I just tried to move a system into our test network AD (2003 Server Mode) from our production AD and the same thing happened ("Access is Denied"). There are no errors on the DC, but I do get failed Object Access errors (Event ID: 560) when the domain admin acct. that I use to join the system is trying to access the Winlogon "object". If I sysprep the PC it will work. Any ideas as to what might be too locked down?
Thanks! ----------------------------------- Cory G. Stuart Network Administrator Nuclear Engineering Division Argonne National Laboratory ---------------------------------- -----Original Message----- From: Stuart, Cory G. Sent: Wednesday, December 10, 2003 12:24 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] Rejoining Windows 2000 Systems to a Domain (2000 Native Mode) I just noticed that the Computer Account is created in AD, even though I'm getting the "Access Denied." ----------------------------------- Cory G. Stuart Network Administrator Nuclear Engineering Division Argonne National Laboratory ---------------------------------- -----Original Message----- From: Stuart, Cory G. Sent: Wednesday, December 10, 2003 11:49 AM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] Rejoining Windows 2000 Systems to a Domain (2000 Native Mode) I AM using a domain admin account. ----------------------------------- Cory G. Stuart Network Administrator Nuclear Engineering Division Argonne National Laboratory ---------------------------------- -----Original Message----- From: Thommes, Michael M. Sent: Wednesday, December 10, 2003 11:46 AM To: Stuart, Cory G. Subject: FW: [ActiveDir] Rejoining Windows 2000 Systems to a Domain (2000 Native Mode) (I didn't post this to the newsgroup) When you "rejoin" a computer, you are really "joining" the computer as in a first time. You are probably trying to join with the local admin computer account that has no privileges (ie, "accessed denied"). I bet it would work if you tried joining with a domain admin account. -mike -----Original Message----- From: Stuart, Cory G. Sent: Wednesday, December 10, 2003 11:40 AM To: [EMAIL PROTECTED] Subject: [ActiveDir] Rejoining Windows 2000 Systems to a Domain (2000 Native Mode) Hi All, Sometimes when I try to rejoin a 2000 system after it has been removed from AD, I get an access denied error. I renamed the PC and rebooted. When I try to join it, I get the same error. This sometimes also happens when attempting to move the system from one domain to another within the same forest. Any help is really appreciated! Thanks, Cory ----------------------------------- Cory G. Stuart Network Administrator Nuclear Engineering Division Argonne National Laboratory ----------------------------------- List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/