Hello,
We are running a simple windows 2003 domain with 1 domain controller (w2k3 x64). A recent attempt to upgrade the domain to a 2008 server failed, mainly due to a lack of delegation permissions. That pointed us to the group policies.
Looking at the DC after this, we started to get a lot of Event log errors 1030 and 1097 (see below). We are able to run the group policy MMC from an XP x32, and make changes to the group policy. I can make changes and see those reflected on client PCs (win7 and XP) by looking at the gpresult output. We have the 3 basic policies that came with the domain: Default DC Policy, Default Domain Policy, Default Password Policy. To help with troubleshooting, I've renamed these slightly by adding a 1 to the end (ie "Default Domain Policy1") and added an empty test policy. Again, I see the changes on my client machines, but on the DC, gpresult reports that only the USER SETTINGS are coming from the new policies. The COMPUTER settings are still listed from the old/non-existent policies. (See example below).
We've run a DCDIAG, netdiag which come back fine. We've been through a lot of the other suggestions for the Event 1030 error with no luck.
Any thoughts? Thanks
COMPUTER SETTINGS------------------
CN=SHIRLEY,OU=Domain Controllers,DC=han***,DC=com
Last time Group Policy was applied: 5/17/2013 at 1:17:37 PM
Group Policy was applied from: SHIRLEY.han***.com
Group Policy slow link threshold: 500 kbps
Domain Name: han***
Domain Type: Windows 2000
Applied Group Policy Objects
-----------------------------
DomainPasswordPolicy
Default Domain Controllers Policy
Default Domain Policy
Local Group Policy
...
USER SETTINGS--------------
CN=m***,CN=Users,DC=han****,DC=com
Last time Group Policy was applied: 5/17/2013 at 11:57:46 AM
Group Policy was applied from: SHIRLEY.han***.com
Group Policy slow link threshold: 500 kbps
Domain Name: HAN***
Domain Type: Windows 2000
Applied Group Policy Objects
-----------------------------
Default Domain Policy1
Default Domain Policy1
Local Group Policy
-------------------------------------------------------------------------
Event Type:Error
Event Source:Userenv
Event Category:None
Event ID:1097
Date:5/17/2013
Time:12:32:35 PM
User:NT AUTHORITY\SYSTEM
Computer:SHIRLEY
Description:
Windows cannot find the machine account, The logon attempt failed .
-------------------------------------------------------------------------
Event Type:ErrorEvent Source:Userenv
Event Category:None
Event ID:1030
Date:5/17/2013
Time:12:32:35 PM
User:NT AUTHORITY\SYSTEM
Computer:SHIRLEY
Description:
Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.