Anyone know anything about Active Directory?

A forum for the discussion of issues technical and computer.
Post Reply
Uziel
Posts: 12
Joined: Sat Dec 18, 2004 5:01 am
Contact:

Anyone know anything about Active Directory?

Post by Uziel »

I'm having a bizarre problem in a Windows 2000 server environment, and I'm looking for someone to help me bounce some ideas around. Anyone out there know much about Active Directory and GPOs?
User avatar
karmakaze
Posts: 1222
Joined: Wed May 07, 2003 10:36 am
Location: 31337
Contact:

Post by karmakaze »

whats the problem?
Making a HONDA fast is like coming out of the closet, yeah you might suprise a few people; but in the end.. your still gay.
-
http://www.xanga.com/karmakaze
http://www.myspace.com/karmakaze
Uziel
Posts: 12
Joined: Sat Dec 18, 2004 5:01 am
Contact:

Post by Uziel »

Alright,

The problem, in short, is client machines not refreshing GPOs.

Here's what I know:

Domain authentication is working
GPO refresh settings are synchronous on logon and startup
DNS is working
As far as I know, Active Directory Integrated Zone in DNS is working.
No error messages are being generated.
Group membership is working.

Any thoughts?
User avatar
karmakaze
Posts: 1222
Joined: Wed May 07, 2003 10:36 am
Location: 31337
Contact:

Post by karmakaze »

Uziel wrote:Alright,

The problem, in short, is client machines not refreshing GPOs.

Here's what I know:

Domain authentication is working
GPO refresh settings are synchronous on logon and startup
DNS is working
As far as I know, Active Directory Integrated Zone in DNS is working.
No error messages are being generated.
Group membership is working.

Any thoughts?


that is wierd.

so it is authenticating fine,
they become a part of the domain,

but to become part of the domain the clients have to be receiving the GPO. (the DNS name is the top level of the forest)

What kind of domain model? if you have more than one domain to they all trust each other?

What sort of auth. protocol are you using? Kerebros?

you also might want to check to make sure that there are not any LGPOs on the clients that might conflict with the GPO.
Making a HONDA fast is like coming out of the closet, yeah you might suprise a few people; but in the end.. your still gay.
-
http://www.xanga.com/karmakaze
http://www.myspace.com/karmakaze
Uziel
Posts: 12
Joined: Sat Dec 18, 2004 5:01 am
Contact:

Post by Uziel »

Clients don't have to recieve the GPO to authenticate, only a copy of the SAM.

I just did fresh installations, so there are no LGPOs.

Kerebos is the auth. protocol.

The domain is ridiculously small, no trust issues.

I'll verify the GPOs when I get into work tomorrow. If nothing else, I'll reboot and kick the Domain Controller.
Uziel
Posts: 12
Joined: Sat Dec 18, 2004 5:01 am
Contact:

Post by Uziel »

I fixed the problem. Just as a FYI, the client machines were only pulling local GPOs, and only authenticating through Netbios. The problem resided in DNS.

Thus, I had to ensure that I had an Active Directory Integrated Zone, set for dynamic updates, with an associated SRV record pointing to a domian controller.
Post Reply
Users browsing this forum: No registered users and 1 guest