Group Policy Error

M

MikeG

Hello,

I just set up a Terminal Server which 40 out-of-state employees will
connect to. I want to set a policy to limit the applications the users
in the "Remote Users" group can run. I also want to hide My Computer,
My Network Place, Control Panel, etc. When I try to open 'Domain
Security Policy' I get an error that says: "Failed to open the group
policy object. You may not have appropriate rights. Details: The
network name cannot be found." I get this error when I logon locally
and remotely, it also doesn't matter what account I login as (Domain
Admin, etc.)

Here is my netdiag.log:

Computer Name: SENCORE-POWER
DNS Host Name: sencore-power.Tops.net
System info : Windows 2000 Server (Build 2195)
Processor : x86 Family 6 Model 8 Stepping 10, GenuineIntel
List of installed hotfixes :
KB823980
Q147222


Netcard queries test . . . . . . . : Passed



Per interface results:

Adapter : Local Area Connection

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : sencore-power
IP Address . . . . . . . . : 192.168.0.100
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.0.1
Dns Servers. . . . . . . . : 192.168.0.100


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed

WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{11FD849E-45CE-4E5A-A9DE-1267FE511529}
1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server
'192.168.0.100' and other DCs also have some of the names registered.


Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{11FD849E-45CE-4E5A-A9DE-1267FE511529}
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{11FD849E-45CE-4E5A-A9DE-1267FE511529}
The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Skipped


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Passed
IPSec policy service is active, but no policy is assigned.


The command completed successfully

Thanks,
Mike
 
S

Steven L Umbach

Is there anything in the logs that you can see with Event Viewer that may
indicate the problem? I would also run the support tools dcdiag and gpotool
to see what they report. Can you open Domain Controller Security Policy and
create an edit a new Group Policy even if just for a test? --- Steve
 
M

MikeG

Thanks for the reply,

dcdiag gives me this error: "The procedure entry point DsIsMangledDnW
could not be located in the dynamic link library NTDSAPI.dll"

if I run gpotool I get this error: "Validating DCs... Error: DC list
is empty"

In the Application log there are two errors I receive every 5min.
The first one is Userenv, Event ID 1000: "The Group Policy client-side
extension Security was passed flags (17) and returned a failure status
of (3).
The second error is SceCli, Event ID 1001:"Security policy cannot be
propagated. Cannot access the template. Error code = 3."

If I try to open Domain Controller Security Policy I receive the same
error from my original post.

Any ideas?
Mike
 
S

Steven L Umbach

Make sure that you are using the support tools from the install disk for the
correct operating system or you can get weird error messages if you do not
but the link to the KB article below seems to describe your problem and that
it is with the sysvol structure. Offhand I don't know the best way to
proceed with that but what I suggest you do is to post in the
active_directory newsgroup and let them know if you have more than one
domain controller. --- Steve

http://support.microsoft.com/kb/271213/EN-US/
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top