Rebooting would fix it for a random amount of time, sometimes for hours and sometimes only for minutes. There is a corresponding warning EventID 40961 from source LsaSrv in the System log. Finally, I dropped to a command prompt and found this Do you see it? No, I don't mean my horrible "coloring job" - I mean the Junction pointing to C:\Winnt\path... About Twitter Updates follow me on Twitter Subscribe to this blog's feed Categories Active Directory Blackberry Cisco Current Affairs Exchange Faith Family Leadership Lync Mac Networking Office Random Server 2008 Solarwinds useful reference
Other posts from Microsoft engineer suggest that if a domain controller is multi-homed (more than 1 network card) they may experience this problem (note that "network card" could mean a physical Solved DC cannot query list of Group Policy Objects Event ID: 1030 and 1058 in Userenv Posted on 2012-06-29 Windows Server 2003 Active Directory 2 Verified Solutions 5 Comments 3,767 Views x 88 Anonymous In my case, it turned out that the problem here was the share permission for ''NT AUTHORITY\SYSTEM'' was missing on the SYSVOL share. Recent Comments Kristen on On Making Hard Decisions J5 on On Making Hard Decisions Don H on Dell PowerConnect + RADIUS + Windows Server 2008 NPS Ryan Hermann on Passionate about https://support.microsoft.com/en-us/kb/887303
A data value of 0 means that the client is turned on. What is the role of Userenv? I don't really know why this would effect some logons, and not others, but it did work for us.
I activated the access on this DC and the problem was fixed. I'll reboot it tonight and see if the errors come back at all. 0 LVL 38 Overall: Level 38 Windows Server 2003 33 Active Directory 17 Message Accepted Solution by:ChiefIT2012-07-03 Updating the network driver on the host machine clears up the error. Dfsutil /purgemupcache See ME839499 to fix this problem.
The error stopped within five minutes on the DCs. Windows Cannot Access The File Gpt.ini For Gpo 1058 TECHNOLOGY IN THIS DISCUSSION Join the Community! x 1 Rolf A. you could try here From a newsgroup post: "I connected to the Sysvol share as the current user (non- administrator), and noticed that I could get into "mydomain" directory, but when I tried to get
FIXWMI.CMD ------------------------ @echo on cd /d c:\temp if not exist %windir%\system32\wbem goto TryInstall cd /d %windir%\system32\wbem net stop winmgmt winmgmt /kill if exist Rep_bak rd Rep_bak /s /q rename Repository Rep_bak Kb840669 Replacing the permissions on all subdirectories with those of \WINNT\SYSVOL solved the problem for me. I could view \\dcname\anyothershare but not \\dcname\sysvol. x 3 Anonymous I was able to correct this problem by changing the NIC's Advanced TCPIP\NetBIOS settings from "Enable NetBIOS over TCP/IP" to the new "Default" option in Win2k3.
The posts also indicate that the Client for Microsoft Networks and the File and Printer Sharing services have to be bound to the network adapter. From a newsgroup post: "I had the 1030 and 1058 errors in the event log every 5 minutes on a W2K3 domain controller that also ran DNS, DHCP, Exchange 2003 Standard, Windows Cannot Access The File Gpt.ini For Gpo About Advertising Privacy Terms Help Sitemap × Join millions of IT pros like you Log in to Spiceworks Reset community password Agree to Terms of Service Connect with Or Sign up Kb885887 In other words, your hosts file should look like this (if you have just two domain controllers):
x 2 Paul Cocker The event was occurring in combination with EventID 1030 from source Userenv and was referencing a GPO that existed on the PDC but not on the other see here from the command line. Running nslookup showed me the extra invalid record for the domain. In our case, it helped to upgrade VMWare Tools on our virtualized Domain Controller (Win 2003 SP2). Windows Cannot Access The File Gpt.ini For Gpo Cn= 31b2f340-016d-11d2-945f-00c04fb984f9
When I tried to open the default domain policy, I received several pop-ups: "There is an inconsistency between the GPO Object in SYSVOL and Active Directory. x 4 Jack Brasher I am running Windows XP Pro SP2 in an SBS 2003 Domain. There is a workaround or a maintenance release that will fix the problem. http://introbuilder.net/windows-cannot/windows-xp-userenv-error.php It happened after I moved the DC from a Virtual Server to Hyper-V and it received new network card drivers.
x 84 Anonymous A combination of event 1030, 1058, and 4015 can occur when a NIC is replaced and the binding order is wrong. Event Id 1030 Group Policy Failed Perform the following troubleshooting steps as per the article: 1. x 4 Richard Righart van Gelder This error started on Monday after rebooting our SBS2003 server.
x 48 Chris A The netlogon share was ok but not the Sysvol share. Custom search for *****: Google - Bing - Microsoft - Yahoo Feedback: Send comments or solutions - Notify me when updated Printer friendly Subscribe Subscribe to EventID.Net now!Already a subscriber? x 3 EventID.Net See ME842804 for a hotfix applicable to Microsoft Windows 2000 and Microsoft Windows Server 2003. Windows Cannot Access The File Gpt.ini For Gpo Access Is Denied The problem seems to be related to the background group policy refresh failing if the user has locked the workstation.
I would add that it is probably best practice to export any registry key that is about to be deleted to a ".reg" file. For more information on this issue, check pages 10 & 11 of this document “Symantec Endpoint Protection 11.0 - SBS 2003 Best Practices White Paper”. Enable this Group Policy and allow it to replicate to all computers involved. Get More Info Office 365 Active Directory Exchange Azure Transferring Active Directory FSMO Roles to a Windows 2012 Domain Controller Video by: Rodney This tutorial will walk an individual through the process of transferring
This combination resolved my issues. I removed the lingering entries for the old server from DNS and restarted the DNS service. x 1 Daniel Wilson On my dual-homed Windows Server 2003, this error started to appear after I had removed “Client for Microsoft Networks” and “File and Print Sharing” from the external I fixed the problem by running DCGPOFIX on the Win2k3 server followed by a reboot.
I did the usual stuff. I asked Dr. All rights reserved.Unauthorized reproduction or linking forbidden without expressed written permission. x 6 EventID.Net See ME842804 for a hotfix applicable to Microsoft Windows 2000 and Microsoft Windows Server 2003. However, after a while I discovered I was having all sorts of Group Policy application errors on my Windows XP workstation in my Windows 2000 domain.
The server had two NICs, one of which was normally unused and disabled. See example of private comment Links: EventID 675 from source Security, EventID 1097 from Userenv, EventID 1058 from Userenv, Dcgpofix, EventID 40960 from source LsaSrv, EventID 40961 from source LsaSrv, EventID This fixed the issue in my case. Cancel Red Flag SubmittedThank you for helping keep Tek-Tips Forums free from inappropriate posts.The Tek-Tips staff will check this out and take appropriate action.
Also, while working through this I discovered that besides the already cool "Resultant Set of Policy" MMC snap-in in Windows XP, there is also a "GPUPDATE" command in Windows XP which, Then log in as the user. 2) Upgrade McAfee to 8.5i. 3) Remove QoS from networking. 4) Make user administrator of local machine. Microsoft network server: Digitally sign communications (always) Disabled Microsoft network server: Digitally sign communications (if client agrees) Disabled To see these settings on a workstation go to Start -> Settings Apparently this has changed since Windows 2000.
For example, if you have the domain "mydomain.local" you have to edit the hosts file on each DC as follows: mydomain.local 10.0.0.1 # local DC mydomain.local 10.0.0.2 # second DC mydomain.local If it doesn't use a sledgehammer..." RE: Event ID 1030 crmayer (Programmer) (OP) 18 Sep 08 12:48 Instead of attaching the file I just typed the event id in the second If another user logged in on that same machine, no errors appeared and all policies were applied. Windows 2000 Server and Windows Server 2003 do not distinguish between non-ASCII and ASCII characters in account names.