Re: Security policies are propagated with warning

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 03/25/05


Date: Thu, 24 Mar 2005 22:32:02 -0600

Going to http://www.Eventid.net and entering the source and Event ID number
often will be very helpful. Make sure that your dns is absolutely correct
for the domain for both domain controllers and domain computers per the
first link below. Also on domain controllers first run the netdiag and then
the dcdiag support tools. The will run a batty of tests and failed
tests/warnings/errors can help you pinpoint the problem. Gpotool and replmon
can also be very helpful. If any of your domain controllers are multihomed
or also a Remote Access server, that can often cause problems. --- Steve

http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B291382 --- AD
dns FAQ
http://support.microsoft.com/default.aspx?scid=kb;en-us;321708 --- netdiag
and how to install support tools.

"GVB" <nospam@notever.no.no> wrote in message
news:XvE0e.6312$fT3.3210@fe02.lga...
> The following error is showing up in my event viewer:
> -------------
> Security policies are propagated with warning. 0x4b8 : An extended error
> has
> occurred.
>
> For best results in resolving this event, log on with a non-administrative
> account and search http://support.microsoft.com for "Troubleshooting Event
> 1202s".
> -------------
>
> This does not happen every five minutes, like the associated KB articles
> state. Instead, they are showing up about every three hours or so. I am
> also not using any XP computers in my environment, so the XP related
> solutions really shouldn't seem to apply.
>
> I attempted another suggested fix (on a test server), which was to
> analyize
> and rebuild the security database. This caused a large number of errors
> on
> the next reboot, hanging the server, and eventually forced me to rebuild
> the
> server... thus, I'm not going to attempt that on a production server.
>
> Other than the warnings, there does not appear to be anything adverse
> happing as a result of these errors. As a result, I'm uncertain if this
> should be a concern, or if attempting to fix it may result in more
> problems
> (which is what resulted on my test server).
>
> Suggestions / insight would be appreciated... thanks -
>
>



Relevant Pages

  • Re: Multi-homed WINS Server does not let me administer it.
    ... Being a VPN Server and even simply running RRAS makes it multi-homed. ... Domain Controllers with the PDF Role are automatically Domain Master Browser. ... Multihomed DCs, DNS, RRAS servers. ... Insure that all the NICS only point to your internal DNS serveronly and none others, ...
    (microsoft.public.windows.server.dns)
  • Re: DNS on Windows Server 2003
    ... You should never multihome domain controllers. ... Then configure the clients toi use the domain internal DNS server only on ther e NIC's and add the ISP's DNS server to the FORWARDERS tab under the DNS server properties in the DNS management console. ... Insure that all the NICS only point to your internal DNS serveronly and none others, such as your ISP's DNS servers' IP addresses. ...
    (microsoft.public.windows.server.dns)
  • Re: Is it safe to use a DHCP to assign the IP addresses to the servers
    ... Being a VPN Server and even simply running RRAS makes it multi-homed. ... Domain Controllers with the PDF Role are automatically Domain Master Browser. ... Multihomed DCs, DNS, RRAS servers. ... there are some registry changes to eliminate the registration of the external NIC. ...
    (microsoft.public.windows.server.networking)
  • Re: Installing Windows 2003 DC in a Windows 2000 Evironment-- Need Hel
    ... How to Upgrade Windows 2000 Domain Controllers to Windows Server 2003 ... Initial synchronization requirements for Windows 2000 Server and Windows ... ensure that you have designed a DNS and Active ...
    (microsoft.public.windows.server.active_directory)
  • Re: Forced client disconnect problem.
    ... it is very interesting as I have an ISP DNS configured ... > save a file to a network server the problem could also be network related ... The short of it is that domain controllers need to point to ... >>> to check for their domain configuration health. ...
    (microsoft.public.windows.server.security)