Link to home
Start Free TrialLog in
Avatar of tcianflone
tcianfloneFlag for United States of America

asked on

SBS2003 User Cannot Access companyweb or Network Shares After Password Change with Server Offline

We had this company's Dell PowerEdge 840 in for repair (PERC Card failed). While the server was offline, a user got a prompt to change his password (domain password policy), which he did. We put the server back in today and everything worked as expected with the other users. They were able to access shares, companyweb, etc. But this one user that changed his password while the server was offline, we cannot get him to connect to anything on the server. Tried changing the password from the server, from the client, nothing works. He can log into the domain with whatever the password is set to, BUT when he attempts to access a share or companyweb, he gets a login prompt and NOTHING we use there will get him access. Client OS is either XP or Win 7. Attempting to verify that now.

Additional config info: DHCP is being handled by the router, not SBS2003. DHCP delivers the server IP address as primary DNS and Google's public DNS server as secondary. This is so, with the server down, the IP phones and Internet browsing from the clients still works.
Avatar of Member_2_6515809
Member_2_6515809

DHCP is being handled by the router, not SBS2003. DHCP delivers the server IP address as primary DNS and Google's public DNS server as secondary.

I sense that you may know this, but this is not a supported configuration.  DHCP on SBS (so it knows where the computers are and can update DNS appropriately) and only the SBS svr configured as DNS svr is the supported config.
Avatar of Larry Struckmeyer MVP
Agreeing that DHCP should be on the SBS.  adding that all the nics in all the systems should point to the SBS for DNS and in the DNS app on the SBS you use the ISP DNS servers, (or other known good DNS servers) as forwarders.  The CEICW wizard fixes all that for you after you turn off DHCP on the router.

It the SBS is off line then you can turn on the DHCP server on the router, turning it off again when the SBS comes back on line.

As for your current condition, sounds like the user is out of sync in AD.  There are probably solutions to all of this but I would most like export his OST to pst, verify that as the admin I could move his redirected documents to a safe place, then remove the user, create a new one, import the mail and put the documents back in his My Documents folder.  They will redirect if that policy is in place.  Should be less complicated than messing with the AD.

You can read more about tombstoned objects here:

http://windowsitpro.com/windows-server-2003/ad-tombstone-objects
ASKER CERTIFIED SOLUTION
Avatar of Steve
Steve
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of tcianflone

ASKER

Yes, I know about the recommended SBS configuration regarding DHCP services. I inherited this site and all the while it has been running fine with the non-recommended config, i.e., the router running DHCP. I checked the DNS records for the PC's today, including the problem PC. The DNS records are up to date, meaning they have the correct IP addresses. The client can ping the SBS by short name and fqdn, and vice versa. The login from the problem PC works fine as well, the password change is being registered by the DC.

I tried creating another account for this user, logged into it, and then I could access the SBS shares no problem. BUT, I still could NOT access the companyweb site!!! Got the login prompt for that and could not connect no matter what I tried from that prompt. Why would the DC authenticate me for login, shares, but NOT the companyweb???
as advised above, just remove the PC from the domain. chuck in a reboot and re add it. this should reset its security cache etc.
The plan is to rebuild the client machine from scratch because there are a lot of other issues with it. Once I do that then rejoin it to the domain, I will report back with results and close the question. Thanks.
If the PC has issues anyway then rebuilding certainly isnt a bad idea.
rebuilding it will also work as the security cache will be created from scratch anyway.