GPO access denied.

Posted on 2009-07-06
Last Modified: 2012-05-07
I add new server to the domain. don't know what happen, but now on all exist server, I got error when tried to modify GPO.

 "You do not have permission to perform this operation", Access denied.

I can now only able to access GPO using new server.  I used administrator login to all DC.

Question by:ajeab
  • 2
LVL 57

Expert Comment

by:Mike Kline
ID: 24790034
You need to first go through the logs on those DCs and also run dcdiag and see what sort of errors you are getting on those DCs that are having this problem.
So all you did was just promote a new box and nothing else?

Author Comment

ID: 24790110

      Starting test: NetLogons
         [EXCHANGE] An net use or LsaPolicy operation failed with error 5, Acces
s is denied..
         ......................... SERVER failed test NetLogons
      Starting test: MachineAccount
         Could not open pipe with [SERVER]:failed with 5: Access is denied.
         Could not get NetBIOSDomainName
         Failed can not test for HOST SPN
         Failed can not test for HOST SPN
         * Missing SPN :(null)
         * Missing SPN :(null)
         ......................... SERVER failed test MachineAccount
      Starting test: Services
         Could not open Remote ipc to [SERVER]:failed with 5: Access is denied
         ......................... SERVER failed test Services
      Starting test: ObjectsReplicated
         ......................... SERVER passed test ObjectsReplicated
      Starting test: frssysvol
         [SERVER ] An net use or LsaPolicy operation failed with error 5, Acces
s is denied..
         ......................... SERVER failed test frssysvol
      Starting test: frsevent
         ......................... SERVER failed test frsevent
      Starting test: kccevent
         Failed to enumerate event log records, error Access is denied.
         ......................... SERVER failed test kccevent
      Starting test: systemlog
         Failed to enumerate event log records, error Access is denied.
         ......................... SERVER failed test systemlog

DCDiag show these errors.
I add the server to domain. (not as ADC yet) then I start having problem.  so I tried to add new server as ADC. the new server added OK to the domain but I still having the same problem.
LVL 57

Accepted Solution

Mike Kline earned 500 total points
ID: 24795046
Check out this article
You cannot open file shares or Group Policy snap-ins when you disable SMB signing for the Workstation or Server service on a domain controller
Are you also seeing those 1030 and 1058 events in your logs?

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

778 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question