G
Guest
I've been searching online for two days for the solution to this, and I'm not
having any luck.
Problem:
Clients on my network are not applying computer domain policies. They are,
however, applying user domain policies. They all have the following in the
eventlog:
Windows cannot access the file gpt.ini for GPO
CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=dev,DC=surveillant,DC=net.
The file must be present at the location
<\\dev.surveillant.net\sysvol\dev.surveillant.net\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>.
(Access is denied. ). Group Policy processing aborted.
From a client, I can see the contents of
\\dev.surveillant.net\sysvol\dev.surveillant.net\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini
just fine. However, if I try it from NT AUTHORITY\SYSTEM (using at.exe), I
get access denied. Also, the two domain controllers don't have a problem
applying the policies locally.
Here are the things I've ruled out:
1. dfsutil /PurgeMupCache doesn't help.
2. The DFS service is not stopped on the server (we use DFS for other things).
3. The DFS client is working fine on the clients.
4. The domain controllers are running DNS, and it's working fine.
5. The SMB signing thing is not the issue. The settings are compatible.
6. We don't have any account names that use non-ASCII characters.
7. We don't have too many IP addresses.
8. Our domain controllers are dual-homed, but the second NIC is disabled in
both.
9. No permission I set on the contents of the SYSVOL folder seems to make a
difference.
10. I added the ip addresses for the DCs in the HOSTS file on the DCs.
11. The TCP/IP NetBIOS Helper service is started on all machines.
12. The domain controller security policy has "bypass traverse checking"
rights assigned to the appropriate people.
What should I try next?
Thanks,
Jamie
having any luck.
Problem:
Clients on my network are not applying computer domain policies. They are,
however, applying user domain policies. They all have the following in the
eventlog:
Windows cannot access the file gpt.ini for GPO
CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=dev,DC=surveillant,DC=net.
The file must be present at the location
<\\dev.surveillant.net\sysvol\dev.surveillant.net\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>.
(Access is denied. ). Group Policy processing aborted.
From a client, I can see the contents of
\\dev.surveillant.net\sysvol\dev.surveillant.net\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini
just fine. However, if I try it from NT AUTHORITY\SYSTEM (using at.exe), I
get access denied. Also, the two domain controllers don't have a problem
applying the policies locally.
Here are the things I've ruled out:
1. dfsutil /PurgeMupCache doesn't help.
2. The DFS service is not stopped on the server (we use DFS for other things).
3. The DFS client is working fine on the clients.
4. The domain controllers are running DNS, and it's working fine.
5. The SMB signing thing is not the issue. The settings are compatible.
6. We don't have any account names that use non-ASCII characters.
7. We don't have too many IP addresses.
8. Our domain controllers are dual-homed, but the second NIC is disabled in
both.
9. No permission I set on the contents of the SYSVOL folder seems to make a
difference.
10. I added the ip addresses for the DCs in the HOSTS file on the DCs.
11. The TCP/IP NetBIOS Helper service is started on all machines.
12. The domain controller security policy has "bypass traverse checking"
rights assigned to the appropriate people.
What should I try next?
Thanks,
Jamie