Event 1202 error

S

Scott

I'm running W2K Server (SP4) on a domain controller.
Fairly simple setup, one server and six workstations
running either W2K Prof. or Win XP Prof. Just recently I
started getting an Event 1202 error in the application log:

Event Type: Warning
Event Source: SceCli
Event Category: None
Event ID: 1202
Date: 6/2/2004
Time: 3:10:45 PM
User: N/A
Computer: PREMIER-SERVER
Description:
Security policies are propagated with warning. 0x4b8 : An
extended error has occurred.

For best results in resolving this event, log on with a
non-administrative account and search
http://support.microsoft.com for "Troubleshooting Event
1202s".


I enabled logging per a MS troubleshooting KB article and
after refreshing policy settings this is the log file
generated every five minutes:

Error 0 to send control flag 1 over to server.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

[Mapping] gpt00000.dom = Default Domain Policy
-------------------------------------------
06/02/2004 05:45:40
Invoke Registry Value Delay Filter.
Analyze machine\software\microsoft\windows
nt\currentversion\setup\recoveryconsole\securitylevel.
Analyze machine\software\microsoft\windows
nt\currentversion\setup\recoveryconsole\setcommand.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatecdroms.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatedasd.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatefloppies.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\cachedlogonscount.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\passwordexpirywarning.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\scremoveoption.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\disablecad.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\dontdisplaylastusername.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\legalnoticecaption.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\legalnoticetext.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\shutdownwithoutlogon.
Analyze
machine\system\currentcontrolset\control\lsa\auditbaseobjec
ts.
Analyze
machine\system\currentcontrolset\control\lsa\crashonauditfa
il.
Analyze
machine\system\currentcontrolset\control\lsa\fullprivilegea
uditing.
Analyze
machine\system\currentcontrolset\control\lsa\lmcompatibilit
ylevel.
Analyze
machine\system\currentcontrolset\control\lsa\restrictanonym
ous.
Analyze
machine\system\currentcontrolset\control\print\providers\la
nman print services\servers\addprinterdrivers.
Analyze
machine\system\currentcontrolset\control\session
manager\memory management\clearpagefileatshutdown.
Analyze
machine\system\currentcontrolset\control\session
manager\protectionmode.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\autodisconnect.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\enableforcedlogoff.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\enablesecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\requiresecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\enableplaintextpassword.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\enablesecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\requiresecuritysignature.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\disablepasswordchange.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\requiresignorseal.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\requirestrongkey.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\sealsecurechannel.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\signsecurechannel.
Analyze
MACHINE\System\CurrentControlSet\Control\Lsa\SubmitControl.
Analyze MACHINE\Software\Microsoft\Non-Driver
Signing\Policy.
Analyze MACHINE\Software\Microsoft\Driver
Signing\Policy.
Error 1208: An extended error has occurred.
Error deleting SCP.
----Configuration engine is initialized with error.----


----Un-initialize configuration engine...
**************************


I am not receiving an Event 1000 error.

Sorry for the long post but this is over my head. I have
not changed any active directory settings in the recent
past. Anyone have any suggestions? Thanks in advance.
 
A

Adrian Grigorof

See if this helps:
http://www.eventid.net/display.asp?eventid=1202&eventno=348&source=SceCli&phase=1
--

Adrian Grigorof
www.eventid.net

Scott said:
I'm running W2K Server (SP4) on a domain controller.
Fairly simple setup, one server and six workstations
running either W2K Prof. or Win XP Prof. Just recently I
started getting an Event 1202 error in the application log:

Event Type: Warning
Event Source: SceCli
Event Category: None
Event ID: 1202
Date: 6/2/2004
Time: 3:10:45 PM
User: N/A
Computer: PREMIER-SERVER
Description:
Security policies are propagated with warning. 0x4b8 : An
extended error has occurred.

For best results in resolving this event, log on with a
non-administrative account and search
http://support.microsoft.com for "Troubleshooting Event
1202s".


I enabled logging per a MS troubleshooting KB article and
after refreshing policy settings this is the log file
generated every five minutes:

Error 0 to send control flag 1 over to server.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

[Mapping] gpt00000.dom = Default Domain Policy
-------------------------------------------
06/02/2004 05:45:40
Invoke Registry Value Delay Filter.
Analyze machine\software\microsoft\windows
nt\currentversion\setup\recoveryconsole\securitylevel.
Analyze machine\software\microsoft\windows
nt\currentversion\setup\recoveryconsole\setcommand.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatecdroms.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatedasd.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatefloppies.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\cachedlogonscount.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\passwordexpirywarning.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\scremoveoption.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\disablecad.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\dontdisplaylastusername.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\legalnoticecaption.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\legalnoticetext.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\shutdownwithoutlogon.
Analyze
machine\system\currentcontrolset\control\lsa\auditbaseobjec
ts.
Analyze
machine\system\currentcontrolset\control\lsa\crashonauditfa
il.
Analyze
machine\system\currentcontrolset\control\lsa\fullprivilegea
uditing.
Analyze
machine\system\currentcontrolset\control\lsa\lmcompatibilit
ylevel.
Analyze
machine\system\currentcontrolset\control\lsa\restrictanonym
ous.
Analyze
machine\system\currentcontrolset\control\print\providers\la
nman print services\servers\addprinterdrivers.
Analyze
machine\system\currentcontrolset\control\session
manager\memory management\clearpagefileatshutdown.
Analyze
machine\system\currentcontrolset\control\session
manager\protectionmode.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\autodisconnect.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\enableforcedlogoff.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\enablesecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\requiresecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\enableplaintextpassword.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\enablesecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\requiresecuritysignature.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\disablepasswordchange.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\requiresignorseal.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\requirestrongkey.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\sealsecurechannel.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\signsecurechannel.
Analyze
MACHINE\System\CurrentControlSet\Control\Lsa\SubmitControl.
Analyze MACHINE\Software\Microsoft\Non-Driver
Signing\Policy.
Analyze MACHINE\Software\Microsoft\Driver
Signing\Policy.
Error 1208: An extended error has occurred.
Error deleting SCP.
----Configuration engine is initialized with error.----


----Un-initialize configuration engine...
**************************


I am not receiving an Event 1000 error.

Sorry for the long post but this is over my head. I have
not changed any active directory settings in the recent
past. Anyone have any suggestions? Thanks in advance.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top