RE: Intermittent Very Long domain logon time

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi Ray,

I've worked with a few customers on this problem and the most common root
cause is usually a GPO configuration. Particularly, a File System GPO. I
have seen configurations where a GPO was configured to ACL C:\, C:\Windows,
C:\windows\system32, etc. Setting ACLs on this number of files can take a
long time and cause a slow boot. The reason it is so sporadic is that the
Security CSE (Client Side Extension) will reprocess even when no changes
are made to the GPO every 16 hours. If the computer is left on overnight
this will not really affect the user as it will occur in the background and
only cause minor performance issues. However, if the user has shut the PC
down overnight and this 16 hour threshold is exceeded, when the boot up in
the morning the execution of the Security CSE will be required before the
user will be able to complete their logon.

Please review your GPOs for any config similar to mentioned above. Also,
potentially you could look for a large number of registry security
permissions being set although I have not yet seen this cause the symptoms
you have mentioned.

File System and Registry Policies can be found at:
Computer Configuration \ Windows Settings \ Security Settings \ File System
Computer Configuration \ Windows Settings \ Security Settings \ Registry

If this is not the case I would recommend enabling userenv logging on the
machines that are exhibiting the symptoms and wait for the next occurance.
At the next reported occurance collect the userenv.log file for analysis.

Userenv logging is configured by creating a registry key as follows:
Value Path: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Value Name: UserEnvDebugLevel
Value Type: REG_DWORD
Value Data: 10002 (hex)

http://support.microsoft.com/kb/221833


Hope this helps,

Brian Delaney
Microsoft Canada
--

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
Thread-Topic: Intermittent Very Long domain logon time
thread-index: AccwL75MSJ0FAxxUSpycnOvfl1mWBg==
X-WBNR-Posting-Host: 64.109.7.158
From: =?Utf-8?B?Y215YXI=?= <cmyar@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: Intermittent Very Long domain logon time
Date: Thu, 4 Jan 2007 10:40:01 -0800

I have 140 users, XP SP2, connectiong to a W2K domain. Every now and then
a
few users will have horribly long logon times. The long logon only
happens
when logging on after powering on the computer connected to the domain.
After the successful logon if I log that user off and log back in, the
logon
happens in about 3-5 seconds versus 5 minutes. I have Gigabit connections
to
everyones computer, so slow link isn't the issue. The GPO's in place are
applied to the entire domain, so GPO's shouldn't be the problem or
everyone
would be having the same issue. DNS is setup correctly I have verified
that
many times. I have had success (not always though) with unbinding the
computer from the domain and rebinding, I have also had success (again not
always) with flushing the dns resolver cache on the local computer and
restarting. Any suggestions would be very helpful.

Thanks Ray


.



Relevant Pages

  • Re: Group Policy does not take effect
    ... > *ONLY* the Terminal Server machine account should be in this OU, ... > GPO to the TS-OU. ... > On the security filtering of the TS GPO, ... > Configuration part of the TS GPO is applied to the Terminal ...
    (microsoft.public.win2000.termserv.apps)
  • Solaris Security Summary
    ... Administering Security on the Solaris OE ... Configuration control, facility management, and system ... Authentication: The ability to prove who you are. ...
    (comp.unix.solaris)
  • Re: DCOM calls fails - access denied
    ... That's exactly how I understood the ASP.NET security. ... But why does one configuration work but not the other? ... should get the token from IIS. ... If you set there a domain account, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • [TOOL] LogAgent, ASCII Log Monitor
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... LogAgent tries to fill that gap by monitoring the log files on ... for network-wide log file centralization. ... # This program gets its configuration from the file config.txt, ...
    (Securiteam)
  • Re: Security for 64 bit Vista Laptop
    ... Windows Defender is enabled, as is Windows firewall. ... I'd like to address strong security. ... Understanding and Configuring User Account Control in Windows Vista. ... Internet Explorer Enhanced Security Configuration changes the browsing ...
    (microsoft.public.windows.vista.security)