?
Solved

AD Permissions problem with new server

Posted on 2010-09-12
7
Medium Priority
?
334 Views
Last Modified: 2012-05-10
Newly joined Windows Server 2008 R2 computer to a newly set up domain -- when logged in as a new (domain) user (with domain admin permissions) -- can't run anything.   You get this message:

"Windows cannot access the specified device, path or file.  You may not have appropriate permissions to access the item."

If you log in as a local machine user - everything runs.

I've never seen this problem before.
0
Comment
Question by:paulflint
7 Comments
 
LVL 10

Expert Comment

by:Bawer
ID: 33657734
try giving the domain user permission on C drive and other drives, also note that you may not have setup a roaming profile and the profile is not loading....
0
 

Author Comment

by:paulflint
ID: 33658401
Yes but this doesn't make sense - you don't HAVE to use roaming profiles with domain workstations and as for drive permissions -- howcome I don't have this with another 100 PC domain I can add brand new computers to with no problem .. !!

Paul
0
 
LVL 3

Expert Comment

by:petelettin
ID: 33658513
is the time in sync

Pete :-)
0
Easily Design & Build Your Next Website

Squarespace’s all-in-one platform gives you everything you need to express yourself creatively online, whether it is with a domain, website, or online store. Get started with your free trial today, and when ready, take 10% off your first purchase with offer code 'EXPERTS'.

 

Author Comment

by:paulflint
ID: 33658609
petelettin -- yep, time is all synced !

paul

The problem seems to be with the active directory and group policy -- it just isn't being picked up by the newly joined server.
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 33659087
I would recommend using rsop.msc on the problematic machine. This will allow you to troubleshoot the GPO issue on this machine. You can also use gpresult /v. This will also give you detailed information, to see what is exactly being applied to the machine.

Another thing you can do is check the event viewer as this will also help...
0
 
LVL 5

Assisted Solution

by:MisterTwelve
MisterTwelve earned 500 total points
ID: 33662120
HI.
I try this
1. disjoint machine from domain
2. reboot Machine
3. Join Machine to domain again and reboot again.
I think this resolve the problem
0
 

Author Closing Comment

by:paulflint
ID: 33773898
Problem lay with VM images -- needed to run sysprep WITH "generalize" as security tokens were conflicting and AD just didn't like the imposter machines (vm's).  Sysprep with generalize .. THEn join domains, etc. - all good.   Thanks all.
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Scripts are great for performing batch jobs against users, however sometimes the GUI is all you need.
The Windows Firewall provides an important layer of protection and a rich interface to configure it. Unfortunately, it lacks item level filtering. This article details my process of implementing firewall-as-code to reduce GPO bloat.
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

569 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question