I've had this problem for a while and the only fix I have is to reboot the workstation. Sometimes it's good for a few weeks, sometimes only a couple of days. And sometimes I have to reboot several times. Here is what I can see in the event viewer for the latest incidence.
ON WORKSTATION, the following error occurred over 100 times (Application Events), one for every 4-5 min for almost all users, with no user logon attempt.
Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1030
Date: 2/27/2008
Time: 8:39:09 PM
User: NT AUTHORITY\SYSTEM
Computer: WORKSTATION
Description:
Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.
Then later on, when user attempts to log in, the following starts to show in Application Events
Event Source: Winlogon
Event Category: None
Event ID: 1219
Date: 2/28/2008
Time: 1:26:59 PM
User: N/A
Computer: WORKSTATION
Description:
Logon rejected for DOMAIN\user. Unable to obtain Terminal Server User Configuration. Error: Not enough resources are available to complete this operation.
The domain server event log showing Netlogin error, though the time does not match the workstation:
Event Type: Error
Event Source: NETLOGON
Event Category: None
Event ID: 5723
Date: 2/27/2008
Time: 9:16:32 PM
User: N/A
Computer: DomainServer
Description:
The session setup from computer 'XXXX-YYYYYYYYY' failed because the security database does not contain a trust account 'XXXX-YYYYYYYYY$' referenced by the specified computer.
How can I tell which computer the above log is referring to? XXXX appears to be the domain name and Y appears to be hexdecimal.
What's exhausting resources on the workstation? Event 1030?
I can see hundreds of audit events in security event viewer. Is that exhausting resource?
Anyway for me to troubleshoot the problem?
Thanks!
ON WORKSTATION, the following error occurred over 100 times (Application Events), one for every 4-5 min for almost all users, with no user logon attempt.
Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1030
Date: 2/27/2008
Time: 8:39:09 PM
User: NT AUTHORITY\SYSTEM
Computer: WORKSTATION
Description:
Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.
Then later on, when user attempts to log in, the following starts to show in Application Events
Event Source: Winlogon
Event Category: None
Event ID: 1219
Date: 2/28/2008
Time: 1:26:59 PM
User: N/A
Computer: WORKSTATION
Description:
Logon rejected for DOMAIN\user. Unable to obtain Terminal Server User Configuration. Error: Not enough resources are available to complete this operation.
The domain server event log showing Netlogin error, though the time does not match the workstation:
Event Type: Error
Event Source: NETLOGON
Event Category: None
Event ID: 5723
Date: 2/27/2008
Time: 9:16:32 PM
User: N/A
Computer: DomainServer
Description:
The session setup from computer 'XXXX-YYYYYYYYY' failed because the security database does not contain a trust account 'XXXX-YYYYYYYYY$' referenced by the specified computer.
How can I tell which computer the above log is referring to? XXXX appears to be the domain name and Y appears to be hexdecimal.
What's exhausting resources on the workstation? Event 1030?
I can see hundreds of audit events in security event viewer. Is that exhausting resource?
Anyway for me to troubleshoot the problem?
Thanks!