Solved

SBS2003 User Cannot Access companyweb or Network Shares After Password Change with Server Offline

Posted on 2013-06-25
7
896 Views
Last Modified: 2016-11-23
We had this company's Dell PowerEdge 840 in for repair (PERC Card failed). While the server was offline, a user got a prompt to change his password (domain password policy), which he did. We put the server back in today and everything worked as expected with the other users. They were able to access shares, companyweb, etc. But this one user that changed his password while the server was offline, we cannot get him to connect to anything on the server. Tried changing the password from the server, from the client, nothing works. He can log into the domain with whatever the password is set to, BUT when he attempts to access a share or companyweb, he gets a login prompt and NOTHING we use there will get him access. Client OS is either XP or Win 7. Attempting to verify that now.

Additional config info: DHCP is being handled by the router, not SBS2003. DHCP delivers the server IP address as primary DNS and Google's public DNS server as secondary. This is so, with the server down, the IP phones and Internet browsing from the clients still works.
0
Comment
Question by:tcianflone
7 Comments
 
LVL 14

Expert Comment

by:BlueCompute
Comment Utility
DHCP is being handled by the router, not SBS2003. DHCP delivers the server IP address as primary DNS and Google's public DNS server as secondary.

I sense that you may know this, but this is not a supported configuration.  DHCP on SBS (so it knows where the computers are and can update DNS appropriately) and only the SBS svr configured as DNS svr is the supported config.
0
 
LVL 21

Expert Comment

by:Larry Struckmeyer MVP
Comment Utility
Agreeing that DHCP should be on the SBS.  adding that all the nics in all the systems should point to the SBS for DNS and in the DNS app on the SBS you use the ISP DNS servers, (or other known good DNS servers) as forwarders.  The CEICW wizard fixes all that for you after you turn off DHCP on the router.

It the SBS is off line then you can turn on the DHCP server on the router, turning it off again when the SBS comes back on line.

As for your current condition, sounds like the user is out of sync in AD.  There are probably solutions to all of this but I would most like export his OST to pst, verify that as the admin I could move his redirected documents to a safe place, then remove the user, create a new one, import the mail and put the documents back in his My Documents folder.  They will redirect if that policy is in place.  Should be less complicated than messing with the AD.

You can read more about tombstoned objects here:

http://windowsitpro.com/windows-server-2003/ad-tombstone-objects
0
 
LVL 27

Accepted Solution

by:
Steve earned 500 total points
Comment Utility
password resets are updated on the DC (PDC) but as the DC was not available at the time it's all gone wrong. I'm surprised it let them change the password without the DC in the first place!

try logging into webmail as the user to establish if the user account is screwed or not, and also to confirm exactly which password is currently active on the DC.

You probably best to remove the PC from the domain via a PC local administrator account, and then re add it.

This may reset accounts and force it to refresh the AD uses that can log on.
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 1

Author Comment

by:tcianflone
Comment Utility
Yes, I know about the recommended SBS configuration regarding DHCP services. I inherited this site and all the while it has been running fine with the non-recommended config, i.e., the router running DHCP. I checked the DNS records for the PC's today, including the problem PC. The DNS records are up to date, meaning they have the correct IP addresses. The client can ping the SBS by short name and fqdn, and vice versa. The login from the problem PC works fine as well, the password change is being registered by the DC.

I tried creating another account for this user, logged into it, and then I could access the SBS shares no problem. BUT, I still could NOT access the companyweb site!!! Got the login prompt for that and could not connect no matter what I tried from that prompt. Why would the DC authenticate me for login, shares, but NOT the companyweb???
0
 
LVL 27

Expert Comment

by:Steve
Comment Utility
as advised above, just remove the PC from the domain. chuck in a reboot and re add it. this should reset its security cache etc.
0
 
LVL 1

Author Comment

by:tcianflone
Comment Utility
The plan is to rebuild the client machine from scratch because there are a lot of other issues with it. Once I do that then rejoin it to the domain, I will report back with results and close the question. Thanks.
0
 
LVL 27

Expert Comment

by:Steve
Comment Utility
If the PC has issues anyway then rebuilding certainly isnt a bad idea.
rebuilding it will also work as the security cache will be created from scratch anyway.
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Small Business Server 2011. NOTE: This guide has been written using the preview version of SBS2011 therefore some of the screens may …
If you are a user of the discontinued Microsoft Office Accounting 2008 (MSOA) and have to move to a new computer running Windows 8, you will be unhappy to discover that it won't install.  In particular, Microsoft SQL Server 2005 Express Edition (SSE…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now