Select the product you need help with
Group Policy may not be applied to users belonging to many groupsArticle ID: 263693 - View products that this article applies to. This article was previously published under Q263693 NoticeThis article applies to Windows 2000. Support for Windows 2000 ends on July 13, 2010. The Windows 2000 End-of-Support Solution Center
(http://support.microsoft.com/?scid=http%3a%2f%2fsupport.microsoft.com%2fwin2000)
is a starting point for planning your migration strategy from Windows 2000. For more information see the Microsoft Support Lifecycle
Policy
(http://support.microsoft.com/lifecycle/)
.On This PageSYMPTOMS If a user is a member of many groups either directly or
because of group nesting, Kerberos authentication may not work. The Group
Policy object (GPO) may not be applied to the user and the user may not be
validated to use network resources. CAUSE The Kerberos token has a fixed size. If a user is a member
of a group either directly or by membership in another group, the security ID
(SID) for that group is added to the user's token. For a SID to be added to the
user's token, it must be communicated by using the Kerberos token. If the
required SID information exceeds the size of the token, authentication does not
succeed. The number of groups varies, but the limit is approximately 70 to 80
groups. For many operations, Windows NTLM authentication succeeds; the Kerberos authentication problem may not be evident without analysis. However, operations that include GPO application do not work at all. RESOLUTIONService pack informationTo resolve this problem, obtain the latest service pack for Windows 2000. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:260910
(http://support.microsoft.com/kb/260910/
)
How to Obtain the Latest Windows
2000 Service Pack
Hotfix informationA supported hotfix is available from Microsoft. However, this hotfix is intended to correct only the problem that is described in this article. Apply this hotfix only to systems that are experiencing this specific problem.If the hotfix is available for download, there is a "Hotfix download available" section at the top of this Knowledge Base article. If this section does not appear, submit a request to Microsoft Customer Service and Support to obtain the hotfix. Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, visit the following Microsoft Web site: http://support.microsoft.com/contactus/?ws=support Note The "Hotfix download available" form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language.
(http://support.microsoft.com/contactus/?ws=support)
File informationThe English version of this hotfix has the file attributes (or later) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.Date Time Version Size File name -------------------------------------------------------- 01/25/2001 02:24p 5.0.2195.2842 130,320 Adsldpc.dll 01/25/2001 02:24p 5.0.2195.2835 348,944 Advapi32.dll 01/25/2001 02:23p 5.0.2195.2816 502,032 Instls5.dll 01/25/2001 02:24p 5.0.2195.2842 140,560 Kdcsvc.dll 01/17/2001 01:17p 5.0.2195.2842 198,928 KERBEROS.dll 12/19/2000 09:13p 5.0.2195.2808 69,456 Ksecdd.sys 01/25/2001 02:24p 5.0.2195.2816 484,112 Lsasrv.dll 01/02/2001 08:45a 5.0.2195.2816 33,552 Lsass.exe 01/23/2001 05:06p 5.0.2195.2850 108,816 Msv1_0.dll 01/25/2001 02:24p 5.0.2195.2844 912,656 Ntdsa.dll 01/25/2001 02:24p 5.0.2195.2780 363,280 Samsrv.dll 01/25/2001 02:24p 5.0.2195.2797 128,272 Wldap32.dll STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. This problem was first corrected in Windows 2000 Service Pack 2. MORE INFORMATIONImportant This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base: 322756
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in WindowsA registry parameter is available after you apply this hotfix that you can use to increase the Kerberos token size. For example, increasing the token size to 65 KB allows a user to be present in more than 900 groups. Because of the associated SID information, this number may vary. To use this parameter:
297869 After you set the value and the computer is
updated, restart the computer. You can use Group Policy settings to set this
value for all computers. If you add the registry key to computers before you
apply the hotfix or Windows 2000 SP2, no changes take
effect.
(http://support.microsoft.com/kb/297869/
)
SMS administrator issues after you modify the Kerberos MaxTokenSize registry value
For additional information about this registry value, click the following article number to view the article in the Microsoft Knowledge Base: 313661
(http://support.microsoft.com/kb/313661/
)
Error Message: "Timeout expired" occurs when you connect to SQL Server over TCP/IP and the Kerberos MaxTokenSize is greater than 0xFFFF
300367
(http://support.microsoft.com/kb/300367/
)
DCOM client may put memory on the wire
Frequently Asked Questions
ReferencesFor additional informations, click the following article number to view the article in the Microsoft Knowledge Base:277741
(http://support.microsoft.com/kb/277741/
)
Internet Explorer logon fails due to an insufficient buffer for Kerberos
297869
For additional information about how to install Windows 2000 and Windows 2000 hotfixes at the
same time, click the following article number to view the article in the Microsoft Knowledge Base:
(http://support.microsoft.com/kb/297869/
)
SMS administrator issues after you modify the Kerberos MaxTokenSize registry value
249149
(http://support.microsoft.com/kb/249149/
)
Installing Microsoft Windows 2000 and Windows 2000
hotfixes
Properties |



Back to the top








