Nope, thats for another pair of events not my pair.
Main Topics
Browse All TopicsOn a newly demoted then promoted DC!
Event ID: 1030
Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.
Event ID: 1006
Windows cannot bind to ebs.com domain. (Local Error). Group Policy processing aborted.
__________________________
Many things have been tried, to include a demotion and re-promotion of one of our 2 DC's, but this error will not go away on the promoted DC. This error existed before it got demoted, and now exists EVEN after re-promoted! How can I fix THIS!
FOR 2000 pts... GET these erros\issue gone\fixed for me!
Netdiag shows all passed or skipped, but no failures
In the "userenv.log" I do find a few issues on our newly promoted DC.
USERENV(370.be0) 11:57:10:859 ProcessGPOs: Processing failed with error 8341.
USERENV(370.be0) 11:57:10:849 ProcessGPOs: GetGPOInfo failed.
USERENV(370.be0) 11:57:10:829 GetGPOInfo: ldap_bind_s failed with = <82>
I've read where demoting\promoting has cause similar errors, I have tried a fix once that work until I tried a non authoritative restore, then it never fixed again after these event ID erros came back to haunt me. Tried deleting all sorts of logs once that worked but this has never worked again.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
It's for the 1030, at least :)
But check this one also : " http://www.experts-exchang
Best Regards !
I'm sure you saw this already...but here are some ideas:
Last update 10/11/2005):
In my case, the event appeared on a Windows 2003 server after we changed the domain admin password. All services had correctly been changed, but the console was logged on during the password change. A simple logoff-logon solved the problem.
James (Last update 6/28/2005):
My issues on this event were caused by cached credentials on the client. They were not showing up when I logged in as Administrator (Tristen and Sean below had issues related to this, but were able to find and delete the offending credentials). Rob's comments under EventID 14 from source Kerberos, about client credentials not appearing were very helpful in pointing me in the right direction to solve my issue. Instead of deleting and re-adding the computer & account, etc. from the domain as he did, I just temporarily gave the affected user administrative privileges and was able to find the stored user name info when I logged in as that user. Go to Start -> Control Panel -> User Accounts -> Advanced tab -> Manage Passwords. Note that you cannot go in to this area without Admin privileges and you cannot see them when you are logged in as another user. Once I found and deleted the stored credentials, I removed admin privileges and was able to log in normally without the authentication problems.
Brad Albert (Last update 6/14/2005):
We were getting this along with event 1030, on two SQL servers; both errors started on the same day and were associated with the same user. It turned out that the database administrator had left herself logged on to both SQL servers and then changed her password. We simply logged her off and the error was gone.
Ionut Marin (Last update 6/14/2005):
As per Microsoft: "An Active Directory, network connectivity, or network configuration problem prevents Group Policy settings from being applied. Group Policy processing for the computer or user failed and will continue to fail until this problem is resolved". See MSW2KDB for more details.
From a newsgroup post: "Last weekend I deployed the first GPO for desktop screen saver protection to all computers. On Monday, I found out that not all computers had this policy applied, and most of the computers had this event logged. After two days investigation, I found the reason for this error was due to the logon password expiration. Apparently, quite a few user accounts had their passwords expired over the weekend, and they did not change their passwords before expiration. Then GPO are not pushed out because of the user account cannot be validated. A bit funny, but that makes sense. Users who changed their password will not have that problem later on".
From a newsgroup post :"This may occur on a multihomed DC (2003) with two NICs, where one NIC has port filtering enabled and is blocking port 389. This can occur even if the “port blocking” NIC is lower in the binding order than a “non port blocking” NIC.
Also check to see whether there are any services running in the context ABC\Administrator.
Lastly, make sure the DNS zone for the AD Domain has dynamic updates enabled".
Sean (Last update 9/22/2004):
I had exactly the same problem as Tristen. I went into Control Panel -> User Accounts -> Advanced tab -> Manage Passwords, and removed the user from the list. After a reboot, the problem disappeared.
Tristen (Last update 9/9/2004):
I was getting EventID 1006 and EventID 1030 errors on a user’s machine. The problem turned out to be caused by the fact that both domain controllers had entries under "user accounts / manage passwords" which were blank. I removed both entries, which fixed the problem and allowed the group policy to update.
Robert Auch (Last update 5/31/2003):
Only seen by laptop user after returning from offsite work (logging in with cached credentials on previous logon/bootup) - system will hang at blue screen before "starting windows" window appears on screen. This is NOT a boot error message (M242518 is the only article I can find which looks similar), but a network issue: if the network cable is unplugged, the system boots fine. If "Offline Files" in Explorer is turned off, the system boots fine. Can't turn off Offline files, as user needs it for laptop to work offsite properly.
My last post was from source: http://www.eventid.net/dis
Ok...can you provide more information then? Basically, youve only provided some event id's to us....
How many DC's? What OS's? What SP level? How is your network configured/designed? Do you have third party apps on this server? Are you only seeing these event errors on one machine? What else does this server do? DNS/DHCP/ETC...
Did you run the MPSREPORT on this machine? http://www.microsoft.com/d
couple questions.
did you get the error when you demoted the server?
do you get any errors when you run gpupdate?
have you looked over gpresult?
have you run RSoP and looked for errors?
how many NICs in this server? i know that one is off the wall but with most of the answers pointing to DNS i was curious.
I have posted on this before:\ To no AVAIL what so ever. i.e. no one at all can solve this one, it's to hard! All experts have been stumpted on it.
see here:\ http://www.experts-exchang
We had two DC's that are windows 2003 standard edition with no service paks. {I recently upgraded to SP1 on the DC I Just promoted, but the problem still persisted}, both DC's run DNS\DHCP etc... Its just a one domain deal no extra domains or anything snazzy. We have User Manager Pro installed, Diskeeper, logmeister, Symantec Antivirus, EZ-Audit, Dymo Label. I dont think any of these have anything at all to do with this issue, but who knows.
If I ran MPSREPORT which would be most applicable?
Dirsvc and Network?
mdgil.
The errors pre-existed my being at this job, but I was told the DC in question had these issues prior and was hence demoted and promoted at least one other time. So it was not this instance of demotion\promotion that may have spawned the errors. But the previous demotion\promotion may have had something to do with it. I ran gpudate and User\Computer policy refresh completed with no errors.
gpresult had nothing out the ordinary, i.e. no errors reported.
I have not run RSoP on my DC, will that work, what may it tell?
We have two NICS, one that is 192... and the other is 172... as the backup network only.
this is probably going to be a stupid question but;
do you have disk quota enabled on the C: drive? and how much free space do you have on that drive?
something else i was thinking about is time sync. if the servers are running kerberos some times the time gets out of whack. net time \\PrimaryServer /SET
still looking..
Please answer the following:
1) Is the 192.x.x.x NIC at the top of the binding order? It should be.
2) Is DHCP and DNS listening only to the 192.x.x.x network? They should be.
3) Is the 172.x.x.x NIC registered in DNS? At this point it should NOT be since you aren't using that network. In fact, you should disable the NICs on both servers that are not in use.
4) Was the initial domain a Windows 2000 domain that was updated?
5) Do you see a Forward Lookup zone for _msdcs? Is it inside or outside the Forward Lookup zone for the domain?
6) Do you have a reverse zone created for this subnet?
7) Do you have the ISP DNS address listed on ANY network card inside your LAN? It should NOT be. The only place this should be is on the Forwarder tab of your DNS server.
8) Is replication working? Use REPLMON to determine when (if) replication occurred last and whether it was successful.
9) If you open a CMD window on each server and run "NET SHARE" do you see the SYSVOL share on each DC?
10) Are ALL 5 FSMO roles plus the GC present and accounted for?
Let us know.
It's 12:54am ... I am too tired to read through everyone's possible solutions.
I have run into a similar situation at a client site... not the same errors..but the group policies failing...account not able to authenticate, etc.. Turned out it was the locally installed AntiVirus client scanning the c:\windows\security folder and corrupting the local security data file, and also on the Server same deal... had to exclude the c:\windows\security\ folder on the server and workstation before it would work correctly. Weird thing is it was only on a couple of machines..not all of them..
- pdxsrw
Netman66 has some good suggestions to go thru.
i did run across some info on the 1006 error. the one thing that caught my eye is to copy the sysvol folder from a good DC to the bad DC. i would probably rename the old sysvol folder first tho.
the other things were to check dcdiag /dnsall for errors
and just a thought, how about installing vmware on a beefy workstation and install another DC. just to test if the problem starts from the initial replication. make sure you copy as many settings from the bad DC as you can. with vmware you can take snapshots just incase something goes bad.
last but not wanted. you have to take into account the amount of time you have spent on this problem and will continue to spend on this issue. compare that to how long would it take to rebuild the server from scratch and how long the company will be without the server.
good luck.
This question has been classified as abandoned because there are no comments in the last 21 days. I will make a recommendation to the moderators on its resolution in approximately 4 days. I would appreciate any comments by the experts that would help me in making a recommendation.
It is assumed that any participant not responding to this request is no longer interested in its final disposition.
If the asker does not know how to close the question, the options are here:
http://www.experts-exchang
-red
EE Cleanup Volunteer
Thanks for the reply Netman66,
No comment has been added to this question in more than 21 days, so it is now classified as abandoned.
I will leave the following recommendation for this question in the Cleanup topic area:
Split: NJComputerNetworks{http:#1
Any objections should be posted here in the next 4 days. After that time, the question will be closed.
-red
EE Cleanup Volunteer
Business Accounts
Answer for Membership
by: mcp_jonPosted on 2006-02-02 at 09:33:01ID: 15854947
Please have a look at this inhouse Answer, from ODBA, " http://www.experts-exchang e.com/Netw orking/Mic rosoft_Net work/ Q_211 26829.html "
Hope it helps !
Best Regards !