Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Active Directory Users Cannot Access Servers

Status
Not open for further replies.

Schmakt

IS-IT--Management
Jun 15, 2007
3
US
Servers: 2x AD servers running W2k3 Enterprise SP2
Crimson -> 1 NIC, PDC, Terminal Server
Clover -> 2 NIC (one internal, one external), Remote Access, DFS, File Server
Workstations: mix of W2k Pro, XP Pro, and Vista Business

No AD users (including Administrator) are able to access any shares on the servers this morning.
Vista Error message when accessing \\Crimson or \\Clover:
\\[ServerName] is not accessible. You might not have permission to use this network resource. Contact the administrator of this server to find out if you have access permissions

Logon failure: the user has not been granted the requested logon type at this computer.

When I looked at Clover, there was a dialer program on the machine, which I uninstalled.
I then ran AVG Pro 7, and it returned no threats.
When I rebooted Clover and tried to log back in, I was given the error:
Not enough storage is available to process this commend

I was able to boot into safe mode - removing the AVG Services from startup using msconfig allowed me to boot the machine and login regularly.
After getting back in, I uninstalled AVG (and AVG Firewall)
Crimson rebooted with no issues.

Now both servers are bootable and running ok, but I still get the access denied errors when trying to access either server from anywhere else on the network.
When I attempt to edit Local Computer Policy -> Windows Settings -> Security Settings -> Local Policies -> User Rights Assignments -> Access this computer from the network, I see the following users:
Enterprise Domain Controllers
IUSR_CLOVER
IUSR_CRIMSON
IWAM_CLOVER
IWAM_CRIMSON

And the "Add User or Group" and "Remove" buttons are greyed out, so I cannot add anything to the policy. (I am currently logged on as the Administrator)

I then attempted to recreate the Default Domain Group Policies using dcgpofix, and this gave me the following error:
Unable to read EFS certificates from Registry.pol file of Default Domain Policy. The error was Logon failure: the user has not been granted the requested logon type at this computer.

While I was attempting to solve this problem on Crimson, I tried installing some hotfixes from Microsoft on Clover. While doing that, the installation failed for:
SQL Service Pack 2
Intel - Networking - Intel(R) PRO/1000 GT Desktop Adapter
SQL Server 2005 Service Pack 1

As best I can tell, the root of all of my problems is that the GPO access levels were reset either by some sort of hack... and right now, I'm completely stuck.

Is there some way to force the rights to be reset to default while the Admin account has no access?

Any thoughts at all are very very very appreciated. Thanks...
 
Restore your system state from backup?

I hope you find this post helpful.

Regards,

Mark

Check out my scripting solutions at
Work SMARTER not HARDER. The Spider's Parlor's Admin Script Pack is a collection of Administrative scripts designed to make IT Administration easier! Save time, get more work done, get the Admin Script Pack.
 
That's what I was afraid of... This system configuration is new as of Monday, and it was all working yesterday... and I scheduled the first backup to run early this morning.

So my backup's the same as my frontup.

Looks like I might end up in format/reinstall mode... which is always fun with DC's. Ugh. Thanks for the suggestion. :)
 
Setup a temporary DC so you can replicate your AD and preserve SIDs. Then rebuild and join the server back.

I hope you find this post helpful.

Regards,

Mark

Check out my scripting solutions at
Work SMARTER not HARDER. The Spider's Parlor's Admin Script Pack is a collection of Administrative scripts designed to make IT Administration easier! Save time, get more work done, get the Admin Script Pack.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top