Re: "Enabling" an already enabled user account?



Thanks for the replies,

I've checked both DCs and there are no replication errors. In fact, I
can disable the account on one machine, connect to the other and what
it disabled, and then enable it from the 2nd and watch it enable on the
first.

The event log errors on the workstation are as follows:

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1058
Date: 1/22/2007
Time: 11:56:13 AM
User: SUTTON\KSmith
Computer: XX29437D
Description:
Windows cannot access the file gpt.ini for GPO
CN={37E1E4C6-9EDB-4A04-99F6-F01159942766},CN=Policies,CN=System,DC=sutton,DC=XXX,DC=XXX.
The file must be present at the location
<\\sutton.ewu.edu\SysVol\sutton.XXX.XXX\Policies\{37E1E4C6-9EDB-4A04-99F6-F01159942766}\gpt.ini>.
(Logon failure: account currently disabled. ). Group Policy processing
aborted.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1030
Date: 1/22/2007
Time: 11:56:13 AM
User: SUTTON\KSmith
Computer: XX29437D
Description:
Windows cannot query for the list of Group Policy objects. A message
that describes the reason for this was previously logged by the policy
engine.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Error
Event Source: AutoEnrollment
Event Category: None
Event ID: 15
Date: 1/22/2007
Time: 11:57:41 AM
User: N/A
Computer: XX29437D
Description:
Automatic certificate enrollment for SUTTON\ksmith failed to contact
the active directory (0x8007052b). Unable to update the password. The
value provided as the current password is incorrect.
Enrollment will not be performed.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Jorge Silva wrote:
Hi
Sounds like an replication issue, check which DC is the user authenticating
and look for replication errors.

--

I hope that the information above helps you.
Have a Nice day.
Jorge Silva
MCSE

<jtgasper3@xxxxxxxxx> wrote in message
news:1169493811.187410.297380@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi,

I'm running a fairly small domain, and have an issue I can't resolve.

I've got a user that tries to access a shares\printers on one of the
domain controllers. She gets the error "Logon failure: account
currently disabled." I look in the AD Users and computers and her
account is active. When I point her to a 2nd DC she can connect with
out issue.

I've tried actually disabling the account and then re-enabling and with
no change? The event log has nothing specific to the cause, just some
symptomatic stuff like it can't process GPO. The only difference
between the the day she could log in and the next when she couldn't is
that several Office product updates occured that night.

I should mention that other users can log into the affected workstation
and then connect to the shares on both DCs with out incident.

Does anyone have any ideas?

Thanks.


.



Relevant Pages

  • Re: "Enabling" an already enabled user account?
    ... check which DC is the user authenticating and look for replication errors. ... domain controllers. ... She gets the error "Logon failure: account ... I've tried actually disabling the account and then re-enabling and with ...
    (microsoft.public.windows.server.active_directory)
  • Re: Audit Trail of AD account
    ... The disabling will be logged in the Event Log. ... > When the administrator disable an account in Active Directory. ...
    (microsoft.public.windows.server.active_directory)
  • Re: "Enabling" an already enabled user account?
    ... which event IDs with error are mentioned in the event log? ... are the DCs replicating? ... She gets the error "Logon failure: account ... I've tried actually disabling the account and then re-enabling and with ...
    (microsoft.public.windows.server.active_directory)
  • Disabled account causes error 1022
    ... If I disable an account in AD, the event log fills up with error 1022 ... "Logon failure on database..". ... disabling an account impractical. ...
    (microsoft.public.exchange2000.general)
  • RE: Scavanging retired machine accounts
    ... Here's a script I wrote a while back that does exactly what you want. ... 'pull back a list of every user's account name and distinguished name ... we're probably only interested in the disabled computer accounts ... 'There is no point disabling PCs based on how many weeks it's been since the ...
    (microsoft.public.windows.server.scripting)