Solved

Login process never completes

Posted on 2011-03-17
8
361 Views
Last Modified: 2012-06-27
We originally setup a fairly basic Windows network. It included Windows XP Pro clients connected to a single Windows 2003 Server. The server did hand off some tweaks in the domain policy and all worked well when connecting to this server.

A couple of months ago we migrated the all of these workstations to connect to another Windows domain managed by a different W2003 Server with a different AD (and we also demoted the original W2003 server so it was simply a member server).

Now on random occassion when a user try and login they are able to enter their user id and password, but after they click ok the login process never completes. The screen goes to a blank blue screen and hangs. Often I force a shutdown on the workstation, wait a minute and then log back on and then the login process completes as it should.

Any suggestions on how to rectify this situation?
0
Comment
Question by:bnrtech
  • 4
  • 2
  • 2
8 Comments
 
LVL 42

Expert Comment

by:Amit
ID: 35158312
Increase RAM in your Domain controller. I assume DC is unable to process all login request. Did you made any changes to kerberos life time age? By default it is 10 hours
0
 
LVL 38

Expert Comment

by:ChiefIT
ID: 35163039
If these are DHCP clients, DHCP will pass down the DNS server's IP address. After demoting your server, you also probably removed DNS and/or removed it from the network. So, your clients are looking for a DNS server that doesn't exist, AND that DNS server is suppose to point to the direction of your authentication server, (which it can't find now).

Log onto the DHCP scope options, remove any non-existing DNS servers.
0
 

Author Comment

by:bnrtech
ID: 35164744

amitkulshrestha - I will check out the memory on the DC on Monday

ChiefIT - All clients have been assigned a static IP. I will reconfirm that they have the correct IP for the active DNS server
0
 

Author Comment

by:bnrtech
ID: 35180441

Also I am not 100% certain this is the case, but I do believe what I am about to detail is true. At least informally I have noticed this pattern to be true.

Recall that originally we were connected to a Windows domain (Domain A) and then migrated to a new Windows domain (Domain B).

With that said, I am pretty certain that the login process not completing is specific to user that were originally created on Domain A and then migrated to Domain B. I have not seen the issue occur for users that had their user account created after we completed the migration to Domain B
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 42

Expert Comment

by:Amit
ID: 35180920
Move user to different OU and block all GPO iheritance and then test it. If it logs in fast. Then you need to look into GPO or any script which is used while login process
0
 
LVL 38

Expert Comment

by:ChiefIT
ID: 35293097
You will probably have to rejoing the new domain.
0
 

Accepted Solution

by:
bnrtech earned 0 total points
ID: 35443541
sorry for the delay. it was an operational nightmare with the security folks. the approved answer was to wipe and rebuild the computers and no they are ok.
0
 

Author Closing Comment

by:bnrtech
ID: 35465253
This was the solution that we implemented to resolve the matter
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Installing a printer using group policy preferences is not that hard let’s take a look at it. First lets open up your group policy console and edit the policy you want to add it to. I recommend creating a new policy for each printer makes it a l…
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

861 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

24 Experts available now in Live!

Get 1:1 Help Now