Windows 98 in Windows 200 Domain

G

Guest

Hi,

I am having a problem and I can find no resolution.

I have recently put into place 2 domain controllers at 2 remote sites to help take the load off off my central location's domain controllers for authentication. I have also created shares and user directories onto these servers and moved all the remote users files onto the appropriate servers. I created logon scripts that map the users at these remote sites to these shares and home directories. I have also repointed the My Documents icon to the users home directory on the WIndows 98 machines. The Windows 2000 machines map the drive prefectly.

Here is the problem:

The Windows 200 machines are all functioning properly, but the Windows 98 machines have this problem. They keep locking out the users account when the user clicks on a mapped drive or the My Documents icon. This ONLY happens to the 98 machines of the users where I put the 2 domain controllers. All the other sites that have 98 machines that access the Central office servers still work 100%. I sit there and watch in "AD Users and Computers" as the user account gets locked out when I tell them to click on the drive or the My documents.

This is what I have done to troubleshoot:

I have checked the permissions for the shares and the folder security and all are set properly.
I tried loading DS Client on the 98 Machines
All Servers are on Service Pack 4
I have checked DNS for any thing Odd

At this point, I am at a loss. My Windows 98 users at the remote sites are getting frustrated. HELP!!!!!

Any help or guidance is MOST appreciated.

Thanks in advance
Please Email me any solution you may have

Mike Wolf
(e-mail address removed)
 
G

Guest

Something that popped into my head is the PDC Emulator. Windows 9x and NT4 use the PDC Emulator for password changes. One PDC Emulator per domain. Check communication with it. That doesn't really sound like the problem you're having, but you never know. Just a base to cover really

Steve
 
D

Dale Weiss

Hello,

Have you checked replication between all of the domain controllers? Is is
possible that the users are logged into more than one machine and a
password change has occurred?

It also might be useful to see which domain controller is really logging
the users on. See this article:

150898 How to Display Domain Logon Confirmation in Windows
http://kb/article.asp?id=Q150898

Dale Weiss MCSA MCSE CISSP
PSS Security

This posting is provided "AS IS" with no warranties, and confers no rights.
Any opinions or policies stated within are my own and do not necessarily
constitute those of my employer. Use of included script samples are subject
to the terms
specified at http://www.microsoft.com/info/cpyright.htm
 
G

Guest

Thanks for the feedback.

The problem is happeneing to only the users at the 2 remote sites that I put the 2 new domain controllers in. I know that they are not logging into multiple machines and I know that the passwords are not changing. It is happeneing to too many people.

How do I go about verifying that the replication between the domain controllers is working properly?

As I said before, it is only when the user at the remote site tried to access a network share on that new server. Before I put the remote servers into place and they were being authenticated and accessing all their files at the central office, it was working beautifully.

So I cannot for the life of me figure out what is different on those 2 domain controllers.

HELP!!!!

Thanks in advance

Mike
 
G

Guest

I looked at article 150898 and put the value in the registry to show me what server validated one of the 98 machines that is having the problem. It is being validated by the new domain controller that was installed at that site.

So any ideas as to where to go from here?
 
D

Dale Weiss

Hello Michael,

I did a bit more research on this and found that the problem you are seeing
*may* be related to one discussed in this article:

278558 Mapped Drive Access Denied to Windows 2000-Based Server
http://kb/article.asp?id=Q278558

Are you using the Directory Service Client for Windows 9X? Perhaps this
would help, and it would also allow users to change passwords with a local
DC rather than the PDC emulator which might be across the WAN.

It appears that Windows 98 can send invalid credentials when accessing a
share that has been autodisconnected.


Dale Weiss MCSA MCSE CISSP
PSS Security

This posting is provided "AS IS" with no warranties, and confers no rights.
Any opinions or policies stated within are my own and do not necessarily
constitute those of my employer. Use of included script samples are subject
to the terms
specified at http://www.microsoft.com/info/cpyright.htm
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top