Re: Windows domain user is sometimes denied access to server share



Since a reboot clears it I would think it is possibly networking related
such as improper DNS configuration on the computer he is using assuming this
happens on just his computer. Verify that his computer is using ONLY domain
controllers as the primary/secondary DNS servers as shown in tcp/ip
properties. I would also run the support tool netdiag on that computer
looking for any related errors and check the application log for any userenv
errors/warnings that can also indicate a problem finding or contacting a
domain controller. I would also check the server with the share security log
for logon failures that occur when he is denied access to see they can
provide any clues.

Steve

http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B291382 ---
Active Directory DNS FAQ


"Henrik Sjöström" <henrik_the_boss@xxxxxxxxxxx> wrote in message
news:uaAerIg5GHA.1200@xxxxxxxxxxxxxxxxxxxxxxx
Hello all.

We have a user that is randomly denied access to the company's file
server's shares.
He can access the shares that do not have security on them OK, but not the
ones that have security on them (security that his accounts is part of /
qualifies for)
He just get a "access denied". (He is running Win XP w SP 2 and full HFs,
and the server is a Win 2K3 w SP1 and full HFs)

This is the case when he tries to access his private share in the form of
USER$, as well as a couple of shares where access is restricted either
with windows user and or windows group accounts.
He does have at least modify permissions on the shares (in the case of his
private file area, he has full control). The permissions are set OK both
on the shares themselves as well as folder security.

When this occurs, we do not see anything wrong either on his computer or
on the server.
It does not help to disconnect the share, or accessing it by
\\FILESRV\USER$.
A reboot generally clears away the error, and he once again has access.

Since shares that allow everyone access works OK, my hunch is that his
profile is somehow broken, and that the hash that windows sends to the
server when asked to authenticate in order to access the folder is not
correct.

This is not a case of Windows fast logon, where Windows XP logs on before
all group policies have been downloaded, as the domain is small (about 20
accounts, with no active policy changes in the last 6 months)

Logging onto his computer and deleting his profile so that he has to start
over in the hopes of fixing the problem does not appeal to either him or
me.
Note that Norton Internet Security 2006 is installed on the system, and
that this error occurs even though all of Norton's subsystems are
disabled.
No one else have had any problems, so we can probably rule out the server,
right?

Any thoughts?


// Henrik



.



Relevant Pages

  • SecurityFocus Microsoft Newsletter #164
    ... Got Storage Security Risks? ... MICROSOFT VULNERABILITY SUMMARY ... Chat Client FTP Server Default Username Credential Weak... ... NetServe Web Server is a compact web server for Microsoft Windows ...
    (Focus-Microsoft)
  • Re: im being held in memory
    ... How can I harden my computer or server to secure it from hackers? ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
    (microsoft.public.security)
  • MS and security: good effort but no cigar
    ... build upon the progress it's already made in security. ... The low-hanging fruit of millions of insecure Windows machines ... Then there's the issue of poorly secured server applications. ... and execute external virus and filtering ...
    (microsoft.public.windowsxp.general)
  • SecurityFocus Microsoft Newsletter #167
    ... MICROSOFT VULNERABILITY SUMMARY ... Multiple Vendor XML Parser SOAP Server Denial Of Service Vul... ... Proactive Windows Security Explorer ...
    (Focus-Microsoft)
  • Re: Group Policy broke my DCs
    ... to be very careful with tweaking services on domain controllers. ... Group Policy - security policy at the OU level which makes it much easier to ... complied from the Windows 2003 Server Security guide for baseline core ... Server - automatic ...
    (microsoft.public.windows.group_policy)