Solved

Authentication Failure

Posted on 2006-06-24
11
742 Views
Last Modified: 2016-10-27
Hello Everyone,

I am having a serious problems since last 20 days on my network i have windows 2000 adv server domain controller with DNS and exchange 2000 on the same, some users can log on to domain without any problem some users cannot log onto domain the message is something like this "Windows cannot find domain or cannot log onto domain" everytime i have to remove the computer from domain and rejoin it again its really painfull and time consuming and as soon as the user shutoff the system again the same problem occurs can anyone advise me. Ur urgent action in this regard is highly appreciated
NOte : I have tried this solution given by microsoft but all in vain
Windows XP
In Microsoft Windows XP and later versions, machine account password settings can also be configured by using Group Policy Editor (Gpedit.msc). To configure these settings, follow these steps:
1.      Click Start, click Run, type Gpedit.msc, and then press ENTER.
2.      Expand Local Computer Policy, expand Windows Settings, expand Security Settings, expand Local Policies, expand Security Settings, expand Local Policies, and then expand Security Options.
3.      Configure the following settings:
•      Domain Member: Disable machine account password changes (DisablePasswordChange)
•      Domain Member: Maximum machine account password age (MaximumPasswordAge)
•      Domain Controller: Refuse machine account password changes (RefusePasswordChange)

I had problem with my PDC Emulator and i restored the image from Acronis since then this problems starts and i am having tough time these days pls can someone help me out
0
Comment
Question by:senddiamonds
  • 5
  • 5
11 Comments
 
LVL 82

Expert Comment

by:oBdA
ID: 16975252
Is/was this your only DC, or do you have another one?
0
 
LVL 22

Expert Comment

by:rickhobbs
ID: 16977094
Are you running in mixed mode?
0
 

Author Comment

by:senddiamonds
ID: 16978110
No we have Additional Domain Controller its also giving me the same problems, yeah we are running servers in mixed mode. I have restored my Global Catalog with acronis image since then this problems started
0
 
LVL 82

Expert Comment

by:oBdA
ID: 16978190
You are in rather deep trouble here. You can NOT use imaging software to backup domain controllers, at least not if you have more than one.
What you're experiencing currently is a USN rollback, and your DCs now don't replicate anymore.
The only way to recover from this in Windows 2000 is to uninstall Exchange (demoting the machine with Exchange on it will break Exchange), demote the machine you restored, clean out the metadata, then repromote the machine again.

How to detect and recover from a USN rollback in Windows 2000 Server
http://support.microsoft.com/?kbid=885875

How to remove data in Active Directory after an unsuccessful domain controller demotion
http://support.microsoft.com/?kbid=216498

Exchange Server 2003 and Domain Controllers - A Summary
http://blogs.brnets.com/michael/archive/2005/01/24/319.aspx

0
 

Author Comment

by:senddiamonds
ID: 16991752
I am sorry to say that but we dont have Active Directory Restore Password can u help me in this do let me know, i highly appreciate ur answer and it did help me out but the problem is i dont have ads restore password
0
Complete Microsoft Windows PC® & Mac Backup

Backup and recovery solutions to protect all your PCs & Mac– on-premises or in remote locations. Acronis backs up entire PC or Mac with patented reliable disk imaging technology and you will be able to restore workstations to a new, dissimilar hardware in minutes.

 
LVL 82

Accepted Solution

by:
oBdA earned 500 total points
ID: 16991912
Check here:
How to Change the Recovery Console Administrator Password on a Domain Controller
http://support.microsoft.com/?kbid=239803
0
 

Author Comment

by:senddiamonds
ID: 17002193
is their a way to copy active directory users and password into a text file or access database and add it to a new domain
0
 
LVL 82

Expert Comment

by:oBdA
ID: 17002250
With the ADMT; but since the ADMT requires a trust between the two domains, you're likely to run into problems if you don't get your current domain fixed.
There shouldn't be a need to rebuild your domain, though; you "only" need to fix the broken DC.

Active Directory Migration Tool v3.0
http://www.microsoft.com/downloads/details.aspx?FamilyId=6F86937B-533A-466D-A8E8-AFF85AD3D212&displaylang=en
0
 

Author Comment

by:senddiamonds
ID: 17007643
My existing domain controller is PIII 700 Mhz and their is no connection between my existing Glocal catalog and Additional Domain Controller i cant see my global catalogue from my ADC and other scenario is DNS is working fine on Glocal Catalogue and authentication of users are working fine on my ADC i am really worried company have purchased new Xeon Servers 3.8 Ghz and we are planning to implement 2003 and pls tell me friend is it possible to take emails from my exisiting Exchange server which is intalled on my primary domain controller which is also a global catalogue and its installed on D drive and ADS is on C drive, please i am very much confused with this scenario the ADS schema in Glocal catalogue is different and on ADC is different

Thanks in advance
Regards
send diamonds
0
 
LVL 82

Expert Comment

by:oBdA
ID: 17008075
You can move the Exchange server, but that's a question for the Exchange TA.
The first thing you need to do is to fix your AD as described in the article. You won't be able to do a clean migration to the new hardware if your AD is broken.
There's one more article that might be helpful; you'll probably have to seize the roles the primary DC held when you demote it, as I doubt that a proper move is possible.
Using Ntdsutil.exe to transfer or seize FSMO roles to a domain controller
http://support.microsoft.com/?kbid=255504

If you can't uninstall Exchange to depromote the primary DC, the only other option that could work (absolutely no guarantee here!), if the other DC isn't running any other major services, is the following:
*** USE THIS APPROACH AT YOUR OWN RISK ***
Backup your current Exchange database.
Depromote your second DC (you'll probably have to use /forceremoval) and shut it down. If the depromote doesn't work, reinstall the OS.
Restore the primary DC's image again. Clean out your AD from the second DC (which you depromoted) using the article above, seize any FSMO roles the secondary DC might have held.
Restore Exchange.
Fix any errors resulting from changed passwords, added/deleted accounts, changed group membership, and whatever else happened after the first restore.
Promote the second DC again.
*** USE THIS APPROACH AT YOUR OWN RISK ***

At this point, it might be worth it to open a support call with Microsoft.
0
 

Author Comment

by:senddiamonds
ID: 17008883
thanks for your answer and ur help god bless u i will rty and lety you know
0

Featured Post

Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
In this article, I will show you HOW TO: Create your first Windows Virtual Machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, the Windows OS we will install is Windows Server 2016.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now