当前位置: 首页 > news >正文

Userenv 1030

事件类型:错误
事件来源:Userenv
事件种类:无
事件 ID:1030
日期:2005-9-23
事件:9:41:35
用户:NT AUTHORITY\SYSTEM
计算机:WEB服务器/辅助DC
描述:
Windows 不能查询组策略对象列表。请查看事件日志,从中寻找策略引擎以前可能记录的描述此原因的消息。

Details
Product:Windows Operating System
ID:1030
Source:Userenv
Version:5.2
Symbolic Name:EVENT_GPO_QUERY_FAILED
Message:Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.
Explanation

A network connectivity or configuration problem exists. Group Policy settings cannot be applied until the problem is fixed.

User Action

To troubleshoot the network connectivity or configuration problem, try one or all of the following:

  • In Event Viewer, click System, and check for any networking-related messages, such as Netlogon messages, that indicate a network connectivity issue.
  • At the command prompt, type netdiag, and note any errors. Those errors usually have to be resolved before Group Policy processing can continue.
  • At the command prompt, type gpupdate, and then check Event Viewer to see if the Userenv 1030 event is logged again.
  • To verify that the domain controller can be contacted through Domain Name System (DNS), try to access \\mydomain.com\sysvol\mydomain.com, where mydomain.com is the fully qualified DNS name of your domain.
  • Verify that you can access the domain controller by using tools such as the Active Directory Users and Computers snap-in.
  • Check to see whether other computers on your network are having the same problem.
  • If this computer is a part of a cross-forest domain, verify that the forest for the user account is currently available and can be contacted by the computer on which the Group Policy processing failed.
Event ID: 1030
Source Userenv
Type Error
DescriptionWindows cannot query for the list of Group Policy objects. A message that describes the reason for this was previously logged by the policy engine.
Things to understandWhat is the Group Policy?
What is the role of Userenv?
CommentsAdrian Grigorof (Last update 5/30/2004):
As per M810907 (applicable to Windows XP) this may occur in conjunction with Event id 1058 and it is a confirmed (known) problem with XP. A hotfix is available.

This event is also reported in many instances of upgrades from Windows NT or Windows 2000 to Windows 2003 Server.
Some other recommendations in regards to this (from newsgroup posts) is to verify that:
- DFS service on all DCs is started and set to "Automatic"
- there are no FRS issues - (if there are, toubleshoot those first)
- TCP/IP Netbios Helper service is started and set to "Automatic"
- the "Everyone" has the "bypass traverse checking" user right
on the default domain controller policy
- the antivirus (if installed) is not scanning the sysvol or subfolders, if so, exclude it
- consider that the error description in event id 1058 ("network path not found" or "access denied") is caused by different problems and have different solutions.

Other posts from Microsoft engineer suggest that if a domain controller is multi-homed (more than 1 network card) they may experience this problem (note that "network card" could mean a physical or a virtual one - i.e. VMWare or VPN virtual adapters). The posts also indicate that the Client for Microsoft Networks and the File and Printer Sharing services have to be bound to the network adapter.

See also M307900 on updating Windows 2000 Group Policy for Windows XP.

In some other conditions (upgrading to Windows 2003 Server), the 1030 event appears together with event id 1097 from Userenv. From a newsgroup post by a Microsoft engineer: "What is happening is that the TCP/IP Netbios Helper Service is trying to start before the KDC starts upon reboot. It corrects itself. You can safely ignore it. I am trying to get these errors suppressed in a later service pack or hotfix. You can track this running subsequent userenv and netlogon logs. See M221833 and M109626."

If this occurs in conjunction with event id 1058 you can work around this issue by using the Dfsutil.exe file - see M830676.

Ionut Marin (Last update 5/21/2005):
See M842804 for a hotfix applicable to Microsoft Windows 2000 and Microsoft Windows Server 2003.

As per Microsoft: "This behavior occurs if the SMB signing settings for the Workstation service and for the Server service contradict each other. When you configure the domain controller in this way, the Workstation service on the domain controller cannot connect to the domain controller's Sysvol share. Therefore, you cannot start Group Policy snap-ins. Also, if SMB signing policies are set by the default domain controller security policy, the problem affects all the domain controllers on the network. Therefore, Group Policy replication in the Active Directory directory service will fail, and you will not be able to edit Group Policy to undo these settings". See M839499 to fix this problem.

As per Microsoft: "This issue may occur if you have account names that use non-ASCII characters, such as ö and é. Windows 2000 Server and Windows Server 2003 do not distinguish between non-ASCII and ASCII characters in account names.
Windows NT 4.0 distinguishes between ASCII and non-ASCII characters in account names. For example, in a Windows NT 4.0-based domain, you can use Administrator and Administratör as separate account names. However, in Active Directory, both Administrator and Administratör effectively have the same logon credentials. This scenario causes the conflict". See M883271 for details on this issue.

From a newsgroup post: "I connected to the Sysvol share as the current user (non- administrator), and noticed that I could get into "mydomain" directory, but when I tried to get into Policies I received "Access Denied". All of the share/file permissions were correct, allowing this user to get to the share and to traverse/read the files within it. I tracked it down to the fact that I was not allowing read access for Authenticated Users, Everyone, Domain Users, and/or the users Group from the root (C:) to the SYSVOL directory. Once I allowed Everyone, or Authenticated Users, or Domain Users read permissions to from C: -> WINNT -> SYSVOL the users were then able to receive the GPO’s".

From a newsgroup post: "Here is what you should do to get rid of this error and of Event ID 1058 on Windows Server 2003. Edit the hosts file on each domain controller. Put in the IP address for your domain controller (the local IP address should be first in the list), and then next to the IP address do not put the host name, but put the name of the domain. Then list the IP address for each domain controller in your domain, on the same hosts file (with the domain name next to it). In other words, your hosts file should look like this (if you have just two domain controllers):
<IP 1> yourdomainname.com

<IP 2> yourdomainname.com

Where <IP 1> = the IP address of the local domain controller for this hosts file.
Where <IP 2> = the IP address of your other domain controller.

yourdomainname.com = the name of your domain

The list would be reversed (as far as IP address) on the hosts file on the other domain controller. Yes, you need a hosts file on each domain controller".

Also check M290647, M832215, M834649, M886516, M887303, M887421, M888943, and MSW2KDB for more details on this event.

Anonymous (Last update 3/23/2005):
This happened when I was prompted to change my password, and did, but I stayed logged on to a remote Windows 2003 server with my old credentials. The server locked after the timeout and I left it that way for a couple days. The error stopped when I logged off and logged back on with the new password.

Warren Anacoura (Last update 12/9/2004):
Our XP Clients started showing up these errors in the Application Log after we installed Service Pack 2. There is a corresponding warning EventID 40961 from source LsaSrv in the System log. The problem seems to be related to the background group policy refresh failing if the user has locked the workstation. Setting group policy to prevent lock workstation corrects the problem but a better fix seems to be uninstalling the Client for Microsoft Networks from the NIC, reinstalling it, and rebooting.

Jahan Ghaemi (Last update 11/24/2004):
I saw this error in my class after one of my students was working on renaming his domain controller. I fixed the problem by running DCGPOFIX on the Win2k3 server followed by a reboot. See the link to “Dcgpofix” for details on this command.

Daniel Conlon (Last update 10/5/2003):
After upgrading from Win2k to Win2k3 I found I was getting this error every 5 minutes in event log along with error 1053. To solve it I had set the following attributes in the Default Domain Controller Policy:
1. Network Access: Let Everyone permissions apply to anonymous users = "Enabled".
2. Network Access: Shares that can be accessed anonymously -> Add SYSVOL to the list. This is because the servers are trying to access the SYSVOL share as LocalSystem which by default does not have access to network resources.

John Poff (Last update 8/28/2003):
On Windows 2003 I received this error when I disabled TCP/IP NetBios help service. Apparently this has changed since Windows 2000. You can no longer disable this service and have access to Group Policy Objects.

Sean Wallbridge
In the past, I was configuring Domain Controller's in a Windows 2000 domain to have the Distributed File System Services stopped and set to manual until such time as they were needed.This was a recommendation based on services that could be stopped according to Microsoft from some time ago to bring machines to a "only what is required state".We disabled DFS worldwide with Windows 2000, NT and Win98 clients with no issues incurred by this.

However, after a while I discovered I was having all sorts of Group Policy application errors on my Windows XP workstation in my Windows 2000 domain.

Looks like Windows XP speaks quite a bit differently to AD and wants/needs more information (and expects it from DFS shares - \\<domain>.<name>).In fact, from my XP machine, I tried connecting to my domain share (\\<domain>.<name>) and I was told access was denied yet it was available from Win2k machines (event ids 1030 and 1058). So, if you have Windows XP clients or just plain aren't worried about someone cranking up DFS and screwing something up somewhere, plan on leaving DFS enabled again.

Also, while working through this I discovered that besides the already cool "Resultant Set of Policy" MMC snap-in in Windows XP, there is also a "GPUPDATE" command in Windows XP which, when used with the /force switch, will blast computer policy settings to your Windows XP machine immediately.

Tom Holland
As per Microsoft: "This behavior may occur if both of the following conditions are true:
Your Windows XP-based computer is a member of a domain.
-and-
The Microsoft Distributed File System (DFS) client is turned off (disabled).
NOTE: The \\Active Directory Domain Name\Sysvol share is a special share that requires the DFS client to make a connection." See M314494.

相关文章:

  • TechEd 2005游记(二)
  • uniapp获取屏幕宽度的方式_骚年你的屏幕适配方式该升级了-smallestWidth限定符适配方案...
  • 微软Google上演研发战 急调张亚勤对阵李开复[zz]
  • id vue 取对象_在线等,挺急的!vue如何查找id对应的对象,求指导!
  • 支持事务的版本_厉害了,Spring Cloud Alibaba 发布 GA 版本!
  • 李开复发公开信回应大学生质疑 称言行一致
  • vue如何主动销毁子组件_Vue自动销毁的vue event Bus
  • MT summit X 感想之感想
  • 免费电子书籍下载站点大全
  • visio常用快捷键_visio2003常用快捷键有哪些
  • 英语学习资源下载大全 一网打尽
  • laravel auth login 重定向自定义_php-laravel框架用户验证(Auth)模块解析(二)注册模块...
  • 在线翻译总集
  • 偷的名表卖掉能查到吗_回收黄金的利润怎么样?黄金回收的行业未来趋势怎么样?小白做黄金回收的门槛高吗?...
  • ZT 技术不是第一位,商业模式是第一位
  • @jsonView过滤属性
  • 2017前端实习生面试总结
  • Flex布局到底解决了什么问题
  • gops —— Go 程序诊断分析工具
  • HTML中设置input等文本框为不可操作
  • MySQL主从复制读写分离及奇怪的问题
  • PHP面试之三:MySQL数据库
  • Python十分钟制作属于你自己的个性logo
  • React 快速上手 - 07 前端路由 react-router
  • 道格拉斯-普克 抽稀算法 附javascript实现
  • 服务器之间,相同帐号,实现免密钥登录
  • 买一台 iPhone X,还是创建一家未来的独角兽?
  • 前端面试总结(at, md)
  • 手机端车牌号码键盘的vue组件
  • 探索 JS 中的模块化
  • 在Mac OS X上安装 Ruby运行环境
  • mysql 慢查询分析工具:pt-query-digest 在mac 上的安装使用 ...
  • 宾利慕尚创始人典藏版国内首秀,2025年前实现全系车型电动化 | 2019上海车展 ...
  • 昨天1024程序员节,我故意写了个死循环~
  • ## 临床数据 两两比较 加显著性boxplot加显著性
  • #Linux(权限管理)
  • #快捷键# 大学四年我常用的软件快捷键大全,教你成为电脑高手!!
  • ( 用例图)定义了系统的功能需求,它是从系统的外部看系统功能,并不描述系统内部对功能的具体实现
  • (20050108)又读《平凡的世界》
  • (22)C#传智:复习,多态虚方法抽象类接口,静态类,String与StringBuilder,集合泛型List与Dictionary,文件类,结构与类的区别
  • (3)nginx 配置(nginx.conf)
  • (30)数组元素和与数字和的绝对差
  • (二)hibernate配置管理
  • (力扣题库)跳跃游戏II(c++)
  • (四)linux文件内容查看
  • (转)大型网站的系统架构
  • (转)负载均衡,回话保持,cookie
  • .Net MVC4 上传大文件,并保存表单
  • .net MySql
  • .NET/C# 避免调试器不小心提前计算本应延迟计算的值
  • .NET上SQLite的连接
  • @EventListener注解使用说明
  • @JoinTable会自动删除关联表的数据
  • [ vulhub漏洞复现篇 ] GhostScript 沙箱绕过(任意命令执行)漏洞CVE-2019-6116
  • [04] Android逐帧动画(一)