Good Morning,
I'm working on resolving issues in the event logs of some of the servers for one of our clients and came across this. I've seen this error before, but what makes this one different is that the Domain Controllers are mostly Server 2003,
not 2008 R2, where I saw this the last time.
I followed the instructions of http://support.microsoft.com/kb/977695 which had me add IIS AppPool\ to the DefaultAppPool in the GptTmpl.inf file located in C:\WINDOWS\SYSVOL\sysvol\domain.name\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows
NT\SecEdit but this has had no effect on the issue. I have run "gpupdate /force" on the server to confirm that it is getting the updated copy of the template file, and it is.
I have also checked the other SceCli threads, but most of them are related to Server 2008 R2, and when they made the recommended changes in the KB article it worked. Any assistance would be appreciated. Thank you.
I am including the relevant files / logs.
EVENT LOG ERROR:
Event Type:Warning
Event Source:SceCli
Event Category:None
Event ID:1202
Date:3/15/2012
Time:11:14:51 AM
User:N/A
Computer:servername
Description:
Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.
Advanced help for this problem is available on http://support.microsoft.com. Query for "troubleshooting 1202 events".
Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID. This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a
GPO. To resolve this event, contact an administrator in the domain to perform the following actions:
1.Identify accounts that could not be resolved to a SID:
From the command prompt, type: FIND /I "Cannot find" %SYSTEMROOT%\Security\Logs\winlogon.log
The string following "Cannot find" in the FIND output identifies the problem account names.
Example: Cannot find JohnDough.
In this case, the SID for username "JohnDough" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. "JohnDoe").
2.Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:
a.Start -> Run -> RSoP.msc
b.Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for
any errors flagged with a red X.
c.For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled "Source GPO". Note the specific User Rights, Restricted Groups
and containing Source GPOs that are generating errors.
3.Remove unresolved accounts from Group Policy
a.Start -> Run -> MMC.EXE
b.From the File menu select "Add/Remove Snap-in..."
c.From the "Add/Remove Snap-in" dialog box select "Add..."
d.In the "Add Standalone Snap-in" dialog box select "Group Policy" and click "Add"
e.In the "Select Group Policy Object" dialog box click the "Browse" button.
f.On the "Browse for a Group Policy Object" dialog box choose the "All" tab
g.For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting
any references to the problem accounts that were identified in step 1.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
*********************************
C:\WINDOWS\SYSVOL\sysvol\domain.name\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows NT\SecEdit\GptTmpl.inf
[Unicode]
Unicode=yes
[Event Audit]
AuditSystemEvents = 1
AuditLogonEvents = 3
AuditObjectAccess = 1
AuditPrivilegeUse = 1
AuditPolicyChange = 1
AuditAccountManage = 1
AuditProcessTracking = 1
AuditDSAccess = 1
AuditAccountLogon = 3
[Version]
signature="$CHICAGO$"
Revision=1
[Registry Values]
MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\EnableSecuritySignature=4,1
MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\EnableSecuritySignature=4,1
MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\RequireSecuritySignature=4,0
MACHINE\System\CurrentControlSet\Services\LDAP\LDAPClientIntegrity=4,0
MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\RequireSignOrSeal=4,0
MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\SealSecureChannel=4,1
MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\SignSecureChannel=4,1
MACHINE\System\CurrentControlSet\Services\NTDS\Parameters\LDAPServerIntegrity=4,1
MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\RequireSecuritySignature=4,0
[Privilege Rights]
SeAssignPrimaryTokenPrivilege = *S-1-5-21-2673940390-3640934957-3831995314-6138,IIS AppPool\DefaultAppPool,*S-1-5-21-2673940390-3640934957-3831995314-3107,*S-1-5-21-2673940390-3640934957-3831995314-9604,*S-1-5-20,*S-1-5-19,*S-1-5-21-2673940390-3640934957-3831995314-1316,*S-1-5-21-2673940390-3640934957-3831995314-2606,*S-1-5-21-2673940390-3640934957-3831995314-6137,*S-1-5-21-2673940390-3640934957-3831995314-6139
SeAuditPrivilege = IIS AppPool\DefaultAppPool,*S-1-5-20,*S-1-5-19
SeBackupPrivilege = *S-1-5-32-551,*S-1-5-32-544
SeBatchLogonRight = *S-1-5-21-2673940390-3640934957-3831995314-1617,*S-1-5-21-2673940390-3640934957-3831995314-6138,*S-1-5-21-2673940390-3640934957-3831995314-6137,*S-1-5-32-568,*S-1-5-21-2673940390-3640934957-3831995314-9604,*S-1-5-21-2673940390-3640934957-3831995314-2606,*S-1-5-21-2673940390-3640934957-3831995314-1316,*S-1-5-21-2673940390-3640934957-3831995314-3107,*S-1-5-21-2673940390-3640934957-3831995314-2042,*S-1-5-21-2673940390-3640934957-3831995314-2605,*S-1-5-21-2673940390-3640934957-3831995314-1315,*S-1-5-21-2673940390-3640934957-3831995314-3106,*S-1-5-21-2673940390-3640934957-3831995314-1317,*S-1-5-21-2673940390-3640934957-3831995314-3778,*S-1-5-21-2673940390-3640934957-3831995314-1120,*S-1-5-21-2673940390-3640934957-3831995314-6139
SeChangeNotifyPrivilege = *S-1-5-21-2673940390-3640934957-3831995314-6138,*S-1-5-21-2673940390-3640934957-3831995314-9604,*S-1-5-32-547,*S-1-5-32-544,*S-1-1-0,*S-1-5-32-551,*S-1-5-32-545,*S-1-5-21-2673940390-3640934957-3831995314-6137,*S-1-5-21-2673940390-3640934957-3831995314-6139,*S-1-5-21-2673940390-3640934957-3831995314-6141
SeCreatePagefilePrivilege = *S-1-5-32-544
SeCreatePermanentPrivilege =
SeCreateTokenPrivilege =
SeDebugPrivilege = *S-1-5-32-544
SeIncreaseBasePriorityPrivilege = *S-1-5-32-544
SeIncreaseQuotaPrivilege = *S-1-5-21-2673940390-3640934957-3831995314-6138,IIS AppPool\DefaultAppPool,*S-1-5-21-2673940390-3640934957-3831995314-3107,*S-1-5-21-2673940390-3640934957-3831995314-9604,*S-1-5-32-544,*S-1-5-20,*S-1-5-19,*S-1-5-21-2673940390-3640934957-3831995314-1316,*S-1-5-21-2673940390-3640934957-3831995314-2606,*S-1-5-21-2673940390-3640934957-3831995314-6137,*S-1-5-21-2673940390-3640934957-3831995314-6139
SeInteractiveLogonRight = *S-1-5-21-2673940390-3640934957-3831995314-2605,*S-1-5-21-2673940390-3640934957-3831995314-1315,*S-1-5-32-547,*S-1-5-32-551,*S-1-5-32-544,*S-1-5-32-545,*S-1-5-21-2673940390-3640934957-3831995314-3106,*S-1-5-21-2673940390-3640934957-3831995314-2042
SeLoadDriverPrivilege = *S-1-5-32-544
SeLockMemoryPrivilege =
SeMachineAccountPrivilege =
SeNetworkLogonRight = *S-1-5-21-2673940390-3640934957-3831995314-3107,*S-1-5-21-2673940390-3640934957-3831995314-2605,*S-1-5-21-2673940390-3640934957-3831995314-1315,*S-1-5-21-2673940390-3640934957-3831995314-1316,*S-1-5-32-547,*S-1-5-9,*S-1-5-32-544,*S-1-1-0,*S-1-5-32-551,*S-1-5-32-545,*S-1-5-21-2673940390-3640934957-3831995314-2606,*S-1-5-21-2673940390-3640934957-3831995314-3106
SeProfileSingleProcessPrivilege = *S-1-5-32-547,*S-1-5-32-544
SeRemoteShutdownPrivilege = *S-1-5-32-544
SeRestorePrivilege = *S-1-5-32-551,*S-1-5-32-544
SeSecurityPrivilege = *S-1-5-32-544,*S-1-5-21-2673940390-3640934957-3831995314-1109
SeServiceLogonRight = *S-1-5-21-2673940390-3640934957-3831995314-6140,*S-1-5-21-2673940390-3640934957-3831995314-6138,*S-1-5-21-2673940390-3640934957-3831995314-6137,*S-1-5-21-2673940390-3640934957-3831995314-6134,IIS AppPool\DefaultAppPool,*S-1-5-20,*S-1-5-21-2673940390-3640934957-3831995314-3809,*S-1-5-21-2673940390-3640934957-3831995314-1730,*S-1-5-21-2673940390-3640934957-3831995314-1617,*S-1-5-21-2673940390-3640934957-3831995314-9604,*S-1-5-21-2673940390-3640934957-3831995314-6125,*S-1-5-21-2673940390-3640934957-3831995314-10132,*S-1-5-21-2673940390-3640934957-3831995314-1120,*S-1-5-21-2673940390-3640934957-3831995314-6135,*S-1-5-21-2673940390-3640934957-3831995314-6139,*S-1-5-21-2673940390-3640934957-3831995314-6141
SeShutdownPrivilege = *S-1-5-32-547,*S-1-5-32-551,*S-1-5-32-544
SeSystemEnvironmentPrivilege = *S-1-5-32-544
SeSystemProfilePrivilege = *S-1-5-32-544
SeSystemTimePrivilege = *S-1-5-32-547,*S-1-5-32-544,*S-1-5-19
SeTakeOwnershipPrivilege = *S-1-5-32-544
SeTcbPrivilege =
SeDenyInteractiveLogonRight =
SeDenyBatchLogonRight =
SeDenyServiceLogonRight =
SeDenyNetworkLogonRight =
SeUndockPrivilege = *S-1-5-32-547,*S-1-5-32-544
SeSyncAgentPrivilege =
SeEnableDelegationPrivilege = raphael,*S-1-5-21-2673940390-3640934957-3831995314-1617,*S-1-5-21-2673940390-3640934957-3831995314-512
*****************************************************************
Latest winlogon.log entry:
Process GP template gpt00001.inf.
This is not the last GPO : domain policy is ignored on DC.
-------------------------------------------
Thursday, March 15, 2012 11:19:52 AM
----Un-initialize configuration engine...
Process GP template gpt00002.dom.
-------------------------------------------
Thursday, March 15, 2012 11:19:52 AM
----Configuration engine was initialized successfully.----
----Reading Configuration Template info...
----Configure User Rights...
Configure S-1-5-21-2673940390-3640934957-3831995314-6138.
Configure IIS AppPool\DefaultAppPool.
Error 1332: No mapping between account names and security IDs was done.
Cannot find IIS AppPool\DefaultAppPool.
Configure S-1-5-21-2673940390-3640934957-3831995314-3107.
Configure S-1-5-21-2673940390-3640934957-3831995314-9604.
Configure S-1-5-20.
Configure S-1-5-19.
Configure S-1-5-21-2673940390-3640934957-3831995314-1316.
Configure S-1-5-21-2673940390-3640934957-3831995314-2606.
Configure S-1-5-21-2673940390-3640934957-3831995314-6137.
Configure S-1-5-21-2673940390-3640934957-3831995314-6139.
Configure S-1-5-21-2673940390-3640934957-3831995314-10176.
Configure S-1-5-21-2673940390-3640934957-3831995314-10175.
Configure S-1-5-32-544.
Configure S-1-5-21-2673940390-3640934957-3831995314-1617.
Configure S-1-5-32-568.
Configure S-1-5-21-2673940390-3640934957-3831995314-2042.
Configure S-1-5-21-2673940390-3640934957-3831995314-2605.
Configure S-1-5-21-2673940390-3640934957-3831995314-1315.
Configure S-1-5-21-2673940390-3640934957-3831995314-3106.
Configure S-1-5-21-2673940390-3640934957-3831995314-1317.
Configure S-1-5-21-2673940390-3640934957-3831995314-3778.
Configure S-1-5-21-2673940390-3640934957-3831995314-1120.
Configure S-1-1-0.
Configure S-1-5-21-2673940390-3640934957-3831995314-512.
Configure S-1-5-6.
Configure S-1-5-32-547.
Configure S-1-5-32-551.
Configure S-1-5-32-545.
Configure S-1-5-9.
Configure S-1-5-21-2673940390-3640934957-3831995314-1109.
Configure S-1-5-21-2673940390-3640934957-3831995314-6140.
Configure S-1-5-21-2673940390-3640934957-3831995314-6134.
Configure S-1-5-21-2673940390-3640934957-3831995314-3809.
Configure S-1-5-21-2673940390-3640934957-3831995314-1730.
Configure S-1-5-21-2673940390-3640934957-3831995314-6125.
Configure S-1-5-21-2673940390-3640934957-3831995314-10132.
Configure S-1-5-21-2673940390-3640934957-3831995314-6135.
Configure S-1-5-21-2673940390-3640934957-3831995314-6141.
User Rights configuration was completed with one or more errors.
----Configure General Service Settings...
Configure WSearch.
General Service configuration was completed successfully.
----Configure available attachment engines...
Configuration of attachment engines was completed successfully.
----Configure Security Policy...
Configure password information.
Configure account force logoff information.
System Access configuration was completed successfully.
Audit/Log configuration was completed successfully.
Kerberos Policy configuration was completed successfully.
Configure machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.
Configure machine\system\currentcontrolset\services\lanmanserver\parameters\requiresecuritysignature.
Configure machine\system\currentcontrolset\services\lanmanworkstation\parameters\enablesecuritysignature.
Configure machine\system\currentcontrolset\services\lanmanworkstation\parameters\requiresecuritysignature.
Configure machine\system\currentcontrolset\services\ldap\ldapclientintegrity.
Configure machine\system\currentcontrolset\services\netlogon\parameters\requiresignorseal.
Configure machine\system\currentcontrolset\services\netlogon\parameters\sealsecurechannel.
Configure machine\system\currentcontrolset\services\netlogon\parameters\signsecurechannel.
Configure machine\system\currentcontrolset\services\ntds\parameters\ldapserverintegrity.
Configuration of Registry Values was completed successfully.
----Configure available attachment engines...
Configuration of attachment engines was completed successfully.
----Un-initialize configuration engine...
this is the last GPO.