RE: URGENT - Domain Lockout

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Little more info:
Forest and Domain Functionality Level: 2003 (all boxes run Win 2003).
Domain GPO Cached Logons: 0

--
John


"JT" wrote:

> Hi,
> I hope someone can help me with this one! I am running a Win2003/SP1
> domain. After having successfully installed a failover cluster, I was using
> RDC from home to do some locking down with group policy. I made the grave
> error of changing several of the LDAP signing requirements and locking down
> the LAN Manager Authentication Level in the DOMAIN policy while leaving much
> of this undefined in the DC policy. I immediately started seeing NTLM errors
> logged, and any attempt to reverse things with gpupdate failed due to
> authentication errors. Then I did something even more stupid - I left my
> desktop long enough to require logon. Needless to say, logon is failing.
> There is no one else with an open connection to the domain that would allow
> me to try registry manipulation.
> Any clue as to how to resolve this? I am desperate right about now!
> Thanks
> --
> John
.



Relevant Pages

  • RE: URGENT - Domain Lockout
    ... John ... >> RDC from home to do some locking down with group policy. ... >> the LAN Manager Authentication Level in the DOMAIN policy while leaving much ... Needless to say, logon is failing. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
    (microsoft.public.windows.server.sbs)
  • RE: Event ID 537 and Kerberos
    ... a logon type of 3 translates to Network. ... Click Services tab and select Hide All Microsoft Services and Disable ... Step 4: Configure account lockout policy. ... and then click Account Lockout Policy. ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote Client Configuration
    ... Thanks for quickly updates. ... Just as I know, if you only logon the domain with cache credential, the ... group policy will not be updates, instead it will use the old policy that ... dial up VPN connection to logon SBS domain once-in-a-while for the group ...
    (microsoft.public.windows.server.sbs)
  • RE: Remote Desktop not working after SP1
    ... "The local policy does not permit you to logon interactively" error message ... Remote Desktop Users ... Use the ISAinfo utility to collect the ISA configuration information: ...
    (microsoft.public.windows.server.sbs)