![]() |
|
|
|||||||
| Petri.co.il is happy to award auglan the title of Most Valuable Member !!! |
| Register | Calendar |
Search |
Today's Posts |
Mark Forums Read |
| Notices |
|
|
default permission for default domain policy in SYSVOL ?this thread has 6 replies and has been viewed 22010 times
|
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||||||
|
||||||||
|
I'm getting 1058/1030 errors and it's pointing to an access denied error on gpt.ini in the default domain policy. I'm getting this on all DC's on my child domain in the event viewer.
I've consulted the following thread as well: http://www.petri.co.il/forums/showthread.php?t=1101 and numerous others. so far i know this: 1. i can net user \\anydc\sysvol and no connection issue 2. I can physically access the files and all folders that the error is pointing to on any dc When I checked the folder permission for folder {31B..} under \\DC\SYSVOL\child.domain.com\policies\{31b..} was: Administrators - Full Control Authenticated users - Read and Execute Server Operators - Read and Execute Creator Owner - Special - Full Control System - Special - Full Control this was inherited to all file and folders under the root folder. Is the permissions correct? What is the default permissions for default domain policy in sysvol share? the other GPO's folder permissions are: Domain Admins (Child Domain\Domain Admins) - Full Control Creator Owner - Full Control SYSTEM - Full Control Enterprise ADmins (Root forest\Enterprise Admins) - full control Authenticated Users - Read and Execute Enterprise Domain Controllers - Read and Execute should i reset the "problem" folder to the the following above? I really hate this error because it's so hard to track down. Other than seeing this on my event viewer, there is nothing wrong with the domain. Users can login and so forth. Thanks in advance |
|
#2
|
|||||||||||
|
|||||||||||
|
Hi,
Check this out: http://support.microsoft.com/kb/888943 http://support.microsoft.com/kb/842804 Regards,
__________________
Kapil Sharma ~~~~~~~~~~~~~ Life is too short, Enjoy It. |
|
#3
|
||||||||
|
||||||||
|
Thanks for your reply.
The first KB article doesn't apply to me as I don't have problems opening up the gpo snap-in. I've looked through the 2nd article and verified the services are started. I've doubled checked the sysvol share/ntfs permission and it's set to what other articles have pointed out. I'm curious, but under the sysvol/policies share, are all the permissions there different for every policy? Does anyone know what the default domain policy permissions should be? |
|
#4
|
||||||||
|
||||||||
|
I've also noticed a strange thing. On my DC, whenever I access the sysvol share, i get an event ID 3019 MRxSMB warning - The redirector failed to determine the connection type?
every time i navigate a folder I get one warning in the SYSVOL share. Is this normal? |
|
#5
|
|||||||||||
|
|||||||||||
|
__________________
Kapil Sharma ~~~~~~~~~~~~~ Life is too short, Enjoy It. |
|
#6
|
|||||||||||
|
|||||||||||
|
Additionally default permissions are as given in below KB:
http://support.microsoft.com/kb/319808 Regards,
__________________
Kapil Sharma ~~~~~~~~~~~~~ Life is too short, Enjoy It. |
|
#7
|
||||||||
|
||||||||
|
Thanks for the links!
so status update, after rebooting the servers the messages have completely disappeared. prior to that, I thought there was some FRS replication issue or something so i watched it with sonar and nothing turned up. As far as I can tell, the domain was functioning fine before the reboot. After the reboot there has been no change in functionality, just the errors are gone. this is quite mysterious. |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| default Domain policy | elliottd | Windows Server 2000 / 2003 | 3 | 15th October 2007 18:43 |
| Reseting Default Domain Policy... | thecoffeeguy | Windows Server 2000 / 2003 | 9 | 1st June 2007 07:10 |
| Default Domain Policy | scyzo | Windows Server 2000 / 2003 | 1 | 11th September 2006 16:12 |
| Adding Domain user accounts by default to the Administrators group of domain computer | smjailani | Windows Server 2000 / 2003 | 2 | 26th August 2006 07:56 |
| placing vplogon.bat default user profile policy under group policy win2003 server | gila | GPO | 2 | 10th October 2005 04:23 |