Logon Problem w/ Third Party Security Software

G

Guest

Hello All,

I work at a public library and we're running Windows 2000 Professional on
all of the patron computers and Windows 2000 Server on our server. The
server also runs as a PDC.

Recently, we purchased and installed a security program called PCRefresh
that allows the computer to 'refresh' itself whenever the computer is
restarted. For example, if a computer becomes infrected with a virus,
restarting the computer will restore the computer to it's original settings
that we specified.

Unfortunately, we've been noticing an error that comes up about once a month
on all of the locked-down machines. The error reads:

"System cannot log you on to this domain because the systems computer
account in it's primary domain is missing or the password on that account is
incorrect."

The only way we've been able to resolve the problem is to turn off
PcRefresh, disconnect and reconnect from the domain, and re-enable PcRefresh.
The whole process takes about 20 minutes, but with 50+ computers, it's
becoming tiresome.

After speaking with the creators of PcRefresh, their technicial support
staff suggested that we enable the "Prevent System Maintenance of Local
Account Password" in the Default Domain Policy in our server's Active
Directory, but that did not fix our problem..

Their technicial support also mentioned to use the 'dnsquery' command on the
server, but I believe that the Tech. Support team was using Windows Server
2003 to test this problem. We've searched the Microsoft website for Windows
2000 Active Directory updates/service packs that include the 'dnsquery'
command, but
have not found anything.

My supervisor and our computer conslutant team seem to think that the client
computer's SIDs are trying to authenticate to the PDC, and once a month, they
are unable to be authenticated, thus giving us the error.

My question is: Is there any way to disable SID authentication and still
allow access to the domain?

Thanks for your time.

Joey Rawlings
Computer Services Technician
Charles County Public Library
LaPlata, MD
 
K

Kevin D. Goodknecht Sr. [MVP]

Joey R said:
Hello All,

I work at a public library and we're running Windows 2000
Professional on all of the patron computers and Windows 2000 Server
on our server. The server also runs as a PDC.

Recently, we purchased and installed a security program called
PCRefresh that allows the computer to 'refresh' itself whenever the
computer is restarted. For example, if a computer becomes infrected
with a virus, restarting the computer will restore the computer to
it's original settings that we specified.

Unfortunately, we've been noticing an error that comes up about once
a month on all of the locked-down machines. The error reads:

"System cannot log you on to this domain because the systems computer
account in it's primary domain is missing or the password on that
account is incorrect."


I believe the problem lies with the computer changing its password, by
default the computer changes its password on its domain account every seven
days. When PCRefresh rolls back the computer, it rolls back its password to
an earlier password. Then the only thing you can do is delete its account
and rejoin it to its domain.
There is a way to prevent the computer from changing its password, then when
the roll back occurs it should still have the same account password.
You can make this change on the GPO or in the local policy on the computer
if it is not defined in the GPO.

Effects of machine account replication on a domain
http://support.microsoft.com/kb/175468/en-us

How to disable automatic machine account password changes
http://support.microsoft.com/kb/154501/
 
R

Richard Mueller

Kevin D. Goodknecht Sr. said:
I believe the problem lies with the computer changing its password, by
default the computer changes its password on its domain account every
seven
days. When PCRefresh rolls back the computer, it rolls back its password
to
an earlier password. Then the only thing you can do is delete its account
and rejoin it to its domain.
There is a way to prevent the computer from changing its password, then
when
the roll back occurs it should still have the same account password.
You can make this change on the GPO or in the local policy on the computer
if it is not defined in the GPO.

Effects of machine account replication on a domain
http://support.microsoft.com/kb/175468/en-us

How to disable automatic machine account password changes
http://support.microsoft.com/kb/154501/
Computer accounts were reset were every 7 days in NT domains. The system
resets computer accounts every 30 days in Active Directory.

Also, dsquery is not included with Windows 2000 Server. However, a VBScript
program should be able to retrieve whatever info you want.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top