Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

I cannot access GPO to make changes error (0x80070574) occurred parsing file logon failure: the target account is incorrect

Posted on 2014-12-08
16
Medium Priority
?
1,624 Views
Last Modified: 2014-12-28
I cannot access GPO to make changes error (0x80070574) occurred parsing file logon failure: the target account is incorrect -

I am logged in as dc administrator

Please advise,
0
Comment
Question by:Carlos Marin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
16 Comments
 
LVL 83

Expert Comment

by:David Johnson, CD, MVP
ID: 40487054
are you saying you can't open the group policy editor on a domain controller?
0
 
LVL 38

Expert Comment

by:Mahesh
ID: 40487089
Ensure PDC master server is running and try editing GPO on PDC server
If still issue persists, reboot the server once.
0
 
LVL 13

Assisted Solution

by:Mark Galvin
Mark Galvin earned 1000 total points
ID: 40488592
Hi

This may be a corruption of the security permisons on the GPO. I have seen this before and the fix is to right click on the GPO in question and select 'Copy'. Then right click again and select 'Paste'. You should be asked to preserve the permissions of inherit them - do no preserve, go with the other option. This will create a new polci with the name of 'Copy of XXXXXX', XXXXXX being the name of the GPO you are haivng an issue with.

You should then be able to make the changes you need. If you can delete the 'dead' policy and rename the copied policy.

Let me know
Thanks
Mark/
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:Carlos Marin
ID: 40489896
Hey Mark, Thanks- i did just that- but i still get the same message..... any other suggestions ???
0
 

Author Comment

by:Carlos Marin
ID: 40489900
Mahesh, this is the PDC server...
0
 

Author Comment

by:Carlos Marin
ID: 40489903
David, exactly what i am saying.
0
 
LVL 38

Expert Comment

by:Mahesh
ID: 40490519
If you logged on different server, still you getting same error?

If not, it might be that it is problem to that specific user profile and deleting profile should solve issue

U might try on same server with another domain admins ID
0
 

Author Comment

by:Carlos Marin
ID: 40491070
I will try that...
0
 

Author Comment

by:Carlos Marin
ID: 40491319
Same error. from another Server and/or from a different domain admin.
0
 
LVL 38

Expert Comment

by:Mahesh
ID: 40492048
Can you please share screen shot please

If you can run below commands on PDC and share output please
dcdiag /v
dcdiag /test:netlogons
dcdiag /test:sysvolcheck

Also check event logs on DC under file replication services for event ID 13568 - Journal Wrap
0
 

Author Comment

by:Carlos Marin
ID: 40493009
Mahesh,,

First Diag....attached
0
 

Author Comment

by:Carlos Marin
ID: 40493011
0
 

Author Comment

by:Carlos Marin
ID: 40493017
second...dcdiag-test-sysvolchck
dcdiag-test-sysvolcheck.txt
0
 

Author Comment

by:Carlos Marin
ID: 40493032
Last one-
that event id does not show-
i see a lot of: 13555-13552-13562-13512
DCdiag-v.txt
0
 

Author Comment

by:Carlos Marin
ID: 40493868
After i ran the test- i restarted the DNS service and i was able to log on to the GPO- i added the policy needed, but the policy is not updating, even though i forced update- i have some error messages,
1112 1085 and 1058
Folder redirection....
0
 
LVL 38

Accepted Solution

by:
Mahesh earned 1000 total points
ID: 40496825
From logs it turns out that either SDC (other DC) is not operational \ already demoted
The last successful replication between PDC and SDC is in year 24th Feb 2012
U need to do metadata cleanup for failed DC

If above SDC I still alive, you need to forcefully demote it with DCPromo /forceremoval command

Remove all its traces from AD, this includes, domain controller object, Host(A) record, PTR record, SRV record, NS record and any other trace from DNS

After that restart netlogon, File replication service and dns server service on PDC and check if it works
0

Featured Post

Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
It’s been over a month into 2017, and there is already a sophisticated Gmail phishing email making it rounds. New techniques and tactics, have given hackers a way to authentically impersonate your contacts.How it Works The attack works by targeti…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question