Re: Unable to promote a new server



That did it Ada. By adding Administrators to that GPO it worked perfectly.

Thanks VERY much.

Joseph

""Ada Pan [MSFT]"" wrote:

Hello Joseph,

The previous reply is actually for another issue. Sorry for the mistake.
Below is the update for this issue:

====================== Start ======================

After re-checking the files, I noticed the Default Domain Controller policy
has been modified with the following user rights assignments removed:

-Enable Computer and User Accounts to be trusted for Delegation
- Add workstations to domain

You may grant the permissions to the built-in Administrators user group and
then reboot the DC to see if you can join the addition server into this
domain. For more information, please refer to the following MS KB article:

232070 When you run Dcpromo.exe to create a replica domain controller, you
receive the "Failed to modify the necessary properties for the machine
account. Access is denied." error message
http://support.microsoft.com/default.aspx?scid=kb;EN-US;232070


If this problem persists after applying the suggestion above, I would like
to recommend that you utilize Windows Server 2003 Default Group Policy
Restore Utility (Dcgpofix.exe) to reset the Default Domain Controller
policy.

NOTE: If you are using GPMC, it is recommended that you use GPMC to backup
all GPOs in your environment. The Dcgpofix tool is a disaster-recovery tool
that will restore your environment to an initial state only. If you use the
Dcgpofix tool, Microsoft recommends that as soon as you run it, you review
the security settings in these GPOs and manually adjust the security
settings to suit your requirements.

For detailed instructions on how to use the Dcgpofix tool, please refer to
the following MS article:

Default Group Policy objects become corrupted: disaster recovery
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/Opera
tions/b9db0ae7-3d25-4e5e-9320-e5db0b0c9f8a.mspx

More Information:
--------------------------
833783 The Dcgpofix tool does not restore security settings in the Default
http://support.microsoft.com/?id=833783

Q267553 How to Reset User Rights in the Default Domain Controllers GPO
http://support.microsoft.com/support/kb/articles/Q267/5/53.ASP

====================== End ======================

Hope this helps!

Regards,

Ada Pan

Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security
====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.


.



Relevant Pages

  • Re: Help with GPO problem! PLEASE!!
    ... How do I create a new GPO? ... I am racking my brain on this problem with a Windows 2003 Standard ... >> Configuration information could not be read from the domain controller, ... Failed to open the Group Policy Object. ...
    (microsoft.public.windows.group_policy)
  • GPOStatus
    ... > guid and select properties/security to see and manage security on a GPO. ... I am racking my brain on this problem with a Windows 2003 Standard ... >> Configuration information could not be read from the domain controller, ... Failed to open the Group Policy Object. ...
    (microsoft.public.windows.group_policy)
  • Re: Help with GPO problem! PLEASE!!
    ... Can you create a new GPO?? ... If so use it to compare permissions to the two ... > Configuration information could not be read from the domain controller, ... Failed to open the Group Policy Object. ...
    (microsoft.public.windows.group_policy)
  • Re: iNTERACTIVE LOGON welcome screen - make it go away
    ... I created a custom ADM file for these two settings ... and imported it into the GPO under the Computer Administritative templates. ... really great expertise in Group Policy often reply to posts including ... doing a gpupdate on that domain controller which ideally would be the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: New Group Policy Using Windows 2000 Snap-in
    ... Also, as a workaround, you can setup GPMC as your group policy managemtn ... This allows you to edit a GPO by focusing on any domain controller you ...
    (microsoft.public.win2000.active_directory)