?
Solved

Login process never completes

Posted on 2011-03-17
8
Medium Priority
?
367 Views
Last Modified: 2012-06-27
We originally setup a fairly basic Windows network. It included Windows XP Pro clients connected to a single Windows 2003 Server. The server did hand off some tweaks in the domain policy and all worked well when connecting to this server.

A couple of months ago we migrated the all of these workstations to connect to another Windows domain managed by a different W2003 Server with a different AD (and we also demoted the original W2003 server so it was simply a member server).

Now on random occassion when a user try and login they are able to enter their user id and password, but after they click ok the login process never completes. The screen goes to a blank blue screen and hangs. Often I force a shutdown on the workstation, wait a minute and then log back on and then the login process completes as it should.

Any suggestions on how to rectify this situation?
0
Comment
Question by:bnrtech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
8 Comments
 
LVL 44

Expert Comment

by:Amit
ID: 35158312
Increase RAM in your Domain controller. I assume DC is unable to process all login request. Did you made any changes to kerberos life time age? By default it is 10 hours
0
 
LVL 39

Expert Comment

by:ChiefIT
ID: 35163039
If these are DHCP clients, DHCP will pass down the DNS server's IP address. After demoting your server, you also probably removed DNS and/or removed it from the network. So, your clients are looking for a DNS server that doesn't exist, AND that DNS server is suppose to point to the direction of your authentication server, (which it can't find now).

Log onto the DHCP scope options, remove any non-existing DNS servers.
0
 

Author Comment

by:bnrtech
ID: 35164744

amitkulshrestha - I will check out the memory on the DC on Monday

ChiefIT - All clients have been assigned a static IP. I will reconfirm that they have the correct IP for the active DNS server
0
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 

Author Comment

by:bnrtech
ID: 35180441

Also I am not 100% certain this is the case, but I do believe what I am about to detail is true. At least informally I have noticed this pattern to be true.

Recall that originally we were connected to a Windows domain (Domain A) and then migrated to a new Windows domain (Domain B).

With that said, I am pretty certain that the login process not completing is specific to user that were originally created on Domain A and then migrated to Domain B. I have not seen the issue occur for users that had their user account created after we completed the migration to Domain B
0
 
LVL 44

Expert Comment

by:Amit
ID: 35180920
Move user to different OU and block all GPO iheritance and then test it. If it logs in fast. Then you need to look into GPO or any script which is used while login process
0
 
LVL 39

Expert Comment

by:ChiefIT
ID: 35293097
You will probably have to rejoing the new domain.
0
 

Accepted Solution

by:
bnrtech earned 0 total points
ID: 35443541
sorry for the delay. it was an operational nightmare with the security folks. the approved answer was to wipe and rebuild the computers and no they are ok.
0
 

Author Closing Comment

by:bnrtech
ID: 35465253
This was the solution that we implemented to resolve the matter
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question