Hi,
I had to restrain the accounts that could log on a production computer to just a few accounts: <username>, <ITGroup>, and Administrators
But I'm getting an error everytime the GPO is refreshed on the computer in the event viewer. Event id: 1202 source: SceCli and event id: 1085 source: Userenv
In my c:\windows\security\logs\winlogon.log I get this error:
error 1332: No mapping between account names and security IDs was done.
Cannot find Administrators
It only gives me the error on a french OS (so of course the error is in french which is why I didn't copy them), but all our servers have english OS. I added the gpo to 1 english workstation and the error didn't happen, and yes I did make sure that the GPO was being applied.
I guess my problem is because in the GPO, the group name isn't translated to a SID number, which any language OS can find.
Is there anything I can do to fix the issue?
I searched on the web, but it's not because the account doesn't exist, it's not a power users group thing and the group policy still works because it only lets a few accounts log on to the computer.
So any ideas would be appreciated.
Thanks!
I had to restrain the accounts that could log on a production computer to just a few accounts: <username>, <ITGroup>, and Administrators
But I'm getting an error everytime the GPO is refreshed on the computer in the event viewer. Event id: 1202 source: SceCli and event id: 1085 source: Userenv
In my c:\windows\security\logs\winlogon.log I get this error:
error 1332: No mapping between account names and security IDs was done.
Cannot find Administrators
It only gives me the error on a french OS (so of course the error is in french which is why I didn't copy them), but all our servers have english OS. I added the gpo to 1 english workstation and the error didn't happen, and yes I did make sure that the GPO was being applied.
I guess my problem is because in the GPO, the group name isn't translated to a SID number, which any language OS can find.
Is there anything I can do to fix the issue?
I searched on the web, but it's not because the account doesn't exist, it's not a power users group thing and the group policy still works because it only lets a few accounts log on to the computer.
So any ideas would be appreciated.
Thanks!