Posted on 2007-10-11
Last Modified: 2008-10-05
I am recieving the following error on one of our domain controllers "Automatic certificate enrollment for local system failed to enroll for one Domain Controller certificate (0x80070005).  Access is denied." . As well if i try to open the Domain Security Policy, or Domain Controller security policy  i get the following Error Message."Failed to open group policy object. You may not have approperiate Rights". Any idea about this error and how to resolve them. i have another domain controller for the same domain and these errors do not show there.
Question by:Mohbakri
    LVL 4

    Expert Comment

    You need to add the DC to the CERTSVC_DCOM_ACCESS group

    Author Comment

    already done, but the error is still there.
    LVL 4

    Expert Comment

    Have you rebooted the server after adding to group?

    Author Comment

    LVL 4

    Accepted Solution


    Group Policy Error:
    Failed to open the Group Policy Object. You may not have appropriate rights.
    This issue may occur if either of the following conditions exist: " The Domain Administrators group has been denied access to the GPO.  
    " The primary domain controller (PDC) operations master (also known as flexible single master operations or FSMO) of your Windows 2000 domain is down

    If you have a FSMO failure for Infrastructure master, this may explain why the DC is receiving the auto enroll error, even though you have 'added' it to the group.

    Could you run a dcdiag from the DC and post results,



    Featured Post

    How to improve team productivity

    Quip adds documents, spreadsheets, and tasklists to your Slack experience
    - Elevate ideas to Quip docs
    - Share Quip docs in Slack
    - Get notified of changes to your docs
    - Available on iOS/Android/Desktop/Web
    - Online/Offline

    Join & Write a Comment

    Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
    Scenerio: You have a server running Server 2003 and have applied a retail pack of Terminal Server Licenses.  You want to change servers or your server has crashed and you need to reapply the Terminal Server Licenses. When you enter the 16-digit lic…
    Hi everyone! This is Experts Exchange customer support.  This quick video will show you how to change your primary email address.  If you have any questions, then please Write a Comment below!
    Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

    746 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now