Can't set Local Security policies. They fail to save
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
Can't set Local Security policies. They fail to save
Goto page Previous  1, 2
 
Post new topic   Reply to topic    Windows Server Forum Index -> Small Business Server 2003
Author Message
Al-Amin
Guest





Posted: Thu Nov 10, 2005 5:50 pm    Post subject: RE: Can't set Local Security policies. They fail to save Reply with quote

Hi Jenny,
1. The account does not belong to the Remote Operators Group nor the Domain
Power Users Group. Neither Domain Admins nor power Users is in the Remote
Operators group.
2. Administrator, everyone and Authenticated users all have the permission
"access this computer from network"
3. I have run the GP wizard and e-mailed results to you. I have also found a
related error in event view. Please find below.
Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1030
Date: 11/10/2005
Time: 4:54:51 PM
User: AIPDC\aipdcstor
Computer: AIPDC-SERVER
Description:
Windows cannot query for the list of Group Policy objects. Check the event
log for possible messages previously logged by the policy engine that
describes the reason for this.

4. I logged on to the server box and tried to edit Group Policy and it gave
me the usual error
"An extended error has occurred. Failed to save
\\AIPDC.local\sysvol\AIPDC.local\Policies\{31B2F340-016D-11D2-945F-00C04FB98

5. I disabled the trend anti-virus we use and did a clean boot but the
problem still persisted

I have e-mailed you all the results thanks for the help
--
AIP Admin


""Jenny wu [MSFT]"" wrote:

Quote:
Hi,

I appreciate your patient to the issue. After analyze the capture file, I
found there is not any write process happened but Read process can
implement successfully. The problem happened before Write process happened.
Or the user account has not permissions to edit the default domain
controller policy.

For you got error of " LOGON FAILURE: THE USER HAS NOT BEEN GRANTED THE
REQUESTED LOGON TYPE AT THIS COMPUTER", please double check if the user
account belongs to the Remote Operators group or the Domain Power Users
group. Also please check if Domain Admins or Power Users is in the Remote
Operators Group. If yes, please verify it and then test to see if the issue
be fixed.

And also please check if the appropriate groups are listed in the "Access
this Computer from the Network" permission of the Default Domain Controller
policy. You can find this permission in the following folder:

Computer Configuration\Windows Settings\Security Settings\Local
Policies\User Rights Assignment

The following groups have the "Access this Computer from the Network"
permission on domain controllers by default:

Administrators
Authenticated Users
Everyone

NOTE: Include the Everyone group in the list of groups because certain
operations involve accounts that may not have been authenticated to the
domain yet. Examples of these operations include when a user changes an
expired password at logon, or when a user in a trusting domain needs to
anonymously enumerate users and groups to apply Access Control Lists (ACLs)
in the trusting domain (for Microsoft Windows NT 4.0 or inter-forest
trusts).

Is the settings configured fine?

I need more information about your group policy settings and users
permissions, please kindly help me collect group policy report s by run the
Group Policy Result wizard. I appreciate your time!

I. To get group policy report:
1. Run command"gpmc.msc" (no quotation marks) in command prompt to open
Group Policy Management console.
2. Locate Forest: -> Group Policy Results node, right click it to choose
Group Policy Results wizard.. to launch a group policy result wizard.
3. Follow guide to produce some user accounts group policy result.

II. Could you find related error event in Event Viewer (Start -
Administrative Tools -> Event Viewer) in the SBS server box? If yes, please
paste the detail error information in the newsgroup or mail to me.

III. Try to test if you can logon the server box from client computer and
edit the group policy, tell me the result.

IV. Have you installed any thirty party Antivirus software on the server
box? Please disable it and perform a clean boot to verify any conflicts of
applications.

A Clean Boot will allow us to isolate any device drivers or programs that
are loading at startup that may be causing a conflict with other device
drivers or programs that are installed in your computer.

1) Run MSCONFIG.EXE.
2) In the Services tab, click "Hide All Microsoft Services" and click
"Disable All".
3) In the Startup tab, click "Disable All". Click OK. (This will
temporarily prevent third-party programs from running automatically during
start-up.)
4) Restart the computer and check whether the problem still persists.
If the problem does not occur, it indicates that the problem is related to
one application or service we have disabled. You can use the MSCONFIG tool
again to re-enable the disabled item one by one to find out the culprit.

Please add all files to zip file and mail me at v-yanniw@microsoft.com

I appreciate your time to collect information. I am happy to be further
assistance!

Have a nice day!

Sincerely,

Jenny Wu
Microsoft CSS Online Newsgroup Support
Get Secure! - www.microsoft.com/security
======================================================
This newsgroup only focuses on SBS technical issues. If you have issues
regarding other Microsoft products, you'd better post in the corresponding
newsgroups so that they can be resolved in an efficient and timely manner.
You can locate the newsgroup here:
http://www.microsoft.com/communities/newsgroups/en-us/default.aspx

When opening a new thread via the web interface, we recommend you check the
"Notify me of replies" box to receive e-mail notifications when there are
any updates in your thread. When responding to posts via your newsreader,
please "Reply to Group" so that others may learn and benefit from your
issue.

Microsoft engineers can only focus on one issue per thread. Although we
provide other information for your reference, we recommend you post
different incidents in different threads to keep the thread clean. In doing
so, it will ensure your issues are resolved in a timely manner.

For urgent issues, you may want to contact Microsoft CSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

Any input or comments in this thread are highly appreciated.
======================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
Thread-Topic: Can't set Local Security policies. They fail to save
thread-index: AcXkhNxekrxxpY8aQPaHtAoQmhXzWw==
X-WBNR-Posting-Host: 196.3.183.254
From: "=?Utf-8?B?QWwtQW1pbg==?=" <AlAmin@discussions.microsoft.com
References: <524324AD-BD69-47E0-B1F5-1DD131613BE7@microsoft.com
6wdjMLH2FHA.3936@TK2MSFTNGXA01.phx.gbl
69F5C0BD-DB81-4E08-8FF5-F10AD70F525E@microsoft.com
YG8yOiU2FHA.3104@TK2MSFTNGXA01.phx.gbl
461D7B7C-3963-42A5-AD51-4A5EF4754345@microsoft.com
WIkO7ij2FHA.3936@TK2MSFTNGXA01.phx.gbl
4C1A8805-1DB9-4D63-A25C-1700C206EAB1@microsoft.com
US7YId72FHA.1172@TK2MSFTNGXA01.phx.gbl
33GdTl72FHA.1172@TK2MSFTNGXA01.phx.gbl
76C2C2C4-F971-4909-8736-5359CE2B763D@microsoft.com
cjwiwRt3FHA.1172@TK2MSFTNGXA01.phx.gbl
D9E3CD0E-847A-48C1-8F34-DFB31B892C67@microsoft.com
sybBIeF5FHA.1172@TK2MSFTNGXA01.phx.gbl
Subject: RE: Can't set Local Security policies. They fail to save
Date: Tue, 8 Nov 2005 08:52:53 -0800
Lines: 322
Message-ID: <62FFEE0B-874D-4C5B-8276-43DAE4E75123@microsoft.com
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
Newsgroups: microsoft.public.windows.server.sbs
NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.2.250
Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGXA03.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.windows.server.sbs:168655
X-Tomcat-NG: microsoft.public.windows.server.sbs

Hi Jenny,

I have followed the instructions you sent me.
Steps 1-4 went smoothly
In step 5 when I clicked the apply button I got the following error
The GP Snapin was unable to save your changes due to the following error
LOGON FAILURE: THE USER HAS NOT BEEN GRANTED THE REQUESTED LOGON TYPE AT
THIS COMPUTER

Notwithstanding I still clicked Ok and the monitor utility captured some
information which I have sent to you via e-mail.
I also checked the GP permissions using ADSI EDIT. The administrator
account
which I use has full control. So that is OK.

Let me know if there is anything else you need.
Thanks
--
AIP Admin


""Jenny wu [MSFT]"" wrote:

Hi,

Thanks for your information. After research the capture files I can not
find information I need, please kindly help me collect it again. Please
follow below steps to capture:

1. Please reboot the server box in clean boot mode (please refer to the
previous post to get steps to perform clean boot. Regarding to your
capture
files, there is not any file that is captured in clean boot situation).

2. Please run command "gpmc.msc" (no quotation marks) to open Group
Policy
Management console and right click the Default Domain Policy to open
Group
Policy Object Editor console.

3. Locate User Configuration -> Administrative Templates -> Start Menu
and
Taskbar node, please double click Add Logoff to the Start Menu item to
open
it Properties page. Please check "Enabled" checkbox and then please
leave
the GPO Editor console for a moment.

4. Please launch the File Monitor, click "Options" button on the menu
and
choose "Filter/Highlight.." item to open filters settings configuration
page, input "sysvol" (no quotation marks) in the blank of "Include" and
ensure monitor all logs by check all checkboxes of "Log opens". Then
click
Ok.

5. Switch to the GPO Editor console, click "Apply" button to apply the
change. Then you will find records in the File Monitor, please save that
and send it to me.

And also please check the group policy permissions using ADSI Edit. You
can
refer to the following steps to check:

1. Please ensure that the Support Tool has been installed. The ADSI Edit
utility is located in the Support Tools folder on the Windows Server
2003
CD-ROM.

2. Click "Start", and then click "Run". In the "Open" box, type
"adsiedit.msc" (without the quotation marks), and then click "OK".

3. In the left pane, please locate ADSI Edit -> domainname -> CN =
system
-> CN=Policies -> CN= {31B2F340-016D-11D2-945F-00C04FB984F9} node and
right
click it and choose Properties to open Properties page, under Security
tab,
please ensure appropriate user groups list here and they have proper
permissions. If not, please verify it and then try to test.

I appreciate your time and efforts to perform test and collect
information.
I am happy to be further assistance of you and look forward to your
reply!

Have a nice day!

Sincerely,

Jenny Wu
Microsoft CSS Online Newsgroup Support
Get Secure! - www.microsoft.com/security
======================================================
This newsgroup only focuses on SBS technical issues. If you have issues
regarding other Microsoft products, you'd better post in the
corresponding
newsgroups so that they can be resolved in an efficient and timely
manner.
You can locate the newsgroup here:
http://www.microsoft.com/communities/newsgroups/en-us/default.aspx

When opening a new thread via the web interface, we recommend you check
the
"Notify me of replies" box to receive e-mail notifications when there
are
any updates in your thread. When responding to posts via your
newsreader,
please "Reply to Group" so that others may learn and benefit from your
issue.

Microsoft engineers can only focus on one issue per thread. Although we
provide other information for your reference, we recommend you post
different incidents in different threads to keep the thread clean. In
doing
so, it will ensure your issues are resolved in a timely manner.

For urgent issues, you may want to contact Microsoft CSS directly.
Please
check http://support.microsoft.com for regional support phone numbers.

Any input or comments in this thread are highly appreciated.
======================================================
This posting is provided "AS IS" with no warranties, and confers no
rights.

--------------------
Thread-Topic: Can't set Local Security policies. They fail to save
thread-index: AcXjvEiUpyY2RdzKSPGA0FjqSRepag==
X-WBNR-Posting-Host: 196.3.183.254
From: "=?Utf-8?B?QWwtQW1pbg==?=" <AlAmin@discussions.microsoft.com
References: <524324AD-BD69-47E0-B1F5-1DD131613BE7@microsoft.com
6wdjMLH2FHA.3936@TK2MSFTNGXA01.phx.gbl
69F5C0BD-DB81-4E08-8FF5-F10AD70F525E@microsoft.com
YG8yOiU2FHA.3104@TK2MSFTNGXA01.phx.gbl
461D7B7C-3963-42A5-AD51-4A5EF4754345@microsoft.com
WIkO7ij2FHA.3936@TK2MSFTNGXA01.phx.gbl
4C1A8805-1DB9-4D63-A25C-1700C206EAB1@microsoft.com
US7YId72FHA.1172@TK2MSFTNGXA01.phx.gbl
33GdTl72FHA.1172@TK2MSFTNGXA01.phx.gbl
76C2C2C4-F971-4909-8736-5359CE2B763D@microsoft.com
cjwiwRt3FHA.1172@TK2MSFTNGXA01.phx.gbl
Subject: RE: Can't set Local Security policies. They fail to save
Date: Mon, 7 Nov 2005 08:57:06 -0800
Lines: 318
Message-ID: <D9E3CD0E-847A-48C1-8F34-DFB31B892C67@microsoft.com
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 8bit
Back to top
Jenny wu [MSFT]
Guest





Posted: Fri Nov 11, 2005 1:50 pm    Post subject: RE: Can't set Local Security policies. They fail to save Reply with quote

Hi,

Thanks for your update!

Please do as follows to check settings:

1- Verify that the OU GPO has Authenticated Users with Read and Apply Group
Policy.

a. Run command "gpmc.msc" (no quotation marks) to open Group Policy
Management console.
b. Locate Forest servername -> Group Policy Objects, click Default Domain
Controllers Policy
c. Please check if the Authenticated Users list in Security Filter in right
panel. If not, please add it.
d. After please check if these group policy object links to appropriate OU
(still in the Group Policy Management console):

2- Verify that the OU itself has Authenticated Users with Read permissions.

a. Open ADUC (Start -> Administrative Tools -> Active Directory Users and
Computers).
b. Locate server name -> Domain Controllers node, right click your SBS
server in right panel to choose Properties to open Properties page.
c. Under Security tab, please ensure Authenticated Users has Read
permissions.
d. Click Advanced button, under Permissions tab, please ensure Domain Admin
has full control (Allow) permissions.

If not, please verified it and then test to see if how thing goes.

And also I suggest you perform the following check to try to trouble shoot
the issue:

1. Network Binding Order

To correctly configure the network binding order, follow these steps:

A. Right-click My Network Places, and then click Properties.
B. On the Advanced menu, click Advanced Settings.
C. Under Connections, use the up and down arrow buttons to put the
connections in the following order:

Local Area Connection for the internal adapter
Local Area Connection for the external adapter
Remote Access Connections

2. DNS Configuration

Correct DNS configuration is important for the correct functioning of
Active Directory and programs on Small Business Server.

To verify correct DNS configuration, follow these steps:

A. Click Start, point to Programs, point to Administrative Tools, and then
click DNS.
B. Right-click the name of your server, and then click Properties.
C. Click the Forwarders tab, and then click Enable Forwarders. If the IP
addresses provided by your ISP are not listed here, add them by typing the
IP address, and then clicking Add.

3. TCP/IP settings of client computers

A. Right-click My Network Places, and then click Properties.
B. Right-click Local Area Connection for the internal network, and then
click Properties.
C. Click Internet Protocol (TCP/IP), and then click Properties. By default,
the internal IP address of the server with a Class C subnet, 255.255.255.0.
The Default Gateway for this connection must be blank. The IP address for
the Primary DNS server must be the internal IP address of the server and
the Alternate DNS server IP address must be blank.

D. Right-click My Network Places, and then click Properties.
E. Right-click the Local Area Connection for your external adapter, and
then click Properties.
F. Click Internet Protocol (TCP/IP), and then click Properties.
G. Under DNS, click Use the following DNS server. The IP address for the
Primary DNS server must be the IP address of the server, and the Alternate
DNS server IP address must be blank. Do not list your ISP''s DNS servers
here or obtain DNS server IP address automatically.

Restart the SBS server, does the issue still occur?

4. On the XP workstation goes to User Accounts in Control Panel.

Advanced Tab
Manage Passwords
Remove All.
Logged out and back in.

5. Make sure the Distributed File System service is started, and set the
Startup type to Automatic. To do this, use the following steps:

1. Click "Start", point to "Programs", point to "Administrative Tools", and
then click "Services".
2. In "Services", double-click "Distributed File System".
3. On the "General" tab, click "Automatic" next to "Startup type".
4. Under "Service Status", click "Start" if the service is not started.
5. Click "OK", and then close the "Services" window.

Restart the computer in clean boot to see if the issue be fixed.

If the issue still persists, for further trouble shoot the issue we need
more information that is hard handle in newsgroup, I suggest you contact
Microsoft Customer Support Services via telephone so that a dedicated
Support Professional can assist with your request online. Thanks for your
understanding!

To obtain the phone numbers for specific technology request please take a
look at the web site listed below.

http://support.microsoft.com/default.aspx?scid=fh;EN-US;PHONENUMBERS

If you are outside the US please see http://support.microsoft.com for
regional support phone numbers.

More information:
887303 Applying Group Policy causes Userenv errors and events to occur on
your
http://support.microsoft.com/?id=887303

839499 You cannot open file shares or Group Policy snap-ins when you
disable
http://support.microsoft.com/?id=839499

I appreciate your time! I am happy to be assistance and look forward to
your test result.

Have a nice day!

Sincerely,

Jenny Wu
Microsoft CSS Online Newsgroup Support
Get Secure! - www.microsoft.com/security
======================================================
This newsgroup only focuses on SBS technical issues. If you have issues
regarding other Microsoft products, you'd better post in the corresponding
newsgroups so that they can be resolved in an efficient and timely manner.
You can locate the newsgroup here:
http://www.microsoft.com/communities/newsgroups/en-us/default.aspx

When opening a new thread via the web interface, we recommend you check the
"Notify me of replies" box to receive e-mail notifications when there are
any updates in your thread. When responding to posts via your newsreader,
please "Reply to Group" so that others may learn and benefit from your
issue.

Microsoft engineers can only focus on one issue per thread. Although we
provide other information for your reference, we recommend you post
different incidents in different threads to keep the thread clean. In doing
so, it will ensure your issues are resolved in a timely manner.

For urgent issues, you may want to contact Microsoft CSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

Any input or comments in this thread are highly appreciated.
======================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
Quote:
Thread-Topic: Can't set Local Security policies. They fail to save
thread-index: AcXmFWpF0ClDiL+3TYyG9Dl8RvjdMw==
X-WBNR-Posting-Host: 196.3.183.254
From: "=?Utf-8?B?QWwtQW1pbg==?=" <AlAmin@discussions.microsoft.com
References: <524324AD-BD69-47E0-B1F5-1DD131613BE7@microsoft.com
6wdjMLH2FHA.3936@TK2MSFTNGXA01.phx.gbl

<69F5C0BD-DB81-4E08-8FF5-F10AD70F525E@microsoft.com>
<YG8yOiU2FHA.3104@TK2MSFTNGXA01.phx.gbl>
<461D7B7C-3963-42A5-AD51-4A5EF4754345@microsoft.com>
<WIkO7ij2FHA.3936@TK2MSFTNGXA01.phx.gbl>
<4C1A8805-1DB9-4D63-A25C-1700C206EAB1@microsoft.com>
<US7YId72FHA.1172@TK2MSFTNGXA01.phx.gbl>
<33GdTl72FHA.1172@TK2MSFTNGXA01.phx.gbl>
<76C2C2C4-F971-4909-8736-5359CE2B763D@microsoft.com>
<cjwiwRt3FHA.1172@TK2MSFTNGXA01.phx.gbl>
<D9E3CD0E-847A-48C1-8F34-DFB31B892C67@microsoft.com>
<sybBIeF5FHA.1172@TK2MSFTNGXA01.phx.gbl>
<62FFEE0B-874D-4C5B-8276-43DAE4E75123@microsoft.com>
<dXLz2Af5FHA.1236@TK2MSFTNGXA02.phx.gbl>
Quote:
Subject: RE: Can't set Local Security policies. They fail to save
Date: Thu, 10 Nov 2005 08:40:10 -0800
Lines: 336
Message-ID: <215CB8C8-320C-498F-A686-B8FB13AEE330@microsoft.com
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
Newsgroups: microsoft.public.windows.server.sbs
NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.2.250
Path: TK2MSFTNGXA02.phx.gbl!TK2MSFTNGXA01.phx.gbl!TK2MSFTNGXA03.phx.gbl
Xref: TK2MSFTNGXA02.phx.gbl microsoft.public.windows.server.sbs:220950
X-Tomcat-NG: microsoft.public.windows.server.sbs

Hi Jenny,
1. The account does not belong to the Remote Operators Group nor the
Domain
Power Users Group. Neither Domain Admins nor power Users is in the Remote
Operators group.
2. Administrator, everyone and Authenticated users all have the permission
"access this computer from network"
3. I have run the GP wizard and e-mailed results to you. I have also found
a
related error in event view. Please find below.
Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1030
Date: 11/10/2005
Time: 4:54:51 PM
User: AIPDC\aipdcstor
Computer: AIPDC-SERVER
Description:
Windows cannot query for the list of Group Policy objects. Check the event
log for possible messages previously logged by the policy engine that
describes the reason for this.

4. I logged on to the server box and tried to edit Group Policy and it
gave
me the usual error
"An extended error has occurred. Failed to save
\\AIPDC.local\sysvol\AIPDC.local\Policies\{31B2F340-016D-11D2-945F-00C04FB9
8

5. I disabled the trend anti-virus we use and did a clean boot but the
problem still persisted

I have e-mailed you all the results thanks for the help
--
AIP Admin


""Jenny wu [MSFT]"" wrote:

Hi,

I appreciate your patient to the issue. After analyze the capture file,
I
found there is not any write process happened but Read process can
implement successfully. The problem happened before Write process
happened.
Or the user account has not permissions to edit the default domain
controller policy.

For you got error of " LOGON FAILURE: THE USER HAS NOT BEEN GRANTED THE
REQUESTED LOGON TYPE AT THIS COMPUTER", please double check if the user
account belongs to the Remote Operators group or the Domain Power Users
group. Also please check if Domain Admins or Power Users is in the
Remote
Operators Group. If yes, please verify it and then test to see if the
issue
be fixed.

And also please check if the appropriate groups are listed in the
"Access
this Computer from the Network" permission of the Default Domain
Controller
policy. You can find this permission in the following folder:

Computer Configuration\Windows Settings\Security Settings\Local
Policies\User Rights Assignment

The following groups have the "Access this Computer from the Network"
permission on domain controllers by default:

Administrators
Authenticated Users
Everyone

NOTE: Include the Everyone group in the list of groups because certain
operations involve accounts that may not have been authenticated to the
domain yet. Examples of these operations include when a user changes an
expired password at logon, or when a user in a trusting domain needs to
anonymously enumerate users and groups to apply Access Control Lists
(ACLs)
in the trusting domain (for Microsoft Windows NT 4.0 or inter-forest
trusts).

Is the settings configured fine?

I need more information about your group policy settings and users
permissions, please kindly help me collect group policy report s by run
the
Group Policy Result wizard. I appreciate your time!

I. To get group policy report:
1. Run command"gpmc.msc" (no quotation marks) in command prompt to open
Group Policy Management console.
2. Locate Forest: -> Group Policy Results node, right click it to choose
Group Policy Results wizard.. to launch a group policy result wizard.
3. Follow guide to produce some user accounts group policy result.

II. Could you find related error event in Event Viewer (Start -
Administrative Tools -> Event Viewer) in the SBS server box? If yes,
please
paste the detail error information in the newsgroup or mail to me.

III. Try to test if you can logon the server box from client computer
and
edit the group policy, tell me the result.

IV. Have you installed any thirty party Antivirus software on the server
box? Please disable it and perform a clean boot to verify any conflicts
of
applications.

A Clean Boot will allow us to isolate any device drivers or programs
that
are loading at startup that may be causing a conflict with other device
drivers or programs that are installed in your computer.

1) Run MSCONFIG.EXE.
2) In the Services tab, click "Hide All Microsoft Services" and click
"Disable All".
3) In the Startup tab, click "Disable All". Click OK. (This will
temporarily prevent third-party programs from running automatically
during
start-up.)
4) Restart the computer and check whether the problem still persists.
If the problem does not occur, it indicates that the problem is related
to
one application or service we have disabled. You can use the MSCONFIG
tool
again to re-enable the disabled item one by one to find out the culprit.

Please add all files to zip file and mail me at v-yanniw@microsoft.com

I appreciate your time to collect information. I am happy to be further
assistance!

Have a nice day!

Sincerely,

Jenny Wu
Microsoft CSS Online Newsgroup Support
Get Secure! - www.microsoft.com/security
======================================================
This newsgroup only focuses on SBS technical issues. If you have issues
regarding other Microsoft products, you'd better post in the
corresponding
newsgroups so that they can be resolved in an efficient and timely
manner.
You can locate the newsgroup here:
http://www.microsoft.com/communities/newsgroups/en-us/default.aspx

When opening a new thread via the web interface, we recommend you check
the
"Notify me of replies" box to receive e-mail notifications when there
are
any updates in your thread. When responding to posts via your
newsreader,
please "Reply to Group" so that others may learn and benefit from your
issue.

Microsoft engineers can only focus on one issue per thread. Although we
provide other information for your reference, we recommend you post
different incidents in different threads to keep the thread clean. In
doing
so, it will ensure your issues are resolved in a timely manner.

For urgent issues, you may want to contact Microsoft CSS directly.
Please
check http://support.microsoft.com for regional support phone numbers.

Any input or comments in this thread are highly appreciated.
======================================================
This posting is provided "AS IS" with no warranties, and confers no
rights.

--------------------
Thread-Topic: Can't set Local Security policies. They fail to save
thread-index: AcXkhNxekrxxpY8aQPaHtAoQmhXzWw==
X-WBNR-Posting-Host: 196.3.183.254
From: "=?Utf-8?B?QWwtQW1pbg==?=" <AlAmin@discussions.microsoft.com
References: <524324AD-BD69-47E0-B1F5-1DD131613BE7@microsoft.com
6wdjMLH2FHA.3936@TK2MSFTNGXA01.phx.gbl
69F5C0BD-DB81-4E08-8FF5-F10AD70F525E@microsoft.com
YG8yOiU2FHA.3104@TK2MSFTNGXA01.phx.gbl
461D7B7C-3963-42A5-AD51-4A5EF4754345@microsoft.com
WIkO7ij2FHA.3936@TK2MSFTNGXA01.phx.gbl
4C1A8805-1DB9-4D63-A25C-1700C206EAB1@microsoft.com
US7YId72FHA.1172@TK2MSFTNGXA01.phx.gbl
33GdTl72FHA.1172@TK2MSFTNGXA01.phx.gbl
76C2C2C4-F971-4909-8736-5359CE2B763D@microsoft.com
cjwiwRt3FHA.1172@TK2MSFTNGXA01.phx.gbl
D9E3CD0E-847A-48C1-8F34-DFB31B892C67@microsoft.com
sybBIeF5FHA.1172@TK2MSFTNGXA01.phx.gbl
Subject: RE: Can't set Local Security policies. They fail to save
Date: Tue, 8 Nov 2005 08:52:53 -0800
Lines: 322
Message-ID: <62FFEE0B-874D-4C5B-8276-43DAE4E75123@microsoft.com
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
Newsgroups: microsoft.public.windows.server.sbs
NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.2.250
Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGXA03.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.windows.server.sbs:168655
X-Tomcat-NG: microsoft.public.windows.server.sbs

Hi Jenny,

I have followed the instructions you sent me.
Steps 1-4 went smoothly
In step 5 when I clicked the apply button I got the following error
The GP Snapin was unable to save your changes due to the following error
LOGON FAILURE: THE USER HAS NOT BEEN GRANTED THE REQUESTED LOGON TYPE
AT
THIS COMPUTER

Notwithstanding I still clicked Ok and the monitor utility captured
some
information which I have sent to you via e-mail.
I also checked the GP permissions using ADSI EDIT. The administrator
account
which I use has full control. So that is OK.

Let me know if there is anything else you need.
Thanks
--
AIP Admin


""Jenny wu [MSFT]"" wrote:

Hi,

Thanks for your information. After research the capture files I can
not
find information I need, please kindly help me collect it again.
Please
follow below steps to capture:

1. Please reboot the server box in clean boot mode (please refer to
the
previous post to get steps to perform clean boot. Regarding to your
capture
files, there is not any file that is captured in clean boot
situation).

2. Please run command "gpmc.msc" (no quotation marks) to open Group
Policy
Management console and right click the Default Domain Policy to open
Group
Policy Object Editor console.

3. Locate User Configuration -> Administrative Templates -> Start
Menu
and
Taskbar node, please double click Add Logoff to the Start Menu item
to
open
it Properties page. Please check "Enabled" checkbox and then please
leave
the GPO Editor console for a moment.

4. Please launch the File Monitor, click "Options" button on the menu
and
choose "Filter/Highlight.." item to open filters settings
configuration
page, input "sysvol" (no quotation marks) in the blank of "Include"
and
ensure monitor all logs by check all checkboxes of "Log opens". Then
click
Ok.

5. Switch to the GPO Editor console, click "Apply" button to apply
the
change. Then you will find records in the File Monitor, please save
that
and send it to me.

And also please check the group policy permissions using ADSI Edit.
You
can
refer to the following steps to check:

1. Please ensure that the Support Tool has been installed. The ADSI
Edit
utility is located in the Support Tools folder on the Windows Server
2003
CD-ROM.

2. Click "Start", and then click "Run". In the "Open" box, type
"adsiedit.msc" (without the quotation marks), and then click "OK".

3. In the left pane, please locate ADSI Edit -> domainname -> CN =
system
-> CN=Policies -> CN= {31B2F340-016D-11D2-945F-00C04FB984F9} node and
right
click it and choose Properties to open Properties page, under
Security
tab,
please ensure appropriate user groups list here and they have proper
permissions. If not, please verify it and then try to test.

I appreciate your time and efforts to perform test and collect
information.
I am happy to be further assistance of you and look forward to your
reply!

Have a nice day!

Sincerely,

Jenny Wu
Microsoft CSS Online Newsgroup Support
Get Secure! - www.microsoft.com/security
======================================================
This newsgroup only focuses on SBS technical issues. If you have
issues
regarding other Microsoft products, you'd better post in the
corresponding
newsgroups so that they can be resolved in an efficient and timely
manner.
You can locate the newsgroup here:
http://www.microsoft.com/communities/newsgroups/en-us/default.aspx

When opening a new thread via the web interface, we recommend you
check
the
"Notify me of replies" box to receive e-mail notifications when there
are
any updates in your thread. When responding to posts via your
newsreader,
please "Reply to Group" so that others may learn and benefit from
your
issue.

Microsoft engineers can only focus on one issue per thread. Although
we
provide other information for your reference, we recommend you post
different incidents in different threads to keep the thread clean. In
doing
so, it will ensure your issues are resolved in a timely manner.

For urgent issues, you may want to contact Microsoft CSS directly.
Please
check http://support.microsoft.com for regional support phone numbers.

Any input or comments in this thread are highly appreciated.
======================================================
This posting is provided "AS IS" with no warranties, and confers no
rights.

--------------------
Thread-Topic: Can't set Local Security policies. They fail to save
thread-index: AcXjvEiUpyY2RdzKSPGA0FjqSRepag==
X-WBNR-Posting-Host: 196.3.183.254
From: "=?Utf-8?B?QWwtQW1pbg==?=" <AlAmin@discussions.microsoft.com
References: <524324AD-BD69-47E0-B1F5-1DD131613BE7@microsoft.com
6wdjMLH2FHA.3936@TK2MSFTNGXA01.phx.gbl
69F5C0BD-DB81-4E08-8FF5-F10AD70F525E@microsoft.com
YG8yOiU2FHA.3104@TK2MSFTNGXA01.phx.gbl
461D7B7C-3963-42A5-AD51-4A5EF4754345@microsoft.com
WIkO7ij2FHA.3936@TK2MSFTNGXA01.phx.gbl
4C1A8805-1DB9-4D63-A25C-1700C206EAB1@microsoft.com
US7YId72FHA.1172@TK2MSFTNGXA01.phx.gbl
33GdTl72FHA.1172@TK2MSFTNGXA01.phx.gbl
76C2C2C4-F971-4909-8736-5359CE2B763D@microsoft.com
cjwiwRt3FHA.1172@TK2MSFTNGXA01.phx.gbl
Subject: RE: Can't set Local Security policies. They fail to save
Date: Mon, 7 Nov 2005 08:57:06 -0800
Lines: 318
Message-ID: <D9E3CD0E-847A-48C1-8F34-DFB31B892C67@microsoft.com
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 8bit
Back to top
 
Post new topic   Reply to topic    Windows Server Forum Index -> Small Business Server 2003 All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB