Link to home
Start Free TrialLog in
Avatar of Edward Crist
Edward CristFlag for United States of America

asked on

RSOP Red "X"

When running RSOP on my 2008r2 server (Domain Controller), I see a red "X" (see attached image)

The group identified is my staff group here at school.

Not quite sure what this means and/or how to remedy the situation.
RSOP.png
Avatar of Naheer
Naheer
Flag of India image

Can you provide the winlogon.log from the path shown in the screen shot.
Avatar of Edward Crist

ASKER

See attached
Need the winlogon.log file not the RSOP screen shot.
Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 6:10:58 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 6:10:59 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 6:11:00 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 6:16:02 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 6:16:04 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 6:16:04 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 6:21:07 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 6:21:09 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 6:21:09 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 6:31:19 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 6:31:29 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 6:31:32 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 6:36:50 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 6:36:52 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 6:36:52 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 6:41:59 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 6:42:00 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 6:42:01 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 6:47:04 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 6:47:07 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 6:47:08 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 6:52:12 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 6:52:14 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 6:52:15 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 6:57:18 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 6:57:19 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 6:57:20 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:02:23 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:02:24 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:02:25 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:07:28 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:07:29 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:07:30 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:12:32 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:12:34 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:12:34 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:17:38 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:17:40 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:17:41 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:22:43 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:22:45 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:22:46 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:27:48 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:27:50 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:27:50 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:32:52 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:32:54 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:32:54 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:37:57 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:37:58 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:37:58 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:43:01 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:43:02 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:43:02 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:48:04 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:48:06 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:48:06 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:53:08 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:53:09 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:53:09 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 7:58:11 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 7:58:12 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 7:58:12 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:03:14 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:03:16 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:03:16 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:08:18 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:08:19 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:08:19 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:13:58 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:13:59 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:13:59 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:19:01 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:19:03 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:19:03 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:24:04 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:24:06 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:24:06 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:29:08 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:29:09 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:29:09 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:34:11 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:34:13 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:34:13 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:39:15 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:39:16 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:39:16 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:44:18 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:44:20 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:44:20 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:49:22 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:49:23 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:49:23 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:54:25 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:54:26 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:54:26 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 8:59:28 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 8:59:30 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 8:59:30 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 9:04:32 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 9:04:34 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 9:04:34 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 9:09:36 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 9:09:37 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 9:09:37 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 9:14:39 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 9:14:41 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 9:14:41 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 9:19:43 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 9:19:44 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 9:19:44 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 9:24:46 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 9:24:47 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 9:24:47 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 9:29:49 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 9:29:51 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 9:29:51 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 9:34:53 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 9:34:55 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 9:34:55 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 9:40:31 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 9:40:32 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 9:40:32 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 9:45:34 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 9:45:36 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 9:45:36 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 9:50:38 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 9:50:39 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 9:50:39 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 9:55:41 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 9:55:43 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 9:55:43 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 10:00:45 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 10:00:46 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 10:00:46 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 10:05:48 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 10:05:49 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 10:05:49 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 10:10:51 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 10:10:53 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 10:10:53 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 10:15:55 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 10:15:56 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 10:15:56 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 10:20:58 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 10:21:00 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 10:21:00 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 10:26:02 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 10:26:03 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 10:26:03 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 10:31:05 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 10:31:06 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 10:31:06 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 10:36:08 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 10:36:10 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 10:36:10 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
**************************

Error 0 to send control flag 1 over to server.

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )

Make a local copy of \\CITYHIGH.LAN\sysvol\CITYHIGH.LAN\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

Process GP template gpt00000.dom.

This is not the last GPO.
-------------------------------------------
Tuesday, December 13, 2016 10:41:12 AM
      Copy undo values to the merged policy.


----Un-initialize configuration engine...

Process GP template gpt00001.inf.

This is the last GPO : domain policy is ignored on DC.
-------------------------------------------
Tuesday, December 13, 2016 10:41:13 AM


----Un-initialize configuration engine...
-------------------------------------------
Tuesday, December 13, 2016 10:41:13 AM
----Configuration engine was initialized successfully.----

----Reading Configuration Template info...


----Configure User Rights...
            SeSystemtimePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to administrators. This setting is adjusted.
            SeImpersonatePrivilege must be assigned to SERVICE. This setting is adjusted.
            SeNetworkLogonRight must be assigned to Enterprise Controllers account for policy propagation and replication to succeed.
      Configure S-1-5-21-790525478-2000478354-725345543-15314.
      Configure S-1-5-21-790525478-2000478354-725345543-15310.
      Configure S-1-5-21-790525478-2000478354-725345543-6722.
      Configure S-1-5-19.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-20.
            remove SeChangeNotifyPrivilege.
            remove SeImpersonatePrivilege.
Error 50: The request is not supported.
 Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors.
            remove SeChangeNotifyPrivilege.
Configuring SeChangeNotifyPrivilege for this account is not supported.
            remove SeImpersonatePrivilege.
Configuring SeImpersonatePrivilege for this account is not supported.
      Configure S-1-5-21-790525478-2000478354-725345543-13104.
      Configure S-1-5-32-544.
      Configure S-1-5-32-551.
      Configure S-1-5-32-549.
      Configure S-1-5-21-790525478-2000478354-725345543-15309.
      Configure S-1-5-21-790525478-2000478354-725345543-13105.
      Configure S-1-5-21-790525478-2000478354-725345543-6723.
      Configure S-1-5-21-790525478-2000478354-725345543-500.
      Configure S-1-5-21-790525478-2000478354-725345543-1001.
      Configure S-1-5-21-790525478-2000478354-725345543-1002.
      Configure S-1-5-21-790525478-2000478354-725345543-2161.
      Configure S-1-5-21-790525478-2000478354-725345543-6721.
      Configure S-1-5-32-568.
      Configure S-1-5-21-790525478-2000478354-725345543-12528.
      Configure S-1-5-32-554.
      Configure S-1-1-0.
      Configure S-1-5-11.
      Configure S-1-5-6.
      Configure TsInternetUser.
Error 1332: No mapping between account names and security IDs was done.
       Cannot find TsInternetUser.
      Configure S-1-5-32-550.
      Configure S-1-5-32-548.
      Configure S-1-5-18.
      Configure S-1-5-21-790525478-2000478354-725345543-15311.
      Configure S-1-5-21-790525478-2000478354-725345543-2806.
      Configure S-1-5-21-790525478-2000478354-725345543-1106.
      Configure S-1-5-21-790525478-2000478354-725345543-15312.
      Configure S-1-5-21-790525478-2000478354-725345543-29935.
      Configure S-1-5-9.

      User Rights configuration was completed with one or more errors.


----Configure Group Membership...
      Configure Staff.
      Configure CITYHIGH\Staff.
            object already member of Administrators.

      Group Membership configuration was completed successfully.


----Configure General Service Settings...
      Configure Schedule.

      General Service configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Configure Security Policy...
      Configure machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
      Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
      Configure machine\system\currentcontrolset\control\lsa\submitcontrol.
      Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

      Configuration of Registry Values was completed successfully.

      Audit/Log configuration was completed successfully.

      Kerberos Policy configuration was completed successfully.


----Configure available attachment engines...

      Configuration of attachment engines was completed successfully.


----Un-initialize configuration engine...
can you run the the command gpresult /h in command prompt and provide the results
The html report is attached
report.html
ASKER CERTIFIED SOLUTION
Avatar of Naheer
Naheer
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial