We help IT Professionals succeed at work.

Group Policy 1058 errors

Medium Priority
Last Modified: 2012-05-11
Hi Everyone!

I have been working on an issue for several weeks now with no resolution in site.  Hopefully someone can point me in the right direction.  I have an environment with 4 primary DC's and 14 RODC's.  On all of my RODC's Group Policy Processing is functioning fine, but on one RODC I'm getting multiple GroupPolicy 1058 errors.  Here is the exact error:

The processing of Group Policy failed. Windows attempted to read the file \\domain.com\SysVol\tas.com\Policies\{886EDCD6-0D75-476C-B75C-89C5E60E3265}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
a) Name Resolution/Network Connectivity to the current domain controller.
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller).
c) The Distributed File System (DFS) client has been disabled.

It is clear that this is using a DFS pointer and this DFS doesn't seem do exist.  Opening DFS Management on this RODC does not show a DFS Namespace for GP policies and I am unable to find anything when I go to add it.  I can manually browse to the proper network location for the GP policies if I simply insert a specific full DC name in the place of domain.com.  

How to I change the pointers that this device is using to replicate GP policies?  I've checked through Sites and Services, DFS management, etc.....  Any help would be appreciated.  Thanks!

Watch Question

Do a flushdns and try to ping the domain name. It has to resolve to IP of one of the domain controllers.

Have you tried adding the sysvol folder to the namespace? I am not sure if this would work as we do not have DFS setup in our environment.
In case you see replication error you can always revert back the changes.


Did a flushdns and was able to ping the domain and have it resolve to one of the DC's.  You can't add the SysVol Namespace to DFS - it is not allowed.  The really frustrating part is that I can easily browse to the policies on any of our DC's, I just have to replace the domain.com field with a DC server name.  I can't even edit the DFS for SysVol to ensure it is pointing to the correct location.
Unlock this solution and get a sample of our free trial.
(No credit card required)
Qlemo"Batchelor", Developer and EE Topic Advisor
Top Expert 2015

This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.


Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.