Re: Failure to update domain policy Impersonate a client after authenication



"Eddie" <eddie.doey@xxxxxxxxxxxxxxxxxxx> wrote in message
news:1179819789.955544.115210@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I made a mistake and messed up a group policy on our domain. Having
changed the policy "Impersonate a client after authenication", its
screwed up the domain controller (i missed off service). It was
changed very quickly after going through the process of changing the
RPC service identity, resetting the policy and several reboots. The
active directory looks rights, but sometimes clients pick up the old
policy and can't shake it. I just added a new machine to the domain
and on its second reboot it picked up the rogue policy. I have no idea
where is can still be picking it up from. its frustrating to say the
least. I thought it had something to do with cached credentials, but
it happened on a new machine.

gpupdate /force was run, but on the next reboot it was back. its
driving me a little crazy :)

We have a single domain with three AD servers.


Have you yet verified that replication is happening as expected?
replmon is one tool to use to check this
You probably should also run netdiag and dcdiag at each domain
controller to establish a baseline of AD health before going too
far down the road of researching/resolving this specific issue.


.



Relevant Pages

  • Re: GPO causing client security logs to fill?
    ... Enabled Small Business Server Remote Assistance Policy No ... Default Domain Controller policy should not be linked to the domain ... thread titled "Client Logon Failure". ... So basically, the Account lockout threshold, account lockout ...
    (microsoft.public.windows.server.sbs)
  • Re: Files are not disconnecting after closed by client
    ... use Group Policy settings to turn off SMB ... set the Default Domain Controller policy settings to ... Digitally sign client communication ...
    (microsoft.public.win2000.security)
  • Re: authentication problem
    ... I my domain computers already have the client/repond policy assigned to them ... > the problem is that you can only log on to the client ... What's the OS of the server you are logging on? ... >>session with a domain controller in this domain LABB ...
    (microsoft.public.win2000.security)
  • Re: SBS 2003 Lost all the Security Policies.
    ... i didn't use dcgpofix i used another sbs 2003 premium has example and created the policies manually. ... I know that your Default Domain Controller Security Policy or Domain Security Policy it is empty. ... DCGPOFIX.EXE will restore the Default Domain Policy and the Default Domain Controller Policy to original default settings. ...
    (microsoft.public.windows.server.sbs)
  • authentication problem
    ... IPSEC policys is distributed to clients and servers on ... Using the default ipsec policy filters in Windows the ... Canīt read the domain controller name on ... sent when the client is trying to login. ...
    (microsoft.public.win2000.security)