?
Solved

Map Network Drives do not always Map through Group Policy Site Policy

Posted on 2007-11-29
17
Medium Priority
?
747 Views
Last Modified: 2008-06-13
We have 3 different sites/locations and recently changed the way users map network drives.  Depending on what site a user is in, determines the logon script that will run.  However, sometime the logon script does not run.  WHY?

This is how I set it up...

In GPMC, I assigned a policy to each Active Directory Site.  For each policy I enabled a logon script for that site/location under...
User Configuration -->Windows Settings -->Scripts --> Logon
The logon script is a VBS.

For some reason, I have been getting calls from users saying that their drives are not mapping.  All of these users experiencing the issue are running windows XP.  Any Ideas?
0
Comment
Question by:ohmErnie
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 9
  • 6
  • 2
17 Comments
 
LVL 12

Expert Comment

by:bhnmi
ID: 20376322
Are you sure the script itself is not running? Or is it not completing due to an error?
0
 
LVL 1

Author Comment

by:ohmErnie
ID: 20376445
After looking in the event log -- application I can tell it is looking for the script, but failing with these errors:

Event Type:      Error
Event Source:      UserInit
Event Category:      None
Event ID:      1000
Date:            11/29/2007
Time:            1:58:40 PM
User:            N/A
Computer:      COMP
Description:
Could not execute the following script \\domain.com\NETLOGON\logon.vbs. Configuration information could not be read from the domain controller, either because the machine is unavailable, or access has been denied.



Event Type:      Error
Event Source:      Userenv
Event Category:      None
Event ID:      1058
Date:            11/29/2007
Time:            1:58:15 PM
User:            domain\user
Computer:      COMP
Description:
Windows cannot access the file gpt.ini for GPO CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=home,DC=domain,DC=com. The file must be present at the location <\\domain.com\sysvol\domain.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>. (Configuration information could not be read from the domain controller, either because the machine is unavailable, or access has been denied. ). Group Policy processing aborted.

Sometimes if the user restarts their computer a couple times it works.  do I have something configured incorrectly?
0
 
LVL 12

Expert Comment

by:bhnmi
ID: 20376495
Is the script located locally at each site? and is each site the same domain or do you have a top level and child domains?
0
What Is Blockchain Technology?

Blockchain is a technology that underpins the success of Bitcoin and other digital currencies, but it has uses far beyond finance. Learn how blockchain works and why it is proving disruptive to other areas of IT.

 
LVL 16

Accepted Solution

by:
Kevin Hays earned 2000 total points
ID: 20376964
have yet set this setting perhaps?  It seems as though the network may not be fully loaded when the user logs in.  Something that xp does, fast user login.

computer configuration/administrative templates/system/logon/always wait for the network at computer startup and logon.

0
 
LVL 1

Author Comment

by:ohmErnie
ID: 20377000
Bhnmi, yes the script is located at each site and we only have 1 domain.

Kshays, I have not set that setting. Think that will help?
0
 
LVL 16

Expert Comment

by:Kevin Hays
ID: 20377013
It wouldn't hurt that's for sure.  Instead of the user getting the login screen really quick they are forced until everything is loaded (network wise).  This is why some single site domains will not run login scripts.

This is for xp machines only.

Kevin
0
 
LVL 1

Author Comment

by:ohmErnie
ID: 20377046
Kevin, What will happen to laptops that users take off the network?  Will they still be able to logon when they are disconnected from the network?
0
 
LVL 16

Expert Comment

by:Kevin Hays
ID: 20377132
Nothing should happen if you apply that policy.  It just waits for the network connections to get fully load(part of OS) is all.  Let me see if I can find you a link :)

0
 
LVL 16

Expert Comment

by:Kevin Hays
ID: 20377149
0
 
LVL 1

Author Comment

by:ohmErnie
ID: 20457998
Kevin,

Any ideas why all of a sudden this issue is happening.  I know have about 10-15 people that are complaining about having to restart a couple times daily to maybe get the drives to map.  Nothing in my organization has changed accept possible windows updates that may have installed.
0
 
LVL 16

Expert Comment

by:Kevin Hays
ID: 20459413
Not right off hand I don't.  It sounds like it just isn't making sure the network connections are available before running the login scripts.  Are the DC's replicated with each other (i assume so).  Are these the same people over and over?

Have you tried having them login to a different workstation or tried a different user on their workstation.
In the meantime I would probably create a small batch file that the user can just launch from their desktop to map their drives if the login scripts don't run.

There shouldn't be a permissions issue since it was all working fine before.

Have you ran netdiag /v on each dc assuming it's hosting dns service to test funcionality of your DNS service?

Kevin
0
 
LVL 1

Author Comment

by:ohmErnie
ID: 20459452
I now remember the following group policy setting was changed about the time the issue began...

Network security: LAN Manager authentication level

Symantec Endpoint Protection recommended changing it to: "Send NTLMv2 response only"
0
 
LVL 16

Expert Comment

by:Kevin Hays
ID: 20460149
Ahhhhh.  I've got mine set at "send LM & NTLM responses"
Why did they suggest you just use NTLM responses for?
0
 
LVL 16

Expert Comment

by:Kevin Hays
ID: 20460165
0
 
LVL 16

Expert Comment

by:Kevin Hays
ID: 20460354
Much better explanation.

http://kb.iu.edu/data/atvn.html

Kevin
0
 
LVL 1

Author Comment

by:ohmErnie
ID: 20460392
Im trying to find the symantec article that recommended the change, but I cannot.  They probably removed it because it was causing problems.  I changed my setting back to default and will monitor for the next day or so and will post back.
0
 
LVL 16

Expert Comment

by:Kevin Hays
ID: 20461026
Ok, good luck!

Kevin
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is the result of a quest to better understand Task Scheduler 2.0 and all the newer objects available in vbscript in this version over  the limited options we had scripting in Task Scheduler 1.0.  As I started my journey of knowledge I f…
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Add bar graphs to Access queries using Unicode block characters. Graphs appear on every record in the color you want. Give life to numbers. Hopes this gives you ideas on visualizing your data in new ways ~ Create a calculated field in a query: …
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Suggested Courses

741 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question