Re: unable to logon to server 2003

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



OK – I did an rsop and check what policies were being applied the problem DC,
and there are none. This is obviously a replication issue because the domain
policies have not replicated to the DC. I did the same rsop check on another
DC and the domain policies define that admins, rdesktop users are allowed to
logon to the DC’s but since no policies are being applied to then DC then it
won’t work – that includes no local logon.

And when I try to force replication I get errors – now this could be because
either theres a problem with the DC itself or the RPC errors we are getting
worldwide at the moment. This is something we are looking into at the moment
to see what traffic is being allowed through the gateways.

This server is behaving very strangely - dns and other stuff will not
install correctly either.

What we've decided to do is demote the DC via dcpromo /forceremoval (because
it wouldn't remove gracefully), remove the metadata, reformat the machine (it
did have a lot of rubbish on it before it became a DC) and do the AD
promotion again.

Thanks,
Taz

"Paul Bergson [MVP-DS]" wrote:

I would be curious to see a ipconfig /all on a good dc and this the failing
dc plus the following:

DCDIAG /V /C /D /E /s:yourdcname > c:\dcdiag.log

Post dcdiag.log

You can change the first couple of octets and the domain name before
posting, just keep things consistent, so it is readable.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"Taz1972" <Taz1972@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C2FBF6A8-13E1-4E5D-8733-A8AE14E2965D@xxxxxxxxxxxxxxxx
Hi,

We recently installed a new 2003 server to act as a DC in one of our
sites.
But once dcpromo was done and a reboot was required, we now cannot logon
and
get the following error:

'unable to logon because of an account restriction'

This is strange because we don't get this problem when logging onto on any
other of our DC's via remote desktop, or any other server for that matter.
Our default domain policy and DC policy is set to 'allow users to logon
through terminal services' for domain admins and remote desktop groups,
and
the deny option is blank.

Furthermore, the "Allow users to remotely connect to this computer"
Remote
Desktop option is grayed out - why is this?? The registry key on the
affected
server is set to

HKLM\System\CurrentControlSet\Control\TerminalServ er\FDenyTSConnections
Set DWord to 0

I am only able to logon to the server using the enterprise admin password,
but if we try to logon as domain admin etc we just cannot - it give the
above
'account restriction' error.

Please can someone shed some light on this, because I have searched the
web
without success, and I am pulling my hair out about this issue.

Thanks,
Taz



.



Relevant Pages

  • Re: Created users cant immediately login
    ... create the replication topology, looks like the best way to go is to set up ... in the remote locations adding them as DC's(NOTE: ... Is the bridgehead server a necessary evil? ... In order for your clients to logon, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Remote Desktop Logon to Server
    ... User Rights assignments under Local Policies. ... > person to logon to the server in a restricted mode. ... > change (this was before I put them into the Administrator ...
    (microsoft.public.win2000.networking)
  • Re: Profile size for local profiles and login delay...
    ... I want it on the server where I can mange/control/delete ... and I want to be able to wipe out a profile/workstation without ... We want them to log on to the domain to be able to run logon scripts ... certain policies and settings when connected to the classroom network ...
    (microsoft.public.windows.server.general)
  • Re: Created users cant immediately login
    ... Do you mean defining the bridgehead server? ... > up a manual replication schedule. ... > each server in the remote locations adding them as DC's(NOTE: ... In order for your clients to logon, ...
    (microsoft.public.windows.server.active_directory)
  • Win2000 DC logon with domain admin account problem
    ... We're actually running 2 DC in a Win2000 level active directory domain. ... Suddenly we're nto able to logon locally to the Win2000 DC, ... investigating the policies, we've seen that in the policies of the win2000 ... server there are s'trange things'. ...
    (microsoft.public.win2000.active_directory)