Имя пользователя:
Пароль:
 

Показать сообщение отдельно

Аватара для wolf

Скромняга


Сообщения: 365
Благодарности: 1

Профиль | Сайт | Отправить PM | Цитировать


Лови, но это уже встречалось... Я отвечал на этот вопрос... В следующий раз пользуйся поиском...


PSS ID Number: Q247482
Article last modified on 02-07-2000

WINDOWS:2000

WINDOWS


======================================================================
-------------------------------------------------------------------------------
The information in this article applies to:

- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server
-------------------------------------------------------------------------------

SYMPTOMS
========

Every five minutes the following Event error messages are added to the
Applictation Log in Event Viewer.

  Event Type: Warning
 Event Source: SceCli
 Event Category: None
 Event ID: 1202
 Date: 10/16/1999
 Time: 10:13:10 am
 User: N/A
 Computer: COMPUTERNAME

  Description: Security policies are propagated with warning. 0x534 : No mapping
 between account names and security IDs was done. Please look for more details
 in TroubleShooting section in Security Help.

and

  Event Type: Error
 Event Source: Userenv
 Event Category: None
 Event ID: 1000
 Date: 10/16/1999
 Time: 10:13:11 am
 User: NT AUTHORITY\SYSTEM
 Computer: COMPUTERNAME

  Description: The Group Policy client-side extension Security was passed flags
 (17) and returned a failure status code of (1332).

CAUSE
=====

This issue can occur for any of the following reasons:

- You installed a program, which creates user accounts and assigns rights to
 those user accounts. Later, you remove the program, which deletes the user
 accounts, but does not remove the rights from policy before the accounts are
 deleted.
- You add a user account and assign rights to the account. Later, you delete
 the account, but you do not remove the account from the user rights policy.

RESOLUTION
==========

To resolve this issue, follow these steps:

1. Add the ExtensionDebugLevel DWORD value with the value data 2 to the
 following registry key:

  HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\GPExtension\{827...}

2. Under command window type "secedit /refreshpolicy machine_policy /enforce"
 (without the quotation marks) to generate the Winlogon.log file in the
 %windir%\security\logs folder.

3. Search the Winlogon.log file for deleted user accounts.

4. Remove those user accounts from the User Rights Policy.

STATUS
======

Microsoft has confirmed this to be a problem in Microsoft Windows 2000.

Additional query words: Userenv

======================================================================
Keywords          : kbenv kberrmsg kbtool ntdomain ntsecurity
Version           : WINDOWS:2000
Platform          : WINDOWS
Issue type        : kbprb
=============================================================================
Copyright Microsoft Corporation 2000.

-------
Может поставить Microsoft Windows на ракеты ПВО и *истребители?


Отправлено: 08:09, 02-10-2002 | #2