Solved

GPO access denied.

Posted on 2009-07-06
3
743 Views
Last Modified: 2012-05-07
I add new server to the domain. don't know what happen, but now on all exist server, I got error when tried to modify GPO.

 "You do not have permission to perform this operation", Access denied.

I can now only able to access GPO using new server.  I used administrator login to all DC.

HELP>>
0
Comment
Question by:ajeab
  • 2
3 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24790034
You need to first go through the logs on those DCs and also run dcdiag and see what sort of errors you are getting on those DCs that are having this problem.
So all you did was just promote a new box and nothing else?
Thanks
Mike
0
 
LVL 6

Author Comment

by:ajeab
ID: 24790110

      Starting test: NetLogons
         [EXCHANGE] An net use or LsaPolicy operation failed with error 5, Acces
s is denied..
         ......................... SERVER failed test NetLogons
     
      Starting test: MachineAccount
         Could not open pipe with [SERVER]:failed with 5: Access is denied.
         Could not get NetBIOSDomainName
         Failed can not test for HOST SPN
         Failed can not test for HOST SPN
         * Missing SPN :(null)
         * Missing SPN :(null)
         ......................... SERVER failed test MachineAccount
      Starting test: Services
         Could not open Remote ipc to [SERVER]:failed with 5: Access is denied
.
         ......................... SERVER failed test Services
      Starting test: ObjectsReplicated
         ......................... SERVER passed test ObjectsReplicated
      Starting test: frssysvol
         [SERVER ] An net use or LsaPolicy operation failed with error 5, Acces
s is denied..
         ......................... SERVER failed test frssysvol
      Starting test: frsevent
         ......................... SERVER failed test frsevent
      Starting test: kccevent
         Failed to enumerate event log records, error Access is denied.
         ......................... SERVER failed test kccevent
      Starting test: systemlog
         Failed to enumerate event log records, error Access is denied.
         ......................... SERVER failed test systemlog

DCDiag show these errors.
I add the server to domain. (not as ADC yet) then I start having problem.  so I tried to add new server as ADC. the new server added OK to the domain but I still having the same problem.
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 24795046
Check out this article
http://support.microsoft.com/kb/839499
You cannot open file shares or Group Policy snap-ins when you disable SMB signing for the Workstation or Server service on a domain controller
Are you also seeing those 1030 and 1058 events in your logs?
Thanks
Mike
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question