Re: USERENV error - Group Policy



oops, i think you have already tried that.. Could u run a netdiag /v &
pasteit here ?

~Cheers,

Ajay Sarkaria

AJ wrote:
Hi,

This can be anything starting from DNS configuration. I hope you have
already checked it. Try this on the command prompt of the affected
server

DFSUTIL /PURGEMUPCACHE

Then run gpupdate /force to see if you get a 1704

~Cheers,

Ajay Sarkaria

Nadia wrote:
Thanks for your reply Jorge,
-Netlogon and DFS were already started
-Domain controllers have read/apply on DC policy (this policy includes the
correct bypass traverse settings)
-SYSVOL share/NTFS permissions are set correctly (inc. special permissions
and subfolders)
-EventID 1000/1001 is not logged in the App Log.
-DNS records for Domain Controllers is correct
-dfsutil /purgemupcache performed several times with no effect.
-latest SP & latest updates installed.
-I added the WaitForNetwork setting to the registry with no effect
-I've also examined the SMB signing settings, added the registry settings
with no effect.

I've also confirmed it isn't a problem with the policy itself, I've created
new policies all with the same result.

Anything else I should have looked at?


"Jorge Silva" wrote:

Hi
If Domain Controller
*Make sure that the following components are started:
-Netlogon and DFS services are started.
-Domain controllers have the read and apply rights to the Domain Controllers
Policy.
-NTFS file system permissions and share permissions are set correctly on the
Sysvol share.
Event ID 1000, 1001 is logged every five minutes in the Application event
log
http://support.microsoft.com/Default.aspx?id=290647
-DNS entries are correct for the domain controllers
-From cmd, type dfsutil /PurgeMupCache, and then press ENTER.
Make sure that you've the latest Service Pack Installed.
http://support.microsoft.com/kb/889100/
Also take a look ate Registry Change (WaitForNetwork) as described here
Group Policy processing does not work and events 1030 and 1058 are logged in
the Application log of a domain controller
http://support.microsoft.com/kb/842804/en-us
Some situations a warning is also logged in Event Viewer:
Event ID: 3019
Source: MRxSmb
Description: The redirector failed to determine the connection type.
Error message: "The redirector failed to determine the connection type"
http://support.microsoft.com/kb/315244/en-us
-------------------------------------------------
If Clients Windows 2003,Xp,2000:
Applying Group Policy causes Userenv errors and events to occur on your
computers that are running Windows Server 2003, Windows XP, or Windows 2000
http://support.microsoft.com/kb/887303
Group policies are not applied the way you expect; "Event ID 1058" and
"Event ID 1030" errors in the application log
http://support.microsoft.com/kb/314494/en-us
-------------------------------------------------
SBSSmall Business Server 2003 computer
http://support.microsoft.com/kb/888943/en-us
--
*************************************************
I hope that the information above helps you
Good Luck

Jorge Silva

MCSA + Exchange + MSCE
*************************************************

"Nadia" <Nadia@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DE0EFD98-6D0F-47EF-8E90-3485D11ECC7D@xxxxxxxxxxxxxxxx
I'm getting the following error on two of my domain member

servers (both win2k3sp1):

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1058
Date: 6.12.2006
Time: 9:01:57
User: NT AUTHORITY\SYSTEM
Computer: RIVER03
Description:
Windows cannot access the file gpt.ini for GPO

CN={33B07064-3C8C-4337-BD6A-3425D3FB0B18},CN=Policies,CN=System,DC=river,DC=local.
The file must be present at the location
<\\river.local\SysVol\river.local\Policies\{33B07064-3C8C-4337-BD6A-3425D3FB0B18}\gpt.ini>.
(Access is denied. ). Group Policy processing aborted.

I've checked numerous settings as follows:

- that the folder is actually accessible, and the file actually exists
- registry settings on these client machines pertaining to SMB signing:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters
enablesecuritysignature 1
requiresecuritysignature 0
- SMB signing group policy at
Computer Configuration/Windows Settings/Security Settings/Local
Policies/Security Options
- DNS settings
- Permissions on the SYSVOL share
- NetBIOS helper service


Everything appears to be in order, but I'm still getting the USERENV error
either every 1.5 hours or so, or when I force a GP update.

Please help!





.



Relevant Pages

  • Re: Windows Update Error on XP 64bit: update is redirected from v6
    ... Antivir *usually* does not interfere with the installation of core ... Proxycfg settings WORKED. ... Microsoft Windows 2000 Operating System Group Policy Result tool ...
    (microsoft.public.windowsupdate)
  • Re: Windows Update Error on XP 64bit: update is redirected from v6
    ... Proxycfg settings WORKED. ... Microsoft Windows 2000 Operating System Group Policy Result tool ... The user is a member of the following security groups: ...
    (microsoft.public.windowsupdate)
  • Re: USERENV error - Group Policy
    ... -I've also examined the SMB signing settings, ... -Domain controllers have the read and apply rights to the Domain Controllers ... Applying Group Policy causes Userenv errors and events to occur on your ... computers that are running Windows Server 2003, Windows XP, or Windows 2000 ...
    (microsoft.public.windows.server.active_directory)
  • Re: How do I turn off SP2 firewal Group Policy setting
    ... I followed the instructions, but when I go to modify Group Policy, all ... settings are Not Configured Already. ... > Windows XP SP2 client computer in the SBS domain. ... > Firewall for client computers that are running Windows XP Professional. ...
    (microsoft.public.windows.server.sbs)
  • RE: Several Problems; how to reset security and troubleshoot serve
    ... When you tried to launch the Remote assistance, ... On the SBS security settings; I accept your response, ... Both computers must have Windows XP or Windows 2003 installed. ... Start the Microsoft Management Console Group Policy snap-in. ...
    (microsoft.public.windows.server.sbs)