Unable to edit Default Domain Policy : Failed to open group policy object. The might not have the appropriate rights. Details: The network name cannot be found.

hendri yu 66 Reputation points
2020-12-07T10:52:55.107+00:00

Dear Microsoft Expert,

Good Day

We have 2 local domain controllers, DC3 and DC2. Both of these are running Windows Server 2012 Data Centre. The SYSVOL folder is actually available on DC2 only, hence I know that the GPO is residing in DC2. Recently, we have setup new AD running Windows Server 2019 Standard, DC1 and we actually demoted DC3.

After we setup DCPROMO DC1 and make it up as the new DC, then we are actually transferring FSMO roles to new DC1. Currently, the FSMO roles is with DC1. Below is the screenshot:

45762-dc1-fsmo.png

However, after that i am not able to edit the Default Domain Policy anymore from any of the DC. Once i click to edit on any DC, it will show the error message as below:

45717-dc1-gpo-error1.png

I have double checked that the SYSVOL folder is still available in DC2 and i am able to access via the network path and i am still able to find the unique ID in that folders. it means that I have the necessary access right since i am the domain admins. The folder and the files inside are still available and intact.

45679-dc1-gpo-uniqueid.png

Here is the folder location of the policy in DC2:

45580-dc1-gpo-uniqueid-location.png 2: /api/attachments/45717-dc1-gpo-error1.png?platform=QnA
Do you guys has any advise on how to resolve the issue?

Many Thanks for help

Best Regards,

H

Windows for business Windows Client for IT Pros User experience Other
{count} votes

3 answers

Sort by: Most helpful
  1. Anonymous
    2020-12-08T03:53:55.833+00:00

    Hi,
    1,As you promoted a new DC recently, i would suggest you firstly check if the new DC can working well :
    Dcdiag /v >c:\dcdiag1.log
    Repadmin /showrepl >C:\repl.txt
    Repadmin /showreps * 
    Repadmin /syncall /APeD
    Ipconfig /all on both the DCs.
    2,Before promote the new DC, did you make sure DFSR is used for the AD sysvol replication?
    3, If the sysvol synced between DC1 and DC2
    access the sysvol folder on DC1, if the files were synced from DC2,
    If the permission was correctly
    Best Regards,


  2. Thameur-BOURBITA 36,261 Reputation points Moderator
    2020-12-20T13:10:50.797+00:00

    Hi,

    Try to launch a non-authoritative restore to initiate the sysvol replication. it you still have same issue you can launch a authortaive restore from healthy domain controller. It can fix some corrupted files in sysvol folder.

    force-authoritative-non-authoritative-synchronization

    Please Don't forget to mark this reply as answer if it help you to fix your issue


  3. JoseLuisTorresCisneros-3701 0 Reputation points
    2023-03-07T19:29:09.8+00:00

    tengo el mismo problema y situacion con DC1 y DC2 nuestra intension es dejar en produccion DC1 pero no hemos podido quitar DC2 por el tema de las politicas de grupo, alguien ha solucionado este error?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.