Avatar of Nikhil Candy
Nikhil CandyFlag for India asked on

Event ID 1096 How to resolve it?

The processing of Group Policy failed. Windows attempted to read the file \\DOMAIN NAME\sysvol\DOMAIN NAME\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
a) Name Resolution/Network Connectivity to the current domain controller.
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller).
c) The Distributed File System (DFS) client has been disabled.
Microsoft Server OSWindows OSActive Directory

Avatar of undefined
Last Comment
arnold

8/22/2022 - Mon
arnold

Is the gpo supposed to apply?
Check the GPO to make sure it has no errors that prevented its writeout .

In gpmc make sure the ad and sysvol counters for user and computer entries are the same.

If eithe user or computer have different counters for ad vs sysvol, it would suggest an error in the respective GPO section.
Abhilash Pappiyil

Hi,

Its the "Default domain policy" (31B2F340-016D-11D2-945F-00C04FB984F9)...

1) Are you getting this error on the DC?
2) How many Dcs are in the network? Are you getting the same error on all DCs? Is the replication between the DCs correct?
3) When did you start getting this error?
4) Check the permission of the gpt.ini
5) Check “TCP/IP Netbios Helper” service is started and set to automatic.
6) Check if there any dns issue? (RUN this on the DC dcdiag /test:dns).
7) If DNS and, AD replication and File replication is working fine, reboot the DCs first and check before going further.

Thanks,
ASKER
Nikhil Candy

Dear Abhi

I have applied your suggestions & done as per your guidance but it's still not working .please help me out from these issues   Answer of your question as per given below..

1) Are you getting this error on the DC? :-yes right now we have only 1 DC
2) How many Dcs are in the network? Are you getting the same error on all DCs? Is the replication between the DCs correct?:- only 1 DC in my Domain
3) When did you start getting this error?: 60 days ago...I'm tried to fix but unfortunately unsuccessful in all attempt
4) Check the permission of the gpt.ini:-set Everyone permission to Hidden GroupPolicy folder
5) Check “TCP/IP Netbios Helper” service is started and set to automatic.:-running
6) Check if there any dns issue? (RUN this on the DC dcdiag /test:dns).:-Succeed
7) If DNS and, AD replication and File replication is working fine, reboot the DCs first and check before going further.

Thanks,
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
Abhilash Pappiyil

Hi,

Seems like the sysvol share is corrupted. Could you check the below:-

1) Check if SYSVOL and NETLOGON share exists on the server? Run the command "net share" ..... You can output this to a text file (net share > share.txt) and refer the text file to find.

2) Check which file replication is using (FRS or DFS)? --> Refer:-http://www.itprocentral.com/how-to-identify-the-replication-technology-in-use-by-active-directory/

3) Can you provide me the error messages you are seeing in the File replication  or DFS EVENTLOGS?

4) Take a backup of the SYSVOL (C:\Windows\SYSVOL) folder (as a best practice) before performing any further tasks.

5) Do you have any valid backup before the time of the issue? Atleast the SYSVOL folder, in case if it had corrupted and not present now?

I hope you have to refer the article (https://community.spiceworks.com/topic/1892613-event-id-4012-failed-sysvol-replication-on-a-standalone-dc) to fix the SYSVOL replication issue, if you verify the SYSVOL is broken and it is using DFS as the file replication method.

Let me know the results and I will check further...

Thanks,
ASKER
Nikhil Candy

Dear Abhi

1.According to you last suggestions, i have done changes & verifications on my DC.there I can see my Netlogon&Sysvol folders are already shares
2. By running the ADSIdit.msc successfully checked whether replication running or not .Replication is running on my DC__ CN=DFSR-GlobalSetting > "msDFSR-flags   48" all set .ADSIdit.msc snap shot
3.here is the snap of my DFS eventlogs DFSreplication-snap.PNG4.I have no any previous backup but right now i takes the backup of my sysvol folder

Thanks for Your Responce
ASKER CERTIFIED SOLUTION
Abhilash Pappiyil

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
arnold

Since you only have one DC, checking whether the GPO has an error, or the GPO does not apply, I.e. A computer GPO at the top of the domain, has an empty user section that is not disabled for the user.
The warning occurs at the GPO refresh interval, once every 30 minutes?
Use gpmc, to see whether there is a user or computer setting, if it shoukd not apply to either, disable the option.....

The configuration of the GPO, if using wmi filters.
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.