Petri IT Knowledgebase Forums
 

Petri.co.il forums Home Forums Start Page Forums Frequently Asked Questions FAQ Member List Members List
Go Back   Petri IT Knowledgebase Forums > Microsoft Networking Services > Active Directory
Petri.co.il is happy to award auglan the title of Most Valuable Member !!!
Register Calendar Calendar Search Petri IT Knowledgebase Forums Search Todays Posts Today's Posts Mark Forums Read

Notices

default permission for default domain policy in SYSVOL ?

default permission for default domain policy in SYSVOL ?

this thread has 6 replies and has been viewed 22010 times

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 3rd January 2008, 02:17
roguecoolman roguecoolman is offline
Junior Member
It's not a coincidence
 
 Join Date: Aug 2004
  6 month star 12 month star
 Posts: 139
 Reputation: roguecoolman is on a distinguished road (22)
Default default permission for default domain policy in SYSVOL ?

I'm getting 1058/1030 errors and it's pointing to an access denied error on gpt.ini in the default domain policy. I'm getting this on all DC's on my child domain in the event viewer.

I've consulted the following thread as well: http://www.petri.co.il/forums/showthread.php?t=1101

and numerous others.

so far i know this:

1. i can net user \\anydc\sysvol and no connection issue
2. I can physically access the files and all folders that the error is pointing to on any dc

When I checked the folder permission for folder {31B..} under \\DC\SYSVOL\child.domain.com\policies\{31b..}

was:

Administrators - Full Control
Authenticated users - Read and Execute
Server Operators - Read and Execute
Creator Owner - Special - Full Control
System - Special - Full Control

this was inherited to all file and folders under the root folder.

Is the permissions correct? What is the default permissions for default domain policy in sysvol share?

the other GPO's folder permissions are:

Domain Admins (Child Domain\Domain Admins) - Full Control
Creator Owner - Full Control
SYSTEM - Full Control
Enterprise ADmins (Root forest\Enterprise Admins) - full control
Authenticated Users - Read and Execute
Enterprise Domain Controllers - Read and Execute

should i reset the "problem" folder to the the following above?

I really hate this error because it's so hard to track down.

Other than seeing this on my event viewer, there is nothing wrong with the domain. Users can login and so forth.


Thanks in advance
  #2  
Old 3rd January 2008, 12:16
kapilsharma11's Avatar
kapilsharma11 kapilsharma11 is offline
Member
Here to help
 
 Join Date: Oct 2005
  6 month star 12 month star
 Location: India
 Posts: 551
  Send a message via MSN to kapilsharma11
 Reputation: kapilsharma11 will become famous soon enoughkapilsharma11 will become famous soon enough (106)
Default Re: default permission for default domain policy in SYSVOL ?

Hi,

Check this out:

http://support.microsoft.com/kb/888943

http://support.microsoft.com/kb/842804

Regards,
__________________
Kapil Sharma
~~~~~~~~~~~~~
Life is too short, Enjoy It.
  #3  
Old 3rd January 2008, 20:03
roguecoolman roguecoolman is offline
Junior Member
It's not a coincidence
 
 Join Date: Aug 2004
  6 month star 12 month star
 Posts: 139
 Reputation: roguecoolman is on a distinguished road (22)
Default Re: default permission for default domain policy in SYSVOL ?

Thanks for your reply.

The first KB article doesn't apply to me as I don't have problems opening up the gpo snap-in.

I've looked through the 2nd article and verified the services are started. I've doubled checked the sysvol share/ntfs permission and it's set to what other articles have pointed out.

I'm curious, but under the sysvol/policies share, are all the permissions there different for every policy? Does anyone know what the default domain policy permissions should be?
  #4  
Old 3rd January 2008, 20:12
roguecoolman roguecoolman is offline
Junior Member
It's not a coincidence
 
 Join Date: Aug 2004
  6 month star 12 month star
 Posts: 139
 Reputation: roguecoolman is on a distinguished road (22)
Default Re: default permission for default domain policy in SYSVOL ?

I've also noticed a strange thing. On my DC, whenever I access the sysvol share, i get an event ID 3019 MRxSMB warning - The redirector failed to determine the connection type?

every time i navigate a folder I get one warning in the SYSVOL share. Is this normal?
  #5  
Old 4th January 2008, 12:09
kapilsharma11's Avatar
kapilsharma11 kapilsharma11 is offline
Member
Here to help
 
 Join Date: Oct 2005
  6 month star 12 month star
 Location: India
 Posts: 551
  Send a message via MSN to kapilsharma11
 Reputation: kapilsharma11 will become famous soon enoughkapilsharma11 will become famous soon enough (106)
Default Re: default permission for default domain policy in SYSVOL ?

Hi,

You can safely ignore this information:

http://support.microsoft.com/kb/315244

Regards,
__________________
Kapil Sharma
~~~~~~~~~~~~~
Life is too short, Enjoy It.
  #6  
Old 4th January 2008, 12:15
kapilsharma11's Avatar
kapilsharma11 kapilsharma11 is offline
Member
Here to help
 
 Join Date: Oct 2005
  6 month star 12 month star
 Location: India
 Posts: 551
  Send a message via MSN to kapilsharma11
 Reputation: kapilsharma11 will become famous soon enoughkapilsharma11 will become famous soon enough (106)
Default Re: default permission for default domain policy in SYSVOL ?

Additionally default permissions are as given in below KB:

http://support.microsoft.com/kb/319808

Regards,
__________________
Kapil Sharma
~~~~~~~~~~~~~
Life is too short, Enjoy It.
  #7  
Old 7th January 2008, 22:09
roguecoolman roguecoolman is offline
Junior Member
It's not a coincidence
 
 Join Date: Aug 2004
  6 month star 12 month star
 Posts: 139
 Reputation: roguecoolman is on a distinguished road (22)
Default Re: default permission for default domain policy in SYSVOL ?

Thanks for the links!

so status update, after rebooting the servers the messages have completely disappeared.

prior to that, I thought there was some FRS replication issue or something so i watched it with sonar and nothing turned up. As far as I can tell, the domain was functioning fine before the reboot. After the reboot there has been no change in functionality, just the errors are gone.

this is quite mysterious.
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
default Domain policy elliottd Windows Server 2000 / 2003 3 15th October 2007 18:43
Reseting Default Domain Policy... thecoffeeguy Windows Server 2000 / 2003 9 1st June 2007 07:10
Default Domain Policy scyzo Windows Server 2000 / 2003 1 11th September 2006 16:12
Adding Domain user accounts by default to the Administrators group of domain computer smjailani Windows Server 2000 / 2003 2 26th August 2006 07:56
placing vplogon.bat default user profile policy under group policy win2003 server gila GPO 2 10th October 2005 04:23


All times are GMT +3. The time now is 18:37.

Steel Blue 3.5.4 vBulletin Style ©2006 vBEnhanced
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
 

Valid XHTML 1.0!   Valid CSS!

Copyright 2005 Daniel Petri