GPO access denied.

I add new server to the domain. don't know what happen, but now on all exist server, I got error when tried to modify GPO.

 "You do not have permission to perform this operation", Access denied.

I can now only able to access GPO using new server.  I used administrator login to all DC.

HELP>>
LVL 6
ajeabAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Mike KlineCommented:
You need to first go through the logs on those DCs and also run dcdiag and see what sort of errors you are getting on those DCs that are having this problem.
So all you did was just promote a new box and nothing else?
Thanks
Mike
0
ajeabAuthor Commented:

      Starting test: NetLogons
         [EXCHANGE] An net use or LsaPolicy operation failed with error 5, Acces
s is denied..
         ......................... SERVER failed test NetLogons
     
      Starting test: MachineAccount
         Could not open pipe with [SERVER]:failed with 5: Access is denied.
         Could not get NetBIOSDomainName
         Failed can not test for HOST SPN
         Failed can not test for HOST SPN
         * Missing SPN :(null)
         * Missing SPN :(null)
         ......................... SERVER failed test MachineAccount
      Starting test: Services
         Could not open Remote ipc to [SERVER]:failed with 5: Access is denied
.
         ......................... SERVER failed test Services
      Starting test: ObjectsReplicated
         ......................... SERVER passed test ObjectsReplicated
      Starting test: frssysvol
         [SERVER ] An net use or LsaPolicy operation failed with error 5, Acces
s is denied..
         ......................... SERVER failed test frssysvol
      Starting test: frsevent
         ......................... SERVER failed test frsevent
      Starting test: kccevent
         Failed to enumerate event log records, error Access is denied.
         ......................... SERVER failed test kccevent
      Starting test: systemlog
         Failed to enumerate event log records, error Access is denied.
         ......................... SERVER failed test systemlog

DCDiag show these errors.
I add the server to domain. (not as ADC yet) then I start having problem.  so I tried to add new server as ADC. the new server added OK to the domain but I still having the same problem.
0
Mike KlineCommented:
Check out this article
http://support.microsoft.com/kb/839499
You cannot open file shares or Group Policy snap-ins when you disable SMB signing for the Workstation or Server service on a domain controller
Are you also seeing those 1030 and 1058 events in your logs?
Thanks
Mike
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.