Solved

Errors userenv 1058 and 1030

Posted on 2010-11-26
3
920 Views
Last Modified: 2012-05-10
Hello experts,
 
I had two domain controllers withe Windows Server 2003 SP2. Some days ago, I had to remove (forced remove) one of them, and the other one had to take all the roles. We had a bunch of issues regarding active directory replication, but at the end we made everything work correctly.
 
The domain control functionality seems to work fine. We can create users, modify them, log in computers to the domain, users can log in and so on.
The only issue is that each 5 minutes we get a a pair of errors UserEnv 1030 and 1058 in the event log:

1030 is Windows cannot query for the list of Group Policy objects.
1058 is Windows cannot access the file gpt.ini for GPO CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=MyDomain,DC=org. The file must be present at the location <\\MyDomain.org\sysvol\MyDomain.org\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>. (Configuration information could not be read from the domain controller, either because the machine is unavailable, or access has been denied. ). Group Policy processing aborted.
 
 
Error 1058 tell us that the file gpt.ini in Policies folder can't be accessed. It's no surprise, as that folder and files structure does not exist in SYSVOL.
 
Taking a look to a backup, when the two DC still existed, all those files and folders existed.
 
How should us fix these errors?  Should we just copy back the files from the backup or is it somehow dangerous? Should we do anything else?
 
Thanks in advance,
     Gregorio
0
Comment
Question by:McGregor09
3 Comments
 
LVL 22

Accepted Solution

by:
Matt V earned 500 total points
ID: 34218959
You can safely copy back the policies and scripts folder from a backup.  We often do this when doing a disaster recovery restore of the main DC.

You will probably need to reboot for this to take effect.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 34223347
Make sure you run a metadata cleanup to remove any objects from the failed DC.

http://www.petri.co.il/delete_failed_dcs_from_ad.htm
0
 

Author Closing Comment

by:McGregor09
ID: 34341360
Thanks!

We copied the policies back and everything worked fine after rebooting :)
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now