Do you have any healthy DC in the environment. If so you can perform non-authoritative restore on the broken DC
https://learn.microsoft.com/en-us/troubleshoot/windows-server/group-policy/force-authoritative-non-authoritative-synchronization
how do i fix 31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini error on gpupdate /force command
So when i tried to run the command gpupdate /force on my doamin client computer it spits out a error
Windows attempted to read file \hq.Jatechdesk.lu\sysvol\hq.Jatechdesk.lu\polices{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. group policy settings may not be applied till this issue is resolved.
I have gone to the path where the {31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini file is located and tried to change to permissions for access for Authenticated Users and System,
that does not work.
thigns i have tried doing to fix this issue
- change file perms
- deleted the gpt.ini file, then gpupdated /forced the laptops connected to the domain controller, then gone back and added the file back and gp updating it again.
- changing the Version inside the ini file to version 1, 5, 2, and 4
- deleting the {31B2F340-016D-11D2-945F-00C04FB984F9} folder but i cant because i need administrators perms even though im doing it as a Domain administrator.
- i have tried dcgpofix command in powershell as administrator but it says access denied.
- changing dns settings
- turning DFS on and Off
- CHDSK the whole server
- taking ownership of {31B2F340-016D-11D2-945F-00C04FB984F9} folder to try and Delete it, this also failed
- sharing the {31B2F340-016D-11D2-945F-00C04FB984F9} and gpt.ini file and giving authenticated users full access including domain ad and system.
- replacing the gpt.ini file code.
- replacing the gpt.ini file with another gtp.ini file that works
- smashing the laptop lol
- changing the file share perms for the GPT.ini file only.
- Renaming the gpt.ini file name to GPT.ini instead of gpt.ini
- removing the registry.vol file and gp updating and adding the file back again.
- removing the laptop from the domain and adding it back.
i think the only way to fix this is to demote the domain controller and then re premote it and start fresh from scratch.
if anyone can help me fix this feel free to contact me on discord or here.
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
1 answer
Sort by: Most helpful
-
Vaidish 76 Reputation points
2022-12-26T22:47:05.887+00:00