New Computer Issues with domain authentication

S

Sonny

Hello everyone,

I assume i'm having authentication issues... here is the quick rundown.

i'm on a win2k domain... no issues with over 300 existing computers.

I am setting up new computers for my users. The comptuers came imaged from
the factory. i setup a golden machine and sent it to them, they claim
sysprep was run properly and all was fine.

when i get the machines i do my little installs and what have you. all as a
workgroup. Then i join the domain... install other things, setup users and
log the user in to copy down the roaming profile.

the issues arose from users that have logged into their machine and worked
fine. I had a user get a new machine, log in and get a domain error (cannot
locate 'domain controller' log on locally) ... so i have my tech drop and
rejoin the domain... everything works fine.

Then the users work and log on and off without a hitch... then randomly
during a restart or for the first logon of the day... they get 'a duplicate
name exists' and when they try to log on ' domain cannot be contacted' or
'domain controller not found' ...

On my domain controller it logs event is 5722 which reads " the session
setup from the computer 'computername' failed to authenticate. the name of
the account referenced in the security database is 'computername. the
following error occured "access is denied"."

on the client machine i get some GPO errors about loading and no domain
controller.

The solution is to rejoin the domain, or sometimes rename the computer and
rejoin the domain.

i tried to reset the comptuer account in AD and that didn't do anything... i
also tried netdom and that didn't do anything.

any help out there? i'm holding off rolling out new machine due to this
issue. Let me know if you have any ideas!!!!


thanks in advanced.
 
C

Chriss3 [MVP]

Ensure you really have an unique name standard and not duplications as well
ensure DNS is configured and working 100%

--
Regards
Christoffer Andersson
Microsoft MVP - Directory Services

No email replies please - reply in the newsgroup
 
S

Sonny

Thanks!

I have ensured that i have unique names... I have added a letter to the
machine name to dignify the make of machine it's on... for example
machined001 for desktop and machinel001 for laptop.

What is the best way to test DNS? I can ping though and get proper name
resolution... no errors in event logs...
 
S

Sonny

something unusual in DNS is that my users on the new machines are logging
two PTR's for each computer name.

one being

192.168.0.1 computer
192.168.0.1 computer.domain.com

is this an indication of anything?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top