Corrupted Security Groups Are Created When You Install DHCP or WINS on Multiple Domain Controllers (822048)
The information in this article applies to:
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows Server 2003, Enterprise Edition
- Microsoft Windows Server 2003, Standard Edition
- Microsoft Windows Small Business Server 2003, Premium Edition
- Microsoft Windows Small Business Server 2003, Standard Edition
SYMPTOMSWhen you install the Dynamic Host Configuration Protocol (DHCP) networking component or the Windows Internet Naming Service (WINS) networking component on multiple domain controllers, corrupted objects may be created in the Microsoft Active Directory directory service for the following security groups: DHCP Administrators DHCP Users WINS Users If you remove one or more of these objects from a domain controller where you installed the DHCP component or the WINS component, the rights that are associated with that object are also removed. This causes permissions issues for members of the groups that were previously listed. CAUSEThis issue may occur if all the following conditions are true: - You install the DHCP component or the WINS component on a domain controller.
-and- - The domain controller has not successfully replicated the changes throughout Active Directory.
-and- - You install the DHCP component or the WINS component on a second domain controller.
When you install the DHCP component or the WINS component, the corresponding service searches the local Security Accounts Manager (SAM) database for the following security groups (if applicable): DHCP Administrators DHCP Users WINS Users If these groups do not exist, they are created. When you install these components on a domain controller, the same process occurs. However, if the component is installed on more than one domain controller, and replication has not yet occurred, the security groups are created on each of the domain controllers. After replication completes between the domain controllers, the duplicate groups that are created cause corrupted objects to be created in Active Directory. RESOLUTIONTo resolve this issue, when you install the DHCP component or the WINS component on a domain controller, allow sufficient time for domain controller replication to complete before you install the component on a second domain controller.WORKAROUNDTo work around this issue: - Remove the corrupted security group (or groups) from the domain controller where you installed the DHCP component or the WINS component.
Note You can also remove the uncorrupted security group (or groups) and rename the corrupted groups with their correct names. - On the domain controller where you removed the security group (or groups), remove and then reinstall the DHCP networking component or the WINS networking component.
Modification Type: | Major | Last Reviewed: | 10/9/2003 |
---|
Keywords: | kbprb KB822048 kbAudITPRO |
---|
|