Re: Error binding to local domain



"Lanwench [MVP - Exchange]" wrote:

>
>
> In news:2E7C8934-DBF1-47BE-9EA2-D2947D7C1799@xxxxxxxxxxxxx,
> Steve Larson <SteveLarson@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
> > I am receiving an error in the event log when I try to resolve a
> > domain user name on a client machine (i.e. add a domain user to the
> > permissions on a folder or add domain user to a group) when
> > authenticating as the domain administrator. The permissions dialog
> > just times out trying to resolve the user. The machine is a member
> > of the domain, has XP SP2 installed, and has allowed the same type of
> > permissions updates in the past. The user name is able to be
> > resolved when authenticating as another domain user.
> >
> > This is the message in the client event log. "Windows cannot bind to
> > [MyLocalDomain].local domain. (Local Error). Group Policy processing
> > aborted." Source: Userenv, EventID: 1006 and is always followed by
> > the following event "Windows cannot query for the list of Group
> > Policy objects. A message that describes the reason for this was
> > previously logged by the policy engine." Source: Userenv, EventID:
> > 1030.
> >
> > I have dropped a machine to a workgroup and rejoined it to the domain
> > but
> > get the same results.
> >
> > I did not find a machine personal certificate listed in MMC. When I
> > try to add a certificate, I received an error dialog stating that the
> > wizard could not be started because Active Directory could not be
> > contacted. The [MyLocalDomain] Root Certificate Authority and the
> > [DomainController].[MyPublicDomain] are listed in the Certificates for
> > Trusted Root Certification Authorities. (All this as logged in as
> > domain administrator).
> >
> > I have pasted the help and Support link text at the end of this but
> > nothing seemed to be much help there (I was not able to get the
> > Win2000 netdiag tool to run.)
> >
> > I have also pasted part of the client machine logfile for userenv at
> > the end.
> >
> > Any ideas on where else to troubleshoot?
> >
> > Steve
> <snip>
>
> Just a sanity check - is the *only* DNS server you have on the client, the
> LAN IP address of your SBS server?
>
> If not, make it so. If so, if you run
>
> gpresult
>
> from a command line, what do you see?
> If you try
>
> gpupdate /force
>
> does it help?
>
>
>
This is the result of 'gpresult', 'gpupdate /force', and 'gpresult'. The
behavior has not changed. (It looks like I need to do some research and
maybe a follow up post on GP :>)
C:\Documents and Settings\administrator.MYDOMAIN>gpresult

Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001

Created On 8/14/2005 at 8:08:20 PM


RSOP results for MYDOMAIN\administrator on MUSIC1 : Logging Mode
------------------------------------------------------------------------

OS Type: Microsoft Windows XP Professional
OS Configuration: Member Workstation
OS Version: 5.1.2600
Domain Name: MYDOMAIN
Domain Type: Windows 2000
Site Name: Default-First-Site-Name
Roaming Profile:
Local Profile: C:\Documents and Settings\administrator.MYDOMAIN
Connected over a slow link?: No


COMPUTER SETTINGS
------------------
CN=MUSIC1,OU=Staff
Desktop,OU=SBSComputers,OU=Computers,OU=MyBusiness,DC=MyDomain,DC=local
Last time Group Policy was applied: 8/14/2005 at 7:56:06 PM
Group Policy was applied from: dc1.MyDomain.local
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
-----------------------------
AutoUpdateViaSUS
AutoWindowsUpdate
Small Business Server Windows Firewall
Small Business Server Client Computer
Small Business Server Domain Password Policy
Small Business Server Remote Assistance Policy
Small Business Server Lockout Policy
Default Domain Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Internet Connection Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PreSP2

AV
Filtering: Disabled (GPO)

Full Software
Filtering: Disabled (GPO)

Local Group Policy
Filtering: Not Applied (Empty)

The computer is a part of the following security groups:
--------------------------------------------------------
BUILTIN\Administrators
Everyone
Debugger Users
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
MUSIC1$
Domain Computers
CERTSVC_DCOM_ACCESS


USER SETTINGS
--------------
CN=Administrator,CN=Users,DC=MyDomain,DC=local
Last time Group Policy was applied: 8/14/2005 at 8:05:05 PM
Group Policy was applied from: dc1.MyDomain.local
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
-----------------------------
Default Domain Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Internet Connection Firewall
Filtering: Not Applied (Empty)

Small Business Server Lockout Policy
Filtering: Disabled (GPO)

Small Business Server Windows Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PostSP2

Small Business Server Remote Assistance Policy
Filtering: Disabled (GPO)

Local Group Policy
Filtering: Not Applied (Empty)

Small Business Server Client Computer
Filtering: Not Applied (Empty)

Small Business Server Domain Password Policy
Filtering: Not Applied (Empty)

The user is a part of the following security groups:
----------------------------------------------------
Domain Users
Everyone
Debugger Users
BUILTIN\Users
BUILTIN\Administrators
Group Policy Creator Owners
Domain Admins
SBS Internet Users
SBS Report Users
Schema Admins
Enterprise Admins
SBS Mobile Users
LOCAL
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users

C:\Documents and Settings\administrator.MYDOMAIN>gpupdate /force
Refreshing Policy...

User Policy Refresh has completed.
Computer Policy Refresh has completed.


C:\Documents and Settings\administrator.MYDOMAIN>gpresult

Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001

Created On 8/14/2005 at 8:13:29 PM


RSOP results for MYDOMAIN\administrator on MUSIC1 : Logging Mode
------------------------------------------------------------------------

OS Type: Microsoft Windows XP Professional
OS Configuration: Member Workstation
OS Version: 5.1.2600
Domain Name: MYDOMAIN
Domain Type: Windows 2000
Site Name: Default-First-Site-Name
Roaming Profile:
Local Profile: C:\Documents and Settings\administrator.MYDOMAIN
Connected over a slow link?: No


COMPUTER SETTINGS
------------------
CN=MUSIC1,OU=Staff
Desktop,OU=SBSComputers,OU=Computers,OU=MyBusiness,DC=MyDomain,DC=local
Last time Group Policy was applied: 8/14/2005 at 8:12:05 PM
Group Policy was applied from: dc1.MyDomain.local
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
-----------------------------
AutoUpdateViaSUS
AutoWindowsUpdate
Small Business Server Windows Firewall
Small Business Server Client Computer
Small Business Server Domain Password Policy
Small Business Server Remote Assistance Policy
Small Business Server Lockout Policy
Default Domain Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Internet Connection Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PreSP2

AV
Filtering: Disabled (GPO)

Full Software
Filtering: Disabled (GPO)

Local Group Policy
Filtering: Not Applied (Empty)

The computer is a part of the following security groups:
--------------------------------------------------------
BUILTIN\Administrators
Everyone
Debugger Users
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
MUSIC1$
Domain Computers
CERTSVC_DCOM_ACCESS


USER SETTINGS
--------------
CN=Administrator,CN=Users,DC=MyDomain,DC=local
Last time Group Policy was applied: 8/14/2005 at 8:12:05 PM
Group Policy was applied from: dc1.MyDomain.local
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
-----------------------------
Default Domain Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Internet Connection Firewall
Filtering: Not Applied (Empty)

Small Business Server Lockout Policy
Filtering: Disabled (GPO)

Small Business Server Windows Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PostSP2

Small Business Server Remote Assistance Policy
Filtering: Disabled (GPO)

Local Group Policy
Filtering: Not Applied (Empty)

Small Business Server Client Computer
Filtering: Not Applied (Empty)

Small Business Server Domain Password Policy
Filtering: Not Applied (Empty)

The user is a part of the following security groups:
----------------------------------------------------
Domain Users
Everyone
Debugger Users
BUILTIN\Users
BUILTIN\Administrators
Group Policy Creator Owners
Domain Admins
SBS Internet Users
SBS Report Users
Schema Admins
Enterprise Admins
SBS Mobile Users
LOCAL
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users

C:\Documents and Settings\administrator.MYDOMAIN>

.



Relevant Pages

  • RE: Software Distribution fails with source not available.
    ... Since you distribute MSI's using Group Policy - Computer ... You even don't need to logon the domain with a domain user account to apply ... Did the information provided resolve your further query? ... Microsoft Online Partner Support ...
    (microsoft.public.windows.group_policy)
  • Re: GPO not working!
    ... My intuition says it has something to do with ACLs in your AD or SYSVOL (had ... > Connected over a slow link?: ... > Group Policy was applied from: ... > Applied Group Policy Objects ...
    (microsoft.public.windows.server.active_directory)
  • Re: Installs and Such
    ... I assume that the clients are ... Make sure that the domain user account object is not a member of the ... Use Group Policy to not allow them to install certain applications. ...
    (microsoft.public.win2000.active_directory)
  • Re: Local Group Membership not Persistent
    ... I guess you can tell I am new to Group Policy? ... > It sounds like there might be a restricted group policy being applied to ... > selecting domain user group or role, ... The default AD Group Policy settings are all 'not ...
    (microsoft.public.win2000.group_policy)
  • Re: Folder Security tab missing
    ... Windows 2003 domain controller to see if that domain user has restrictions ... via a Group Policy. ... Group Policy applying the restriction does not apply to the user. ... can see security tab. ...
    (microsoft.public.security)