Solved

Active directory not opening after apply plug n play service disable through GPO

Posted on 2014-04-05
15
703 Views
Last Modified: 2014-04-05
I have active directory n domain controller on Windows server 2008 r2. Yesterday i have disable two services as part of hardening, Print spooler and plug n play services.I ran gpupdate /force command. After some time, Windows activation windows is popping on my server. Even active directory users n computers is not opening and GPO console is not opening. i have attached two error screenshots when i try to open GPO console now. I am unable to start the plug n play service even i have logged in with domain administrator account. plaese help.
GPO-Error.JPG
GPO-error2.JPG
0
Comment
Question by:syinfra
15 Comments
 
LVL 17

Expert Comment

by:Kent Dyer
ID: 39979719
What is the first rule of change management - if you are unable to open an app because of the result of the change you just made..  roll it back - period..

Once you have rolled it back - does AD work again?

If it works, take the new code into a test lab and sort it out there.
0
 
LVL 16

Expert Comment

by:Shaik M. Sajid
ID: 39979721
start the plug and play service and restart the domain .. then check
0
 

Author Comment

by:syinfra
ID: 39979732
Hi Shaik,

I am unable to start the service of Plug n Play. This is my big problem. Any workaround for this. I have doing this by logging with Domain administrator.
0
 
LVL 16

Expert Comment

by:Shaik M. Sajid
ID: 39979757
go to the services... right click the plug and play service

check dependencies ..

and start them all...

in services - click start up type - automatic status services should started..

try this...
0
 

Author Comment

by:syinfra
ID: 39979776
dependencies services are also disabled and cannot be enabled or start through this user. Any other idea?
0
 
LVL 16

Expert Comment

by:Shaik M. Sajid
ID: 39979779
did u tried in safe mode ?
0
 
LVL 16

Expert Comment

by:Shaik M. Sajid
ID: 39979782
is it physical server or virtualserver ?
0
Don't lose your head updating email signatures!

Do your end users still have the wrong email signature? Do email signature updates bore you or fill you with a sense of dread? You can make this a whole lot easier on yourself by trusting an Exclaimer email signature management solution. Over 50 million users do...so should you!

 

Author Comment

by:syinfra
ID: 39979868
A Virtual server in Hyper v
0
 

Author Comment

by:syinfra
ID: 39979878
Server is running in Safe mode. But it is not giving access to start this service.
0
 
LVL 16

Expert Comment

by:Shaik M. Sajid
ID: 39979890
check the virtual disk service ...


go to services. and start the virtual disk service

all the best
0
 
LVL 16

Expert Comment

by:Shaik M. Sajid
ID: 39979893
virtual disk service is depends on plug n play services... check weather it's start or not...

if not start it...
0
 

Author Comment

by:syinfra
ID: 39979927
We have checked, but still whenever i tried to start virtual disk service. It is saying the dependency service not started, so it could not start. ERROR 1068
0
 
LVL 16

Accepted Solution

by:
Shaik M. Sajid earned 500 total points
ID: 39979967
go to regedit

Please navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\PlugPlay and
locate Start registry key

right click Start registry key Edit Dward Value  (value Data change to 2) select the Hexa Decimal

Change Startup type : Automatic -2

Automatic - 2

please take backup of your registry firs before attempting to regedit.
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 39980004
Have you tried to restart domain controller in normal mode, if yes, what error you are getting ? still you are facing same issues ?

If yes, How many domain controllers do you have ?

if you have more than one functional DCs, check if you are able to open all AD snap ins including GPMC on another functional server
Also check if all AD services are running on that server for ex:
Netlogon
NTFRS (File replication service)
Intersite messaging
Kerberos key distribution center
security accounts manager
AD domain services
Also check if Sysvol and netlogon shares are populated

In that case just remove affected server from network and if it contains FSMO roles just seize them on functional DC then do metadata cleanup on functional DC and rebuild the affected server from scratch and promote it again as ADC

if this is the only domain controller you have, then check if you have valid AD system state backup and if yes, just make authoritative restore of system state on affected server by restarting it in directory service restore mode and then check if its working

Mahesh.
0
 

Author Closing Comment

by:syinfra
ID: 39980022
Woilla.....Excellent. I have never think that i can escape from this problem. But yess, after mad these registry changes, i got my DC back.

GURU.....You too good man. God for me.

Cheers,

You deserves a bottle.

-Abhijit
From Syinfra
0

Featured Post

Don't lose your head updating email signatures!

Do your end users still have the wrong email signature? Do email signature updates bore you or fill you with a sense of dread? You can make this a whole lot easier on yourself by trusting an Exclaimer email signature management solution. Over 50 million users do...so should you!

Join & Write a Comment

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now