Article ID: 839499 - Last Review: December 3, 2007 - Revision: 6.3 You cannot open file shares or Group Policy snap-ins when you disable SMB signing for the Workstation or Server service on a domain controllerOn This PageSUMMARYThis article discusses how to resolve the following two problem scenarios that may occur in Microsoft Windows Server 2003 or in Microsoft Windows 2000 Server:
SYMPTOMSScenario 1 - SMB signing is disabled for the Workstation service on a domain controller, but SMB signing is required for the Server service on the same domain controller.Windows Server 2003When you try to open Group Policy snap-ins on the domain controller, you receive an error message that is similar to the following:You do not have permission to perform this operation. Access is denied. Event Type: Error Event Source: Userenv Event Category: None Event ID: 1058 User: NT AUTHORITY\SYSTEM Description: Windows cannot access the file gpt.ini for GPO CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=Domain_Name,DC=com. The file must be present at the location <\\Domain_Name.com\sysvol\Domain_Name.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>. (Access is denied.) Group Policy processing aborted. For more information, see Help and Support Center at http://support.microsoft.com. Event Type: Error Event Source: Userenv Event Category: None Event ID: 1030 User: NT AUTHORITY\SYSTEM Description: Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this. For more information, see Help and Support Center at http://support.microsoft.com. When you log on to the server locally and then try to open shares on the server, you receive repeated password prompts, and you cannot open the shares. Windows 2000 ServerWhen you try to open Group Policy snap-ins on the domain controller, you receive an error message that is similar to the following:You do not have permission to perform this operation. Access is denied. Event Type: Error Event Source: Userenv Event Category: None Time: 4:07:30 PM User: NT AUTHORITY\SYSTEM Description: Windows cannot access the registry information at \\Domain_Name.com\sysvol\Domain_Name.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\registry.pol with (5). Scenario 2 - SMB signing is disabled for the Server service on a domain controller, but SMB signing is required for the Workstation service on the same domain controller.Windows Server 2003When you try to open Group Policy snap-ins on the domain controller, you receive an error message that is similar to the following:Failed to open the Group Policy Object. You may not have the appropriate rights. The account is not authorized to log in from this station. 1240 (ERROR_LOGIN_WKSTA_RESTRICTION) Event Type: Error Event Source: Userenv Event Category: None Event ID: 1058 User: NT AUTHORITY\SYSTEM Description: Windows cannot access the file gpt.ini for GPO CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=Domain_Name,DC=com. The file must be present at the location <\\domainname.com\sysvol\Domain_Name.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>. (The network path was not found.) Group Policy processing aborted. For more information, see Help and Support Center at http://support.microsoft.com. Event Type: Error Event Source: Userenv Event Category: None Event ID: 1030 User: NT AUTHORITY\SYSTEM Description: Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this. For more information, see Help and Support Center at http://support.microsoft.com. When you log on to the server locally and then try to open file shares on the server, you receive an error message that is similar to the following: \\Server_Name\Share_Name is not accessible. You might not have permission to use this network resource. Contact the administrator of this server to find out if you have access permissions. The account is not authorized to log in from this station. Note In a network trace, if SMB signing is enabled, and if SMB signing is required at the client and is disabled at the server, the connection to the TCP session is gracefully closed after the dialect negotiation. Also, the client receives the following error message: 1240 (ERROR_LOGIN_WKSTA_RESTRICTION) Windows 2000 ServerWhen you try to open Group Policy snap-ins on the domain controller, you receive an error message that is similar to the following:Failed to open the Group Policy Object. You may not have the appropriate rights. The account is not authorized to log in from this station. Event Type: Error Event Source: Userenv Event Category: None Event ID: 1000 User: NT AUTHORITY\SYSTEM Description: Windows cannot access the registry information at \\Domain_Name.com\sysvol\Domain_Name.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\registry.pol with (1240). \\Server_Name\Share_Name is not accessible. The account is not authorized to log in from this station. Note In a network trace, if SMB signing is enabled, and if SMB signing is required at the client and is disabled at the server, the connection to the TCP session is gracefully closed after the dialect negotiation. Also, the client receives the following error message: 1240 (ERROR_LOGIN_WKSTA_RESTRICTION) CAUSEThis behavior occurs if the SMB signing settings for the Workstation service and for the Server service contradict each other. When you configure the domain controller in this way, the Workstation service on the domain controller cannot connect to the domain controller's Sysvol share. Therefore, you cannot start Group Policy snap-ins. Also, if SMB signing policies are set by the default domain controller security policy, the problem affects all the domain controllers on the network. Therefore, Group Policy replication in the Active Directory directory service will fail, and you will not be able to edit Group Policy to undo these settings. RESOLUTIONTo resolve this behavior, follow these steps. Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base: 322756
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in Windows
MORE INFORMATIONIf you run the domain controller diagnostic tool (DcDiag.exe) in scenario 1, you receive errors that are similar to the following for Windows 2000 and for Windows Server 2003: Starting test: MachineAccount Could not open pipe with [SERVERNAME]:failed with 5: Access is denied. Could not get NetBIOSDomainName Failed can not test for HOST SPN Failed can not test for HOST SPN * Missing SPN :(null) * Missing SPN :(null) ......................... SERVERNAME failed test MachineAccount Starting test: Services Could not open Remote ipc to [SERVERNAME]:failed with 5: Access is denied. ......................... SERVERNAME failed test Services Starting test: ObjectsReplicated ......................... SERVERNAME passed test ObjectsReplicated Starting test: frssysvol [SERVERNAME] An net use or LsaPolicy operation failed with error 5, Access is denied.. ......................... SERVERNAME failed test frssysvol Starting test: frsevent ......................... SERVERNAME failed test frsevent Starting test: kccevent Failed to enumerate event log records, error Access is denied. ......................... SERVERNAME failed test kccevent Starting test: systemlog Failed to enumerate event log records, error Access is denied. ......................... SERVERNAME failed test systemlog Testing server: Default-First-Site-Name\SERVERNAME Starting test: Replications ......................... SERVERNAME passed test Replications Starting test: NCSecDesc ......................... SERVERNAME passed test NCSecDesc Starting test: NetLogons [SERVERNAME] An net use or LsaPolicy operation failed with error 1240, The account is not authorized to log in from this station.. ......................... SERVERNAME failed test NetLogons Starting test: Advertising ......................... SERVERNAME passed test Advertising Starting test: KnowsOfRoleHolders ......................... SERVERNAME passed test KnowsOfRoleHolders Starting test: RidManager ......................... SERVERNAME passed test RidManager Starting test: MachineAccount Could not open pipe with [SERVERNAME]:failed with 1240: The account is not authorized to log in from this station. Could not get NetBIOSDomainName Failed can not test for HOST SPN Failed can not test for HOST SPN * Missing SPN :(null) * Missing SPN :(null) ......................... SERVERNAME failed test MachineAccount Starting test: Services Could not open Remote ipc to [SERVERNAME]:failed with 1240: The account is not authorized to log in from this station. ......................... SERVERNAME failed test Services Starting test: ObjectsReplicated ......................... SERVERNAME passed test ObjectsReplicated Starting test: frssysvol [SERVERNAME] An net use or LsaPolicy operation failed with error 1240, The account is not authorized to log in from this station.. ......................... SERVERNAME failed test frssysvol Starting test: frsevent ......................... SERVERNAME failed test frsevent Starting test: kccevent Failed to enumerate event log records, error The account is not authorized to log in from this station. ......................... SERVERNAME failed test kccevent Starting test: systemlog Failed to enumerate event log records, error The account is not authorized to log in from this station. ......................... SERVERNAME failed test systemlog The third-party products that this article discusses are manufactured by companies that are independent of Microsoft. Microsoft makes no warranty, implied or otherwise, about the performance or reliability of these products. APPLIES TO
| Article Translations
|
Back to the top
