Click here to get back home

Failure to update domain policy Impersonate a client after authenication

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Failure to update domain policy Impersonate a client after authenication Eddie 05-22-2007
Posted by Eddie on May 22, 2007, 3:43 am
Please log in for more thread options
I made a mistake and messed up a group policy on our domain. Having
changed the policy "Impersonate a client after authenication", its
screwed up the domain controller (i missed off service). It was
changed very quickly after going through the process of changing the
RPC service identity, resetting the policy and several reboots. The
active directory looks rights, but sometimes clients pick up the old
policy and can't shake it. I just added a new machine to the domain
and on its second reboot it picked up the rogue policy. I have no idea
where is can still be picking it up from. its frustrating to say the
least. I thought it had something to do with cached credentials, but
it happened on a new machine.

gpupdate /force was run, but on the next reboot it was back. its
driving me a little crazy :)

We have a single domain with three AD servers.


Posted by Roger Abell [MVP] on May 28, 2007, 11:49 pm
Please log in for more thread options
>I made a mistake and messed up a group policy on our domain. Having
> changed the policy "Impersonate a client after authenication", its
> screwed up the domain controller (i missed off service). It was
> changed very quickly after going through the process of changing the
> RPC service identity, resetting the policy and several reboots. The
> active directory looks rights, but sometimes clients pick up the old
> policy and can't shake it. I just added a new machine to the domain
> and on its second reboot it picked up the rogue policy. I have no idea
> where is can still be picking it up from. its frustrating to say the
> least. I thought it had something to do with cached credentials, but
> it happened on a new machine.
>
> gpupdate /force was run, but on the next reboot it was back. its
> driving me a little crazy :)
>
> We have a single domain with three AD servers.
>

Have you yet verified that replication is happening as expected?
replmon is one tool to use to check this
You probably should also run netdiag and dcdiag at each domain
controller to establish a baseline of AD health before going too
far down the road of researching/resolving this specific issue.



Similar ThreadsPosted
Client and Domain controller across a firewall March 31, 2008, 5:32 am
Windows XPx64 does not require user authenication against Sharepoi February 20, 2007, 6:42 am
Domain Controller Security Policy August 12, 2005, 4:31 pm
secpol on DC vs. Default Domain Policy? November 30, 2006, 6:12 pm
Default Domain Controllers Policy scope May 15, 2006, 11:26 am
Windows 2003 domain password policy September 26, 2006, 9:53 pm
Default domain controllers policy not applied to my server (2k3 sbs) January 3, 2006, 8:32 am
Domain Security Policy -> Access is denied for Administrator July 17, 2006, 7:04 am
Domain Controller Policy setting "Allow log on through Terminal Services" April 1, 2008, 12:01 pm
Discrepancy between MS Update and MSBSA August 23, 2005, 12:30 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap