Solved

Login process never completes

Posted on 2011-03-17
8
360 Views
Last Modified: 2012-06-27
We originally setup a fairly basic Windows network. It included Windows XP Pro clients connected to a single Windows 2003 Server. The server did hand off some tweaks in the domain policy and all worked well when connecting to this server.

A couple of months ago we migrated the all of these workstations to connect to another Windows domain managed by a different W2003 Server with a different AD (and we also demoted the original W2003 server so it was simply a member server).

Now on random occassion when a user try and login they are able to enter their user id and password, but after they click ok the login process never completes. The screen goes to a blank blue screen and hangs. Often I force a shutdown on the workstation, wait a minute and then log back on and then the login process completes as it should.

Any suggestions on how to rectify this situation?
0
Comment
Question by:bnrtech
  • 4
  • 2
  • 2
8 Comments
 
LVL 41

Expert Comment

by:Amit
ID: 35158312
Increase RAM in your Domain controller. I assume DC is unable to process all login request. Did you made any changes to kerberos life time age? By default it is 10 hours
0
 
LVL 38

Expert Comment

by:ChiefIT
ID: 35163039
If these are DHCP clients, DHCP will pass down the DNS server's IP address. After demoting your server, you also probably removed DNS and/or removed it from the network. So, your clients are looking for a DNS server that doesn't exist, AND that DNS server is suppose to point to the direction of your authentication server, (which it can't find now).

Log onto the DHCP scope options, remove any non-existing DNS servers.
0
 

Author Comment

by:bnrtech
ID: 35164744

amitkulshrestha - I will check out the memory on the DC on Monday

ChiefIT - All clients have been assigned a static IP. I will reconfirm that they have the correct IP for the active DNS server
0
 

Author Comment

by:bnrtech
ID: 35180441

Also I am not 100% certain this is the case, but I do believe what I am about to detail is true. At least informally I have noticed this pattern to be true.

Recall that originally we were connected to a Windows domain (Domain A) and then migrated to a new Windows domain (Domain B).

With that said, I am pretty certain that the login process not completing is specific to user that were originally created on Domain A and then migrated to Domain B. I have not seen the issue occur for users that had their user account created after we completed the migration to Domain B
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 41

Expert Comment

by:Amit
ID: 35180920
Move user to different OU and block all GPO iheritance and then test it. If it logs in fast. Then you need to look into GPO or any script which is used while login process
0
 
LVL 38

Expert Comment

by:ChiefIT
ID: 35293097
You will probably have to rejoing the new domain.
0
 

Accepted Solution

by:
bnrtech earned 0 total points
ID: 35443541
sorry for the delay. it was an operational nightmare with the security folks. the approved answer was to wipe and rebuild the computers and no they are ok.
0
 

Author Closing Comment

by:bnrtech
ID: 35465253
This was the solution that we implemented to resolve the matter
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now