S
Scott
I'm running W2K Server (SP4) on a domain controller.
Fairly simple setup, one server and six workstations
running either W2K Prof. or Win XP Prof. Just recently I
started getting an Event 1202 error in the application log:
Event Type: Warning
Event Source: SceCli
Event Category: None
Event ID: 1202
Date: 6/2/2004
Time: 3:10:45 PM
User: N/A
Computer: PREMIER-SERVER
Description:
Security policies are propagated with warning. 0x4b8 : An
extended error has occurred.
For best results in resolving this event, log on with a
non-administrative account and search
http://support.microsoft.com for "Troubleshooting Event
1202s".
I enabled logging per a MS troubleshooting KB article and
after refreshing policy settings this is the log file
generated every five minutes:
Error 0 to send control flag 1 over to server.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )
[Mapping] gpt00000.dom = Default Domain Policy
-------------------------------------------
06/02/2004 05:45:40
Invoke Registry Value Delay Filter.
Analyze machine\software\microsoft\windows
nt\currentversion\setup\recoveryconsole\securitylevel.
Analyze machine\software\microsoft\windows
nt\currentversion\setup\recoveryconsole\setcommand.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatecdroms.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatedasd.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatefloppies.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\cachedlogonscount.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\passwordexpirywarning.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\scremoveoption.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\disablecad.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\dontdisplaylastusername.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\legalnoticecaption.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\legalnoticetext.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\shutdownwithoutlogon.
Analyze
machine\system\currentcontrolset\control\lsa\auditbaseobjec
ts.
Analyze
machine\system\currentcontrolset\control\lsa\crashonauditfa
il.
Analyze
machine\system\currentcontrolset\control\lsa\fullprivilegea
uditing.
Analyze
machine\system\currentcontrolset\control\lsa\lmcompatibilit
ylevel.
Analyze
machine\system\currentcontrolset\control\lsa\restrictanonym
ous.
Analyze
machine\system\currentcontrolset\control\print\providers\la
nman print services\servers\addprinterdrivers.
Analyze
machine\system\currentcontrolset\control\session
manager\memory management\clearpagefileatshutdown.
Analyze
machine\system\currentcontrolset\control\session
manager\protectionmode.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\autodisconnect.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\enableforcedlogoff.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\enablesecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\requiresecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\enableplaintextpassword.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\enablesecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\requiresecuritysignature.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\disablepasswordchange.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\requiresignorseal.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\requirestrongkey.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\sealsecurechannel.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\signsecurechannel.
Analyze
MACHINE\System\CurrentControlSet\Control\Lsa\SubmitControl.
Analyze MACHINE\Software\Microsoft\Non-Driver
Signing\Policy.
Analyze MACHINE\Software\Microsoft\Driver
Signing\Policy.
Error 1208: An extended error has occurred.
Error deleting SCP.
----Configuration engine is initialized with error.----
----Un-initialize configuration engine...
**************************
I am not receiving an Event 1000 error.
Sorry for the long post but this is over my head. I have
not changed any active directory settings in the recent
past. Anyone have any suggestions? Thanks in advance.
Fairly simple setup, one server and six workstations
running either W2K Prof. or Win XP Prof. Just recently I
started getting an Event 1202 error in the application log:
Event Type: Warning
Event Source: SceCli
Event Category: None
Event ID: 1202
Date: 6/2/2004
Time: 3:10:45 PM
User: N/A
Computer: PREMIER-SERVER
Description:
Security policies are propagated with warning. 0x4b8 : An
extended error has occurred.
For best results in resolving this event, log on with a
non-administrative account and search
http://support.microsoft.com for "Troubleshooting Event
1202s".
I enabled logging per a MS troubleshooting KB article and
after refreshing policy settings this is the log file
generated every five minutes:
Error 0 to send control flag 1 over to server.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )
[Mapping] gpt00000.dom = Default Domain Policy
-------------------------------------------
06/02/2004 05:45:40
Invoke Registry Value Delay Filter.
Analyze machine\software\microsoft\windows
nt\currentversion\setup\recoveryconsole\securitylevel.
Analyze machine\software\microsoft\windows
nt\currentversion\setup\recoveryconsole\setcommand.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatecdroms.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatedasd.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatefloppies.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\cachedlogonscount.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\passwordexpirywarning.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\scremoveoption.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\disablecad.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\dontdisplaylastusername.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\legalnoticecaption.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\legalnoticetext.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\shutdownwithoutlogon.
Analyze
machine\system\currentcontrolset\control\lsa\auditbaseobjec
ts.
Analyze
machine\system\currentcontrolset\control\lsa\crashonauditfa
il.
Analyze
machine\system\currentcontrolset\control\lsa\fullprivilegea
uditing.
Analyze
machine\system\currentcontrolset\control\lsa\lmcompatibilit
ylevel.
Analyze
machine\system\currentcontrolset\control\lsa\restrictanonym
ous.
Analyze
machine\system\currentcontrolset\control\print\providers\la
nman print services\servers\addprinterdrivers.
Analyze
machine\system\currentcontrolset\control\session
manager\memory management\clearpagefileatshutdown.
Analyze
machine\system\currentcontrolset\control\session
manager\protectionmode.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\autodisconnect.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\enableforcedlogoff.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\enablesecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\requiresecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\enableplaintextpassword.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\enablesecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\requiresecuritysignature.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\disablepasswordchange.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\requiresignorseal.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\requirestrongkey.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\sealsecurechannel.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\signsecurechannel.
Analyze
MACHINE\System\CurrentControlSet\Control\Lsa\SubmitControl.
Analyze MACHINE\Software\Microsoft\Non-Driver
Signing\Policy.
Analyze MACHINE\Software\Microsoft\Driver
Signing\Policy.
Error 1208: An extended error has occurred.
Error deleting SCP.
----Configuration engine is initialized with error.----
----Un-initialize configuration engine...
**************************
I am not receiving an Event 1000 error.
Sorry for the long post but this is over my head. I have
not changed any active directory settings in the recent
past. Anyone have any suggestions? Thanks in advance.