Solved

2008 Domain Controller - parameter is incorrect (c:\windows\system32)

Posted on 2010-08-19
6
1,104 Views
Last Modified: 2012-05-10
Interesting that I have not encountered but everytime I run any manamgement tool from C:\Windows\System32 (i.e. dsa.msc, dns etc) I get the error "Parameter is incorrect".

I am only able to run tools under Domain "Administrator".....no other account works even if it is in the Domain\Administrators group. I checked permissions on C:\ (root) and \Windows\System32 and permission are inherited from Root drive with Domain\Administrators in the ACL but it does not work. I can only use the tools as the Administrator

I can only assume this is some extended 2008 security feature. I looked at UAC and made changes but no results.

Please give some insight.

Thanks
0
Comment
Question by:MGA2
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
6 Comments
 
LVL 8

Expert Comment

by:SylvainDrapeau
ID: 33481316
Hello !

Try to redo the association of msc files withh mmc.exe.

Maybe the association in HKCR is wrong but the Admin account has something different under HKCU\Software\Classes...

Syldra
0
 

Author Comment

by:MGA2
ID: 33488986
did not work..any other thoughts? I was not sure what you referring with HKCU
0
 

Author Comment

by:MGA2
ID: 33489375
what is interesting is the the Domain "Administrator" which is part of the Domain\Administrators group. I am using a user account that is part of that same group and Domain\Administrators has Full access at Root C:\ drive and down. For some reason only the "Administrator" can run the tools.
Never seen this prior to 2008. Not sure what enhanced Security of other reason this is occuring but it is odd.
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 8

Expert Comment

by:SylvainDrapeau
ID: 33489474
Hello !

Not sure it's an enhance security measure as much as a configuration error.

Clone the Administrator account (name it Test_Admin or whatever) and try with that user. In all logic, it should work. If it does, clone a non-working user (name it Test_Not_Admin) and try. It should not work. Now copy the Administrator profile over that new user's profile (you know how ?). Try again. If, as I believe, there's an error in the registry, it will work. If you are correct and it's some security measure, it will not.

I have another idea but no time to write it down now.

Syldra
0
 

Author Comment

by:MGA2
ID: 33513228
@SylvainDrapeau,

Cloning does not work. I also copied the Administrator profile and still same results
This is a newly installed system so very little changes since OS build and DC services installed.

Note: server running on top of VMWare ESXi Hypervisor

0
 

Accepted Solution

by:
MGA2 earned 0 total points
ID: 33513716
@SylvainDrapeau,

I have resolved this myself. UAC needed to be "disabled" (do you know how?) Of course UAC is a new "security" feature in Vista/2008 OS. It is enabled by default

Go to Local Policies --> User Account Control: Run all administrators in Admin Approval Mode (Disable)
0

Featured Post

Guide to Performance: Optimization & Monitoring

Nowadays, monitoring is a mixture of tools, systems, and codes—making it a very complex process. And with this complexity, comes variables for failure. Get DZone’s new Guide to Performance to learn how to proactively find these variables and solve them before a disruption occurs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We recently had an issue where out of nowhere, end users started indicating that their logins to our terminal server were just showing a "blank screen." After checking the usual suspects -- profiles, shell=explorer.exe in the registry, userinit.exe,…
To effectively work with Diskpart on a Server Core, it is necessary to write some small batch script's, because you can't execute diskpart in a remote powershell session. To get startet, place the Diskpart batch script's into a share on your loca…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question