hive.
USERENV(e4.90) 17:10:14:875 MyRegUnLoadKey: Failed to unmount hive 5
USERENV(e4.90) 17:10:14:875 UnloadUserProfile: Didn't unload user profile <err = 5>
USERENV(e4.90) 17:10:14:875 DumpOpenRegistryHandle: 2 user registry Handles leaked from \Registry\User\S-1-5-21-4033885032-1064338026-362975531-500
USERENV(e4.90) 17:47:45:593 Profile was loaded but the Ref Count is 1 !!!
USERENV(e4.90) 18:23:30:531 MyRegUnLoadKey: Hive unload for S-1-5-21-4033885032-1064338026-362975531-500 failed due to open registry key. Windows will try unloading the registry hive once a second for the next 60 seconds (max).
USERENV(e4.90) 18:24:30:531 MyRegUnLoadKey: Windows was not able to unload the registry hive.
USERENV(e4.90) 18:24:30:531 MyRegUnLoadKey: Failed to unmount hive 5
USERENV(e4.90) 18:24:30:531 UnloadUserProfile: Didn't unload user profile <err = 5>
USERENV(e4.90) 18:24:30:531 DumpOpenRegistryHandle: 2 user registry Handles leaked from \Registry\User\S-1-5-21-4033885032-1064338026-362975531-500
USERENV(e4.90) 18:59:53:078 MyRegUnLoadKey: Hive unload for S-1-5-21-4033885032-1064338026-362975531-500 failed due to open registry key. Windows will try unloading the registry hive once a second for the next 60 seconds (max).
USERENV(e4.90) 19:00:53:093 MyRegUnLoadKey: Windows was not able to unload the registry hive.
USERENV(e4.90) 19:00:53:093 MyRegUnLoadKey: Failed to unmount hive 5
USERENV(e4.90) 19:00:53:093 UnloadUserProfile: Didn't unload user profile <err = 5>
USERENV(e4.90) 19:00:53:093 DumpOpenRegistryHandle: 2 user registry Handles leaked from \Registry\User\S-1-5-21-4033885032-1064338026-362975531-500
USERENV(e4.90) 14:16:45:812 MyRegUnLoadKey: Hive unload for S-1-5-21-4033885032-1064338026-362975531-500 failed due to open registry key. Windows will try unloading the registry hive once a second for the next 60 seconds (max).
USERENV(e4.90) 14:17:45:828 MyRegUnLoadKey: Windows was not able to unload the registry hive.
USERENV(e4.90) 14:17:45:828 MyRegUnLoadKey: Failed to unmount hive 5
USERENV(e4.90) 14:17:45:828 UnloadUserProfile: Didn't unload user profile <err = 5>
USERENV(e4.90) 14:17:45:828 DumpOpenRegistryHandle: 2 user registry Handles leaked from \Registry\User\S-1-5-21-4033885032-1064338026-362975531-500
USERENV(e4.90) 08:43:40:234 Profile was loaded but the Ref Count is 1 !!!
USERENV(e4.90) 13:41:59:421 MyRegUnLoadKey: Hive unload for S-1-5-21-4033885032-1064338026-362975531-500 failed due to open registry key. Windows will try unloading the registry hive once a second for the next 60 seconds (max).
USERENV(e4.90) 13:42:59:421 MyRegUnLoadKey: Windows was not able to unload the registry hive.
USERENV(e4.90) 13:42:59:421 MyRegUnLoadKey: Failed to unmount hive 5
USERENV(e4.90) 13:42:59:421 UnloadUserProfile: Didn't unload user profile <err = 5>
USERENV(e4.90) 13:42:59:421 DumpOpenRegistryHandle: 2 user registry Handles leaked from \Registry\User\S-1-5-21-4033885032-1064338026-362975531-500
USERENV(e4.90) 13:44:20:140 Profile was loaded but the Ref Count is 1 !!!
USERENV(e4.74c) 15:34:38:515 ProcessGPOs: DSGetDCName failed with 2146.
USERENV(e4.a50) 15:40:00:234 ProcessGPOs: DSGetDCName failed with 2146.
USERENV(e4.74c) 15:40:18:515 ProcessGPOs: DSGetDCName failed with 2146.
USERENV(e4.74c) 15:45:58:515 ProcessGPOs: DSGetDCName failed with 2146.
USERENV(e4.90) 19:07:31:375 MyRegUnLoadKey: Hive unload for S-1-5-21-4033885032-1064338026-362975531-500 failed due to open registry key. Windows will try unloading the registry hive once a second for the next 60 seconds (max).
USERENV(e4.90) 19:08:31:375 MyRegUnLoadKey: Windows was not able to unload the registry hive.
USERENV(e4.90) 19:08:31:375 MyRegUnLoadKey: Failed to unmount hive 5
USERENV(e4.90) 19:08:31:375 UnloadUserProfile: Didn't unload user profile <err = 5>
USERENV(e4.90) 19:08:31:375 DumpOpenRegistryHandle: 2 user registry Handles leaked from \Registry\User\S-1-5-21-4033885032-1064338026-362975531-500
USERENV(e4.90) 05:29:58:968 Profile was loaded but the Ref Count is 1 !!!
USERENV(e4.90) 13:21:43:062 MyRegUnLoadKey: Hive unload for S-1-5-21-4033885032-1064338026-362975531-500 failed due to open registry key. Windows will try unloading the registry hive once a second for the next 60 seconds (max).
USERENV(e4.90) 13:22:43:062 MyRegUnLoadKey: Windows was not able to unload the registry hive.
USERENV(e4.90) 13:22:43:062 MyRegUnLoadKey: Failed to unmount hive 5
USERENV(e4.90) 13:22:43:062 UnloadUserProfile: Didn't unload user profile <err = 5>
USERENV(e4.90) 13:22:43:062 DumpOpenRegistryHandle: 2 user registry Handles leaked from \Registry\User\S-1-5-21-4033885032-1064338026-362975531-500

The messages in the event log are all Event ID:1000 information and it contains messages like this :

Event Type: Information
Event Source: Userenv
Event Category: None
Event ID: 1000
Date: 10/18/2006
Time: 11:14:01 AM
User: NT AUTHORITY\SYSTEM
Computer: JRCNAV
Description:
Windows did not apply extension Application Management, and flags are (0x90007).

Lots of stuff like with "Windows did not apply ..." and then ", and flags are (0x90007)"

Any ideas?

Best,
Scott

Florian Frommherz wrote:
Howdie Scott!

Scott wrote:
Working on W2K server. Right now the DDP and DDCP are set to the default settings. Set up a test OU and a test GPO. Linked the GPO to the OU and refreshed the user and machine policy with secedit. The test GPO does not get applied. Only the DDP is showing up as applied. Went through a file from Microsoft on how to debug Group Policy issues and set up a bunch of extended logging but nothing seems to be failing to as to indicate why the test GPO I set up is not be applied. What is the best way to drill down into this problem? Since the DDP is applied there must be some kind of failure. How can I find out more about what is going on?

In addition to Toni's help, I'd like you to post your "extended logging" output to see if we can find you're problem there.

As you wrote you put user accounts into the OU you linked the policy to - did you define User Configuration options? If you still have no clue, try to go through the steps I posted here:

http://www.frickelsoft.net/blog/?p=9

cheers,

Florian
.



Relevant Pages

  • Re: Suspicious UserEnv Error
    ... USERENV10:46:53:859 MyRegUnLoadKey: Windows was not able to unload ... USERENV10:46:53:859 UnloadUserProfile: Didn't unload user profile ...
    (microsoft.public.win2000.general)
  • Windows logoff bug possible security vulnerability and exploit.
    ... Windows XP, Windows Server 2003 ... I believe that it is the purpose of the OS to provide the appropriate security and the purpose of a program to do it's task and not implement the security of the OS. ... The security problem I'm discussing occurs when a user profile fails to unload during logoff. ...
    (Bugtraq)
  • Re: GPO testing
    ... Howdie Scott! ... USERENV16:56:07:859 MyRegUnLoadKey: Windows was not able to unload the registry hive. ...
    (microsoft.public.windows.group_policy)
  • Re: Notification of WIndows Shutdown.
    ... application derived shutdown. ... The Unload statement is invoked from code. ... The current Microsoft Windows operating environment session is ending. ... The Microsoft Windows Task Manager is closing the application. ...
    (microsoft.public.vb.general.discussion)
  • Re: Notification of WIndows Shutdown.
    ... application derived shutdown. ... The Unload statement is invoked from code. ... The current Microsoft Windows operating environment session is ending. ... The Microsoft Windows Task Manager is closing the application. ...
    (microsoft.public.vb.general.discussion)