+ Reply to Thread
Results 1 to 19 of 19
  1. #1
    Junior Member
    Join Date
    Aug 2005
    Posts
    9

    Access denied when adding PC to domain

     
    I have just installed a brand new 2003 server SP1 and everytime I try to join a computer to the domain I get access denied..
    I am new to 2003 and must be missing something that has to be done to allow computers to join the domain.
    So far there are no accounts apart from administrator on AD and I was using the administrators account to try and join the PC to the domain..
    Anyone got any ideas ?

  2. #2
    Ultimate Member SeanC's Avatar
    Join Date
    Oct 2001
    Location
    Toronto Canada
    Posts
    4,801
    What is the OS on the PCs you're trying to add to the domain?

    Sean

  3. #3
    Senior Member bwcc's Avatar
    Join Date
    Nov 2001
    Location
    Central KS
    Posts
    847
    Is the local admin account part of the 'domain admin' group?

  4. #4
    Junior Member
    Join Date
    Aug 2005
    Posts
    9
    The OS of the PCs is XP Pro SP2..
    I am using the default administrators account so I rekon its should be automatically in the domain admin group..

  5. #5
    Junior Member
    Join Date
    Aug 2005
    Posts
    9
    I just checked.. administrator is a member of domain admins..

  6. #6
    Perfetc Member VHockey86's Avatar
    Join Date
    Jan 2003
    Location
    Maryland Suburbia
    Posts
    4,334
    Dumb question, but just checking to make sure.

    first of, do you get a username/password prompt when you attempt to join the domain? If not, you might need to take a look at your domain security policies. Windows might be attempting to use pass-through authentication, and if the administrator passwords dont match it wont work (and you DO NOT want this anyways).

    Secondly, if it is prompting, you are entering the domain administrator password, not the local password, correct?

    Generally speaking I join to the domain as the default admin, then I add a username to domain users, and then finally add that user to the local computer under the domain (taht way you don't end up with multiple profiles for the same user on that PC (one for off the domain, and one for on the domain)).
    Last edited by VHockey86; August 29th, 2005 at 04:00 PM.

  7. #7
    Ultimate Member SeanC's Avatar
    Join Date
    Oct 2001
    Location
    Toronto Canada
    Posts
    4,801
    That's an important part. If it's not prompting for a domain admin account to add the system to the domain then it won't work.

    I always use the domain admin account to connect computers to the domain.

    Sean

  8. #8
    Ultimate Member meese's Avatar
    Join Date
    Jun 2003
    Location
    NJ
    Posts
    2,467
    Is DNS configured properly?

  9. #9
    Junior Member
    Join Date
    Aug 2005
    Posts
    9
    Yes I have the DNS on the workstation pointing at the Server. I let AD instal Wizard configure the DNS on the server..

  10. #10
    Junior Member
    Join Date
    Aug 2005
    Posts
    9
    Yes I do get the logon box for both the FQDN and the Netbios name.
    The account that I am using to join the computer with is the Domain administrators account.. however the local administrators account has the same password... Surely this would not cause a problem??

    Hres some more info..
    When it was a standalone server I setup a folder share and connected to it with the usual \\10.0.254.11 Then used the local administrators account and password to browse the HDD.

    Once I installed active directory I get access denied...
    I will go and setup another admin account with a different name and password and see if that works..

  11. #11
    Junior Member
    Join Date
    Aug 2005
    Posts
    9
    No.. that did not solve the problem...

  12. #12
    Junior Member
    Join Date
    Aug 2005
    Posts
    9
    I have noticed lots of other posts on other forums for the same problem and yet I cannot find any replies that discuss how it was fixed..

  13. #13
    Ultimate Member meese's Avatar
    Join Date
    Jun 2003
    Location
    NJ
    Posts
    2,467
    Are there any warnings or errors in the server event logs, or the client pc event logs, that may be relevant to this?

  14. #14
    Ultimate Member meese's Avatar
    Join Date
    Jun 2003
    Location
    NJ
    Posts
    2,467
    maybe have a look here: http://x220.minasi.com/forum/

  15. #15
    Senior Member bwcc's Avatar
    Join Date
    Nov 2001
    Location
    Central KS
    Posts
    847
    Ok, its been awhile since I setup my 2003 domain at home, but if I remember correctly, it has the same XP security feature of 'allow remote users to connect' under the System Properties... I vaguely remember having to set this, but I think it was for terminal services, rather than domain access. May give that a shot...

    *EDIT*

    Sorry, got home and its "allow Remote access" - so its geared towards setting it up for Terminal Services rather than domain access...

    There isn't any other software on the 2003 server that might be preventing access to it is there? Like a software firewall? Speaking of which - windows firewall is disabled, right?
    Last edited by bwcc; August 29th, 2005 at 09:19 PM.

  16. #16
    Junior Member
    Join Date
    Aug 2005
    Posts
    9
    No firewall, I can log onto the machine using TS..
    I have now tried adding the computer account manually and it says it has found a computer on the DC and I click OK..
    It then comes back with
    No mapping between account names and security ID's was done ??

    I look in the logs and there is an alert during bootup that says..
    MS DTC could not correctly process a DC promotion event..

    The MS Knowledgebase says there is nothing regarding this at this time..

  17. #17
    Senior Member
    Join Date
    Oct 2001
    Posts
    870
    Create a new account in AD. Add it to the domain admins group. Log onto the workstation with those credentials and add it to the domain. You can also create the computer account in AD first but it's not necessary. The user you want to have the ability to add computers to the domain does not HAVE to be a domain admin by the way. You just need to delegate that ability.

  18. #18
    Junior Member
    Join Date
    Aug 2005
    Posts
    9
    Thanks for all the help...
    Finally I read a post that said..
    Install tools on the server..
    then

    dfsutil /PurgeMupCache

    Did this.. and the workstation joined the domain as if by magic..

  19. #19
    Junior Member
    Join Date
    Apr 2008
    Posts
    1

    Talking Late response

    Had same problem, just change computer name, accept it---reboot, then join domain again you're good

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Access Denied.
    By Namie in forum Technical Support
    Replies: 5
    Last Post: May 27th, 2009, 01:59 PM
  2. Access denied by access control list
    By pjaj in forum Networking and Internet
    Replies: 22
    Last Post: November 29th, 2008, 05:44 PM
  3. Access Denied: Unable to access old profile
    By wineglass in forum Security and Privacy Issues
    Replies: 10
    Last Post: February 27th, 2005, 10:30 PM
  4. Access Denied
    By nicolew in forum Applications and Operating Systems
    Replies: 2
    Last Post: August 16th, 2004, 10:18 PM
  5. Access denied.
    By Mr. Fingers in forum General Tech Discussion
    Replies: 8
    Last Post: August 11th, 2002, 06:45 PM

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Recommended Sites: ResellerRatings Store Reviews