Access Denied in Event Viewer after making 2003 Server a Domain Controller

  • Thread starter Thread starter John Faris
  • Start date Start date
J

John Faris

Hi all.

I just used the server roles wizard to make our new 2003 Server a domain
controller for our 2000 domain and it all went through the active directory
setup with no errors or problems. However, I went to check the event logs
on the server and it seems that the only log file I can access is the
security log. Every other log file gives me an access denied error. I
checked the 2000 servers and they can all access their respective logs just
as before. I have looked at the Default Security Policy for the domain
controller and it seems to have the permission "Manage auditing and security
log" assigned for the Administrator account.

Anyone got any ideas what has happened and how I can restore access to the
logs?

Thanks.

John.
 
Don't worry, I fixed this. It turned out the Administrator account was a
member of Domain Guests for some reason, and this group is explictly denied
access to particular logs in Event Viewer. Removed Administrator from the
group, rebooted and all ok. Phew!
 
Back
Top