Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > cant log into child domain

Reply
Thread Tools Display Modes

cant log into child domain

 
 
sawyer
Guest
Posts: n/a

 
      10-30-2009
Hello all

I have a parent and child domain in the AD forest, the AD forest is at
Windows 2003 native. I am a member of the enterprise admins domain admins
and schema admins group. Using my account I cannot log onto one of the DC's
in the child domain when logging onto the child domain. I thought that if my
account was a member of the enterrpise admins group I could use my account
and log on to a DC in the child domain under the child domain?

Thanks

 
Reply With Quote
 
 
 
 
Marcin
Guest
Posts: n/a

 
      10-30-2009
What's the error message you are getting when attempting to logon?

Marcin

"sawyer" <> wrote in message
news:4E66F598-14F4-4D4D-92CC-...
> Hello all
>
> I have a parent and child domain in the AD forest, the AD forest is at
> Windows 2003 native. I am a member of the enterprise admins domain admins
> and schema admins group. Using my account I cannot log onto one of the
> DC's in the child domain when logging onto the child domain. I thought
> that if my account was a member of the enterrpise admins group I could use
> my account and log on to a DC in the child domain under the child domain?
>
> Thanks



 
Reply With Quote
 
sawyer
Guest
Posts: n/a

 
      10-30-2009
Is a "you don't have rights to log into this machine, you must be a member
of the local admin or RDP group"

"Marcin" <> wrote in message
news:...
> What's the error message you are getting when attempting to logon?
>
> Marcin
>
> "sawyer" <> wrote in message
> news:4E66F598-14F4-4D4D-92CC-...
>> Hello all
>>
>> I have a parent and child domain in the AD forest, the AD forest is at
>> Windows 2003 native. I am a member of the enterprise admins domain
>> admins and schema admins group. Using my account I cannot log onto one of
>> the DC's in the child domain when logging onto the child domain. I
>> thought that if my account was a member of the enterrpise admins group I
>> could use my account and log on to a DC in the child domain under the
>> child domain?
>>
>> Thanks

>
>

 
Reply With Quote
 
Marcin
Guest
Posts: n/a

 
      10-30-2009

Verify that Enterpise Admins group is a member of local Administrators group
in the child domain...

hth
Marcin

"sawyer" <> wrote in message
news:64D80AF7-59E0-4755-B0EC-...
> Is a "you don't have rights to log into this machine, you must be a member
> of the local admin or RDP group"
>
> "Marcin" <> wrote in message
> news:...
>> What's the error message you are getting when attempting to logon?
>>
>> Marcin
>>
>> "sawyer" <> wrote in message
>> news:4E66F598-14F4-4D4D-92CC-...
>>> Hello all
>>>
>>> I have a parent and child domain in the AD forest, the AD forest is at
>>> Windows 2003 native. I am a member of the enterprise admins domain
>>> admins and schema admins group. Using my account I cannot log onto one
>>> of the DC's in the child domain when logging onto the child domain. I
>>> thought that if my account was a member of the enterrpise admins group I
>>> could use my account and log on to a DC in the child domain under the
>>> child domain?
>>>
>>> Thanks

>>
>>



 
Reply With Quote
 
Ace Fekay [MCT]
Guest
Posts: n/a

 
      10-31-2009
"sawyer" <> wrote in message
news:4E66F598-14F4-4D4D-92CC-...
> Hello all
>
> I have a parent and child domain in the AD forest, the AD forest is at
> Windows 2003 native. I am a member of the enterprise admins domain admins
> and schema admins group. Using my account I cannot log onto one of the
> DC's in the child domain when logging onto the child domain. I thought
> that if my account was a member of the enterrpise admins group I could use
> my account and log on to a DC in the child domain under the child domain?
>
> Thanks



Are there any Event log errors on any of the DCs?

How is DNS setup in the infrastructure? Is the child domain delegated the
child zone? If so, I assume the parent zone and child zone's replication
scope are Domain wide, and there is a fowarder from the child domain's DNS
to the parent domain's DNS, as well as that all child domain members are
only using the child domain's DNS servers.

If not, can you elaborate on the setup? This could also contribute to your
Exchange issue you had posted earlier.


--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Please reply back to the newsgroup or forum for collaboration benefit among
responding engineers, and to help others benefit from your resolution.

Ace Fekay, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007, MCSE & MCSA
2003/2000, MCSA Messaging 2003
Microsoft Certified Trainer

For urgent issues, please contact Microsoft PSS directly. Please check
http://support.microsoft.com for regional support phone numbers.


 
Reply With Quote
 
sawyer
Guest
Posts: n/a

 
      11-02-2009
Hello Ace, thank very much for your assistance.

DNS in the forest is all AD integrated. The parent domain is
corp.mydomain.com and the zone for this domain is AD integrated. The child
domain is child.corp.mydomain.com and it's the zone for this domain is AD
integrated as well. All Domain controllers are DNS servers, and they all use
forwarders and they all point to the same ISP ip address.

I do not understand what you mean by "is the domain delegated the child
zone"? how can I confirm this?
The parent and child zone replication are forest wide ( I think) when I
right click on the zone both the parent and child zone go to properties and
the general tab, the replication says "All DNS servers in the forest"

Again the forwarder for the child zone is set to look at the ISP, should the
forwarder be the ip address of DNS server located in the parent zone?

Yes all child domain members are using the child domain for DNS

Thanks again for your assitance!

"Ace Fekay [MCT]" <> wrote in message
news:...
> "sawyer" <> wrote in message
> news:4E66F598-14F4-4D4D-92CC-...
>> Hello all
>>
>> I have a parent and child domain in the AD forest, the AD forest is at
>> Windows 2003 native. I am a member of the enterprise admins domain
>> admins and schema admins group. Using my account I cannot log onto one of
>> the DC's in the child domain when logging onto the child domain. I
>> thought that if my account was a member of the enterrpise admins group I
>> could use my account and log on to a DC in the child domain under the
>> child domain?
>>
>> Thanks

>
>
> Are there any Event log errors on any of the DCs?
>
> How is DNS setup in the infrastructure? Is the child domain delegated the
> child zone? If so, I assume the parent zone and child zone's replication
> scope are Domain wide, and there is a fowarder from the child domain's DNS
> to the parent domain's DNS, as well as that all child domain members are
> only using the child domain's DNS servers.
>
> If not, can you elaborate on the setup? This could also contribute to your
> Exchange issue you had posted earlier.
>
>
> --
> Ace
>
> This posting is provided "AS-IS" with no warranties or guarantees and
> confers no rights.
>
> Please reply back to the newsgroup or forum for collaboration benefit
> among responding engineers, and to help others benefit from your
> resolution.
>
> Ace Fekay, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007, MCSE & MCSA
> 2003/2000, MCSA Messaging 2003
> Microsoft Certified Trainer
>
> For urgent issues, please contact Microsoft PSS directly. Please check
> http://support.microsoft.com for regional support phone numbers.
>

 
Reply With Quote
 
sawyer
Guest
Posts: n/a

 
      11-02-2009
So just to confirm what I am experiencing is not normal behavior

My account is a member of the enterprise admins group. I can log onto one of
the child DC's with my corp account (corp is the parent domain) but I cant
log onto one of the child DC's using my corp account but under the child
domain. Example childdomain\myaccount fails.

When I try and log on to a DC on the child domain using
childdomain\myaccount I get a security event

Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 11/2/2009 9:34:42 AM
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: N/A
Computer: DC2.childdomain.corp.mydomain.com
Description:
An account failed to log on.


"Ace Fekay [MCT]" <> wrote in message
news:...
> "sawyer" <> wrote in message
> news:4E66F598-14F4-4D4D-92CC-...
>> Hello all
>>
>> I have a parent and child domain in the AD forest, the AD forest is at
>> Windows 2003 native. I am a member of the enterprise admins domain
>> admins and schema admins group. Using my account I cannot log onto one of
>> the DC's in the child domain when logging onto the child domain. I
>> thought that if my account was a member of the enterrpise admins group I
>> could use my account and log on to a DC in the child domain under the
>> child domain?
>>
>> Thanks

>
>
> Are there any Event log errors on any of the DCs?
>
> How is DNS setup in the infrastructure? Is the child domain delegated the
> child zone? If so, I assume the parent zone and child zone's replication
> scope are Domain wide, and there is a fowarder from the child domain's DNS
> to the parent domain's DNS, as well as that all child domain members are
> only using the child domain's DNS servers.
>
> If not, can you elaborate on the setup? This could also contribute to your
> Exchange issue you had posted earlier.
>
>
> --
> Ace
>
> This posting is provided "AS-IS" with no warranties or guarantees and
> confers no rights.
>
> Please reply back to the newsgroup or forum for collaboration benefit
> among responding engineers, and to help others benefit from your
> resolution.
>
> Ace Fekay, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007, MCSE & MCSA
> 2003/2000, MCSA Messaging 2003
> Microsoft Certified Trainer
>
> For urgent issues, please contact Microsoft PSS directly. Please check
> http://support.microsoft.com for regional support phone numbers.
>

 
Reply With Quote
 
Ace Fekay [MCT]
Guest
Posts: n/a

 
      11-02-2009
"sawyer" <> wrote in message
news:A7C0FDBD-531C-422F-9631-...
> Hello Ace, thank very much for your assistance.
>
> DNS in the forest is all AD integrated. The parent domain is
> corp.mydomain.com and the zone for this domain is AD integrated. The child
> domain is child.corp.mydomain.com and it's the zone for this domain is AD
> integrated as well. All Domain controllers are DNS servers, and they all
> use forwarders and they all point to the same ISP ip address.
>
> I do not understand what you mean by "is the domain delegated the child
> zone"? how can I confirm this?
> The parent and child zone replication are forest wide ( I think) when I
> right click on the zone both the parent and child zone go to properties
> and the general tab, the replication says "All DNS servers in the forest"
>
> Again the forwarder for the child zone is set to look at the ISP, should
> the forwarder be the ip address of DNS server located in the parent zone?
>
> Yes all child domain members are using the child domain for DNS
>
> Thanks again for your assitance!
>


You are welcome, so far.

I think it is a resolution issue based on the DNS infrastructure. Regarding
DNS Parent to child delegation, I had responded to another one of your
threads explaining this. Apparently the two threads are related.

If you decide to delegate, the _msdcs zone stays in the Forest replication
scope. The other two will be put into their own respective domain scope (not
the Windows 2000 compatible one).

Forwarding with delegation is changed. It will go from child to parent, then
parent to ISP.

However, you can keep it the way it is, for simplicity, which may complicate
this diagnosis.

I believe you had already set the search suffixes? (trying to remember info
from this thread and the other one) If so, good.

I would also look at WINS.

Ace



 
Reply With Quote
 
Ace Fekay [MCT]
Guest
Posts: n/a

 
      11-02-2009
"sawyer" <> wrote in message
news:43B304EE-9757-45F6-85FD-...
> So just to confirm what I am experiencing is not normal behavior
>
> My account is a member of the enterprise admins group. I can log onto one
> of the child DC's with my corp account (corp is the parent domain) but I
> cant log onto one of the child DC's using my corp account but under the
> child domain. Example childdomain\myaccount fails.
>
> When I try and log on to a DC on the child domain using
> childdomain\myaccount I get a security event
>
> Log Name: Security
> Source: Microsoft-Windows-Security-Auditing
> Date: 11/2/2009 9:34:42 AM
> Event ID: 4625
> Task Category: Logon
> Level: Information
> Keywords: Audit Failure
> User: N/A
> Computer: DC2.childdomain.corp.mydomain.com
> Description:
> An account failed to log on.
>



Are there any event errors regarinding replication?

Ace


 
Reply With Quote
 
sawyer
Guest
Posts: n/a

 
      11-03-2009
No, the child and parent domain are in the same AD site

"Ace Fekay [MCT]" <> wrote in message
news:#pWI22$...
> "sawyer" <> wrote in message
> news:43B304EE-9757-45F6-85FD-...
>> So just to confirm what I am experiencing is not normal behavior
>>
>> My account is a member of the enterprise admins group. I can log onto one
>> of the child DC's with my corp account (corp is the parent domain) but I
>> cant log onto one of the child DC's using my corp account but under the
>> child domain. Example childdomain\myaccount fails.
>>
>> When I try and log on to a DC on the child domain using
>> childdomain\myaccount I get a security event
>>
>> Log Name: Security
>> Source: Microsoft-Windows-Security-Auditing
>> Date: 11/2/2009 9:34:42 AM
>> Event ID: 4625
>> Task Category: Logon
>> Level: Information
>> Keywords: Audit Failure
>> User: N/A
>> Computer: DC2.childdomain.corp.mydomain.com
>> Description:
>> An account failed to log on.
>>

>
>
> Are there any event errors regarinding replication?
>
> Ace
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
child and parent domain in the same AD site sawyer Active Directory 8 11-02-2009 07:07 PM
Re: Incorrect server name Ace Fekay [MCT] Windows Server 4 10-28-2009 02:17 PM
Re: Migrate from one 2003 Domain to another 2003 Domain Meinolf Weber [MVP-DS] Server Migration 0 10-22-2009 07:35 AM
Re: Migrate from one 2003 Domain to another 2003 Domain Meinolf Weber [MVP-DS] Server Migration 1 10-21-2009 08:54 PM
DOMAIN LOGIN: Authentification server unavailable in remote location Louis Windows Vista Administration 0 02-21-2007 01:45 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59