Re: Domain unavailable for some logons

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 10/27/05


Date: Wed, 26 Oct 2005 17:11:07 -0500

You probably have a dns problem and the computer that you can not logon to
with the domain account can not find the domain controller. My guess is that
the reason you can logon with some accounts is because you are logging on
with "cached" domain credentials which is enabled by default. Try pinging
the domain controller by it's fully qualified domain name to see what
happens, run the support tool netdiag on that domain computer and the domain
controller, and use Event Viewer to check the logs on the domain computer
and domain controller. The link below shows how dns MUST be configured for
an AD domain to work correctly and NEVER configure any domain computer to
use the IP address of an ISP dns server as a preferred dns server anywhere
in the list. You can however configure your domain controller/dns server to
forward to your ISP dns server so that all domain computers can resolved
internet names as explained in the KB dns article. Make sure that DHCP is
disabled on your router device so that only your domain controller is used
for DHCP. You can use the command ipconfig /all on any computer to see the
current IP configuration and what computer/device is acting as the DHCP
server. You only need to configure your DHCP scope or manually configure
computers with static IP addresses like your domain controller to use the IP
of your router as the default gateway. --- Steve

http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B291382 --- AD
dns FAQ.
http://support.microsoft.com/default.aspx?scid=kb;en-us;321708 --- Netdiag
http://support.microsoft.com/kb/301423/ --- how to install support tools

"zuke" <lgilmore@NO_SPAMrainbowgrocery.net> wrote in message
news:uT%23lJKn2FHA.3744@TK2MSFTNGP10.phx.gbl...
> Hello,
>
> I've got a W2K AD network with static IP addresses all round. I use just a
> couple logon accounts for most of the 25 PC's. I have a couple logons for
> individuals.
>
> I just set up a Linksys WRT54G wireless router/access point behid my
> firewall. I set it up using WPA/AES, the network is bridged, not routed
> (as in a gateway). I have, at the moment, just one laptop with wireless
> enabled, with an Atheros WiFi chip and using the Atheros driver. I have
> physical connectivity. I can log onto the domain with my Enterprise/Domain
> Admin account. I can log on with just one of my Domain/User accounts.
>
> Other Domain/User accounts return the following message at the logon
> prompt:
> "This system cannot log you on now because the Domain "X" is not
> available"
>
> But I can just enter my Domain/Admin logon account or the one Domain/User
> account and it logs on, no error. If I use the incorrect password I get
> the usual suggestion to "check my user name and password".
>
> Any suggestions?
>
> Zuke
>



Relevant Pages

  • Re: Domain Password Security
    ... accounts need to use complex passwords and minimum of ntlmv2 should be used for lan ... Services Client and configuring authentication level on Domain Controller Security ... controllers if you have all W2K/XP computers. ... I also recommend you enable auditing of account logon and logon ...
    (microsoft.public.win2000.security)
  • Re: Domain Password Security
    ... Domain Controller Security ... >controllers if you have all W2K/XP computers. ... >administrator accounts only when needed to, ... account logon and logon ...
    (microsoft.public.win2000.security)
  • Re: Domain unavailable for some logons
    ... Logon to that computer with a domain account that you can and run the ... Also run netdiag on the domain controller. ... > My client hosts' preferred DNS server settings already point to my two DNS ... run the support tool netdiag on that domain computer ...
    (microsoft.public.win2000.security)
  • Re: Cannot login using new accounts
    ... I am encountering logon problems when using new created profiles....some old profiles work well. ... logging from an xp client connected to server ... If you created local accounts on a 2003 member server or stand-alone server, and you are trying to use RDP to log on to that server, the users must be part of the local 'users' or 'power users' group to have logon privs on that server. ... Users must be members of 'Domain Admins' or 'Enterprise Admins' to have logon privs on the domain controller. ...
    (microsoft.public.cert.exam.mcsa)
  • Re: Utility to identify DCs
    ... Logon problems are usually BAD DNS configuration, ... Make sure that every domain controller has its DNS properties under NIC ...
    (microsoft.public.win2000.active_directory)