Re: Only 1 computer denied access to DC



Unjoin and rejoin creates a new sid which forces a reset. So go ahead and
give it a try but ishould make no diffrences.

You don't have on the Windows Firewall do you?

--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no rights.

"John Schmidt" <johnaec-nospam-@xxxxxxxxxxx> wrote in message
news:ulamTrGnGHA.2112@xxxxxxxxxxxxxxxxxxxxxxx
Well, netdiag showed no errors at all. The user/computer can authenticate
just fine to that DC, it just can't access any shares or printers on it,
(Access Denied, regardless of user account, even including domain
admins!).
I compared all services and local security policies with a workstation
functioning normally, and no differences. About the only thing left I can
think to try is to reset the computer in Active Directory Users and
Computers, (I've already unjoined the computer from the domain, renamed
it,
and rejoined, all to no avail).

If resetting the computer doesn't do it, I'm just going to flatten the
system and reinstall everything from scratch. BTW - full virus and spyware
scans were also done.

John

"Paul Bergson" <pbergson@xxxxxxxxxxxxxxxxx> wrote in message
news:OKcohQimGHA.4700@xxxxxxxxxxxxxxxxxxxxxxx
run netdiag from the workstation see if you recieve any errors

netdiag /v /l /test:failing_dc_name



If you don't have the tools installed load them from your install disk.

d:\i386\adminpak.msi (Server tools for remote management of servers)
d:\support\tools\setup.exe (Server Utilities)

--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no
rights.

"John Schmidt" <johnaec-nospam-@xxxxxxxxxxx> wrote in message
news:u5Dr9LimGHA.3296@xxxxxxxxxxxxxxxxxxxxxxx
No errors in Event Log at either location.

John

"Paul Bergson" <pbergson@xxxxxxxxxxxxxxxxx> wrote in message
news:uFxGomgmGHA.3752@xxxxxxxxxxxxxxxxxxxxxxx
Are there any errors in any of the event logs related to this
attempted
connection, on either the workstation or the dc?

--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no
rights.

"John Schmidt" <johnaec-nospam-@xxxxxxxxxxx> wrote in message
news:OKbaqBgmGHA.4536@xxxxxxxxxxxxxxxxxxxxxxx
I have about 60 workstations in a WinServer2003R2 Active Directory
network.
All are fine with the exception of one. On this single computer,
even
though
the user can logon to the domain and access most of the network
objects,
(shares, printers, etc.), just fine, when trying to access a
particular
domain controller, it asks for logon credentials, and no matter what
credentials are entered, (full domain admin, etc.), this particular
computer
always receives "Access Denied". No other computers have this
problem.

I suspect it may be a particular Service that's either started or
stopped
on
this computer, but can't figure out which one is responsible. Or
could
it
be
some other security setting? Again - it's workstation specific,
regardless
of the logon at that computer. All others are fine.

Thanks for any ideas or suggestions.

John













.



Relevant Pages

  • Re: Restored from image Cant find DC
    ... Unjoin and rejoin have no influence on the software/data on the computer, ... Check that the ipconfiguration to the domain is correct, try to ping the server via ip address and servername. ... "Meinolf Weber" wrote: ...
    (microsoft.public.windows.server.general)
  • Re: Cannot Logon to Domain, only new PC
    ... >Reset the computer to a workgroup. ... Rejoin the domain. ... >> Any ideas would be great, i've yet to reset the server, ...
    (microsoft.public.win2000.active_directory)
  • Re: Cannot Logon to Domain, only new PC
    ... Once you reset the computer account in AD Users and Computers you have to ... >>the server. ... Rejoin the domain. ...
    (microsoft.public.win2000.active_directory)
  • Re: Server not responding error
    ... If I unjoin and rejoin to the server, how about my old profile(server based ... local profile), If I rejoin can I able to get the same profile(server based ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Win 2K Sever, Win XP Clients, Server died, rebuilt, problems
    ... Do you not know how to remove a computer from a domain and rejoin another ... need to have to rejoin the client machines to the domain. ... Microsoft MVP - Windows NT Server ... > We need to unjoin the previous domain which no longer exists. ...
    (microsoft.public.windows.server.active_directory)

Loading