An example of Our approach Comments: Anonymous We got this on a virtualized domain controller. All as expected, and cannot understand why it would need to contact the child domain. See ME883271 for details on this issue. Edit the hosts file on each domain controller. Source

Reviewed DNS and there was also no references to the old domain. Multihoming is bad news.Do you have an _msdcs zone? Intermittently, gpupdate was working and logging event 1704 from SceCli showing it was working. Event ID: 1030 Source: Userenv Source: Userenv Type: Error Description:Windows cannot query for the list of Group Policy objects.

In our case, it helped to upgrade VMWare Tools on our virtualized Domain Controller (Win 2003 SP2). See ME909260 to solve this problem. It corrects itself. Afterward, Group Policy applies every 90 to 120 minutes.

  • An event will be logged when Group Policy is successful.
  • and for quite a while now (unsure how long - I suspect a year or more) they have been having challenges enumerating & applying group policies.  Event ID 1030/1058 would appear
  • From a newsgroup post: "I connected to the Sysvol share as the current user (non- administrator), and noticed that I could get into "mydomain" directory, but when I tried to get
  • This fixed the issue in my case.
  • None of the suggestions has helped me in this case.
  • x 2 Anonymous We started to receive this error in the event logs of a new DC for a new domain after rebooting.
  • However on a hunch I recreated the child domain and Group Policy processed correctly.
  • Thanks 0 Message Expert Comment by:TechInTheWoods2011-12-09 Wonderful step-by-step explanation of the issue.
  • To to this, please use the following command: secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose See ME313222 for more details about the security settings restore.

Tends to behave most of the time. Both had recently upgraded their SBS2003 servers from Trend Micro CSM suite 2.0 to 3.0. If you needs lookups of another zone (internal non-AD, perhaps?) then use conditional forwarders.Both of your DCs should have only 1 enabled NIC with only 1 IP address. Event Id 1030 Group Policy Server 2008 Looks like Windows XP speaks quite a bit differently to AD and wants/needs more information (and expects it from DFS shares - \\.). In fact, from my XP machine, I tried connecting

NetBIOS problems example: ___________________________________________________________________ 4) PURGING THE MUPCACHE I saw this helps some people out with 1030 and 1058 errors, but I had to ask myself what does purging the Event Id 1030 Error Code 8341 Then, example of FRS problem and how to use the burflag registry flag to reset your replication set example on NON-DFSR servers: _________________________________________________________________ 2)DUAL NICS: Multi-homed servers can cause another x 88 Anonymous In my case, it turned out that the problem here was the share permission for ''NT AUTHORITY\SYSTEM'' was missing on the SYSVOL share. Double-click MaxPacketSize, type 1 in the Value data box, click to select the Decimal option, and then click OK. 6.

Finally, I dropped to a command prompt and found this Do you see it?  No, I don't mean my horrible "coloring job" - I mean the Junction pointing to C:\Winnt\path... Event Id 1030 Error Code 55 Another post regarding Event ID 1030 mentioned that passwords stored in the User Account control panel option, then under Password management could be causing the issue. Example \\Domaincontrollername\share (A NetBIOS UNC Path to a share) \\\share (A DNS name to a share) \\123.456.789.101\share (using the IP path to the share) If your UNC path to your Sysvol DCName \\DC2.domain.comOn DC1, the DCName is DC1, on DC2 it is DC2.

Ad Choices Posted by DWHunter on 06/18/2011 at 01:41 AM in Active Directory, Networking, Server 2008 | Permalink Digg This | Save to | | Comments You can follow this conversation by Event Id 1030 Error Code 58 The issue ended up being caused by the KDC service, which was set to manual and was not started. Event Id 1030 Userenv or you can download these tools There are a great set of tools that many administrators use to diagnose and fix Domain and network problems.

You should find an 1704 info about security policy in the GPO applied sucessfully. this contact form After that try a “gpupdate /force” and have a look in the event viewer after. But, from domain joined servers/computers, it was a no go.  I could get to \\server\sysvol\domain but it was empty.  Same with \\domain\sysvol\domain - empty. Added NT AUTHORITY\SYSTEM with ''Full Controll'' permissions and with this, my problem was solved. Event Id 1030 Error Code 1326

If not, you may have a replication problem or you could have a corrup GPO and may need to recreate the GPO. >>ENSURE THE CORRECT SERVICES STARTED: You might also look You can find it here in EE's time tested solutions: _____________________________________________________________________ Conclusion: Just seeing Event errors 1030 and 1058 is not enough to diagnose and find a fix them. The problem was that for this particular user Group Policy was not being applied when he logged in, therefore not enabling "My Documents Redirection". have a peek here See the link to “Dcgpofix” for details on this command.

Spatula Ars Tribunus Angusticlavius et Subscriptor Registered: Oct 28, 1999Posts: 9097 Posted: Mon May 02, 2011 8:29 am No SP1.We do not own our network, the parent org does, and their Event Id 1030 Windows Cannot Query For The List Of Group Policy Objects The server locked after the timeout and I left it that way for a couple days. x 81 Anonymous In my case, the 1030 & 1058 event were fixed by: 1) Change the binding order of the network adapters (ncpa.cpl-advanced-advanced settings), so that the adapter that is

Also, if SMB signing policies are set by the default domain controller security policy, the problem affects all the domain controllers on the network.

There are two places to find these support tools: \\Support\Tools\ file on the Windows Server install disk. Replacement of the flexible network card with a e1000 nic (reboot, reconfigure network TCP/IP settings, reboot) solved the problem. Again, those annoying SBS policies followed. Error Code 8341 Group Policy This will tell you if you have FRS problems.

Go to Network Connections -> Advanced Settings. See ME935918, WITP79913 and WITP81903 for additional information about this event. There are a couple mentions of DFSR with 2003. "2003 Server R2 and newer should never use the BurFlag method because of the enhanced features of DFSR (Distributive File Share Replication) x 9 Anonymous Error 1030 and error 1006 were showing in the event log.

No multihoming, only 1 IP (for IPv4, IPv6 is enabled, but untouched). Thanks. See also ME555651 for more information. I didn't think dcpromo would let a second DC with the same SID be added. 7 posts Ars Technica > Forums > Operating Systems & Software > Windows Technical Mojo Jump

Haven't been able to reliably catch this happening in order to try Wireshark or other tools.Also, when the Windows servers do not come up nicely (they are all set to perform The posts also indicate that the Client for Microsoft Networks and the File and Printer Sharing services have to be bound to the network adapter. However, after a while I discovered I was having all sorts of Group Policy application errors on my Windows XP workstation in my Windows 2000 domain. Thank you Dave Lipman for that fix. :D x 83 Logan K This event occurred on a Windows XP client in conjucture with Event ID 1080 and 4356.

I don't have all the answers, but have helped out a lot of people diagnose and fix these events. Tuesday, June 12, 2012 12:43 AM Reply | Quote Answers 1 Sign in to vote Hi, I thought I would provide an update as this problem was resolved. The requests were for a subdomain of the domain in question, which had been removed months ago. The error stopped when I logged off and logged back on with the new password.

The issue is happening on the DC itself as well, which I don't believe Netmon will capture. Marina Roos wrote an article about this failure but did not tell how to solve the problem. It was "IRC ports" 6666-6668, and posts on the McAfee forums mentioned the issue.