Got a bit of a problem

rickjr13rickjr13 Member Posts: 30 ■■□□□□□□□□
So I got these two servers, one a dc the other and exchange server. the users that i have created are having issues connecting to the exchange server as well as the public drive shared out on the exchange server. Seems that they can't access the exchange server at all. My admin account which is a member of the domain admins has no problems whatsoever, and when i add a user account to the domain admins account they also have no problems. it seems that whoever is a member of the domain users group has this problem. has anyone had this problem and if so how did you correct it? i have looked at the different permissions that might be causing it as well as any gpo's that might be causing it. the only other help that i have received is that i should reload it, which i am not totally against cuz this time i would get a chance to ghost a fresh image after i get it loaded up. thanks in advance.

Comments

  • dynamikdynamik Banned Posts: 12,312 ■■■■■■■■■□
    What do the logs in event viewer say. You might need to enable and/or configure auditing if you're not seeing the information you need.
  • rickjr13rickjr13 Member Posts: 30 ■■□□□□□□□□
    I attempted that with no luck, i am unsure as to where i apply the audit, on the domain, on the DC, on the exchange server or on the clients specifically? I would put it on the DC but i log in fine, my problem is access to exchange server so do i put it on the OU where i have my exchange server? I moved it from the computer container to an OU i created specifically for my machines, would this have caused the problem?
  • dynamikdynamik Banned Posts: 12,312 ■■■■■■■■■□
    rickjr13 wrote:
    I attempted that with no luck, i am unsure as to where i apply the audit, on the domain, on the DC, on the exchange server or on the clients specifically? I would put it on the DC but i log in fine, my problem is access to exchange server so do i put it on the OU where i have my exchange server?

    Default domain policy would audit everything. You might see a performance hit and/or too much information if you have a large organization. The OU that contains the object would probably be your best bet. Maybe the domain controllers security policy as well, since logon events are taking place. I'm not sure where that would have to be enabled off the top of my head.
    rickjr13 wrote:
    I moved it from the computer container to an OU i created specifically for my machines, would this have caused the problem?

    Depends on what GPOs you have assigned I guess. Moving it back would be a simple test.

    So what is the actual problem. Are they being prompted for their credentials, but it's just not accepting them? How are they trying to access it? Web browser? Windows explorer? What are they trying to access? Shared folders? OWA?

    I've found that you sometimes have to use <domain>\<username> or <username>@&lt;domain> format when logging on to another machine, depending on the circumstances. I'm not sure why you'd be able to log on without it though.
  • rickjr13rickjr13 Member Posts: 30 ■■□□□□□□□□
    I'll give the auditing a shot tomorrow.
    So what is the actual problem. Are they being prompted for their credentials, but it's just not accepting them? How are they trying to access it? Web browser? Windows explorer? What are they trying to access? Shared folders? OWA

    The problem is that once the users logon they are prompted with an error message stating that they cannot find their profile (the profile/home/share directories are all located on the server that hosts the exchange program). When you attempt to navigate through "my network places" you can see the exchange server but once you double click on it you get a message stating they do not have permission to access this network resource. it says something about blank password(don't have), logon hours(don't have) and policy restrictions(couldn't find anything that might be causing the problem).

    You add any user to the domain admins group, no problems at all. I already tried moving the server back from my own OU to the computers container and it still didnt do anything.
  • nice343nice343 Member Posts: 391
    remove any GPO on the server and see if they still have that issue. After that you can troubleshoot from there
    My daily blog about IT and tech stuff
    http://techintuition.com/
  • AhriakinAhriakin Member Posts: 1,799 ■■■■■■■■□□
    Check your share and file permissions, even if they look okay check the Effective Permissions for a user that's having problems from the Advance file security tab.
    We responded to the Year 2000 issue with "Y2K" solutions...isn't this the kind of thinking that got us into trouble in the first place?
  • dynamikdynamik Banned Posts: 12,312 ■■■■■■■■■□
    And as far as the profiles go, are you using roaming profiles? If so, is their location correctly shared? Have you set the location in the user's properties in ADUC to a network location or a local location? i.e. is it \\dc1\profiles or c:\profiles? You should have that set to a network location.
Sign In or Register to comment.