Access Denied in Event Viewer after making 2003 Server a Domain Controller

J

John Faris

Hi all.

I just used the server roles wizard to make our new 2003 Server a domain
controller for our 2000 domain and it all went through the active directory
setup with no errors or problems. However, I went to check the event logs
on the server and it seems that the only log file I can access is the
security log. Every other log file gives me an access denied error. I
checked the 2000 servers and they can all access their respective logs just
as before. I have looked at the Default Security Policy for the domain
controller and it seems to have the permission "Manage auditing and security
log" assigned for the Administrator account.

Anyone got any ideas what has happened and how I can restore access to the
logs?

Thanks.

John.
 
J

John Faris

Don't worry, I fixed this. It turned out the Administrator account was a
member of Domain Guests for some reason, and this group is explictly denied
access to particular logs in Event Viewer. Removed Administrator from the
group, rebooted and all ok. Phew!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top