FileShare in the field of resources sometimes available from domain user

There is the strangest problem I will try to explain as thoroughly as possible.

We used DomainA (resource domain) quite happily in recent years. We have an obligation to migrate on or to DomainB users (the user's domain). We are admins on both.

We have implemented the two-way external trust between DomainA and DomainB. DomainA is a child of the forest of rootdomain. DomainB is the only area in the forest.

We have migrated all groups from DomainA to DomainB (universal local, global, domain). We have maintained the SID history.

We migrated a few users from DomainA to domainB. Both accounts are active in their respective fields. We have maintained the SID history.

We have new users in DomainB, not migrated.

The problem:

If we add the permission groups migrated a user in DomainB for a resource in DomainA, we cannot always access the resource. If we have access by name (netbios or FULL domain name), it does not. When we access by IP, it works.

If we restart the computer, it does not. If we then close, connect, access BY NAME works without problem. If we then restart and try again, access fails. Access continues to fail to all THE until a newspaper, users log on occurs.

Have carefully checked us the DNS and can nslookup both forward and backward without problem. We have even allowed WINS and set that up.

We have eliminated almost completely from group policy, just to eliminate now, default domain policy which (top view) is not the issue.

It is also non-OS specific. It happens on Windows7, Server 2003, Server 2008, Server 2012.

In addition, its not only groups of ads. drive home users have their permissions set domainA\userID and have been migrated with SID history - also fails to connect after a reboot, it works perfectly after a logout to log on. It's almost as if the Kerberos ticket is not generated correctly.

If anyone has any suggestions, we would very much appreciate ideas!

Thank you

Chris

Problem solved

Because we havbe two trusts: 1 two-way transitive trust to the domain root, 1 external trust to the child domain (resource), OR the trust was used to access the resource for the SID filtering.

We have disabled SID Filtering quarantine on the child (because the resource is in this area) but not on the root domain.

As soon as we have disabled quarantine SID on root, it started to work.

Tags: Windows

Similar Questions

  • Why all the PDF Documents open see available to all users on the network?

    Install Adobe Acrobat for all users on the network by using the same account to actviation.  All documents pdf which have been opened by any user is now available to all users.  How can I stop this?

    If you meet all THE USERS who connect to the use of the machine the same Adobe ID, then they will have access to this Adobe ID PDF files.  If you want to stop all services feature Document Cloud, then take a look at the documentation below link and apply the registry entries that are relevant.

    Integration of services

  • The Windows Task Manager - showing processes from all users

    Is it possible to get the Windows Task Manager to view all default processes?

    When the system is running very slowly it's a great nuisance to have to activate the "show processes from all users' the after you have opened the TM and waste valuable time in the process identifying guilty.

    Winston

    Hello

    I don't know of a way well there could be a... Here are some tips of perfomance and tools that can
    also be used as a troubleshooting tool.

    I just realized that if UAC is disabled him show all users remains active.

    ----------------------------------------------------------------------------------

    Process Explorer can be very useful for you.

    Be careful that a lot of these programs and services really need run and often remove some fact little
    at the speed of the machine while making the less easy to use machine.

    Optimize the performance of Microsoft Windows Vista
    http://support.Microsoft.com/kb/959062
    How to troubleshoot performance issues in Windows Vista
    http://support.Microsoft.com/kb/950685

    How to troubleshoot a problem by performing a clean boot in Windows Vista
    http://support.Microsoft.com/kb/929135

    To see everything that is in charge of startup - wait a few minutes without doing anything - then right click on the task - bar
    The task manager - take a look at stored by - Services - process - it is a quick reference (if you have
    a small box in the lower-left - show for all users can check only).

    How to check and change Vista startup programs
    http://www.Vistax64.com/tutorials/79612-startup-programs-enable-disable.html

    A quick check to see that load method 2 is - using MSCONFIG and then display a list of the people here.

    Method 1 using Windows Defender will tell you more specific information about each program.

    ---------------------------------------------

    It's a little more complicated that you might have a few running services that you can do without.

    Also some programs add services that might not really need to start automatically.

    To see these compare these in Start - type in the search box-> find Services at top right click on RUN AS ADMIN as the default Vista as shown here by BlackViper. Ignore and who are disabled (which do not run) or manual (which work only on request) - for any automatic or automatic delayed start you can post them here if you need help to decide if you should run. Some of these can be assigned to the stop and
    Manual if the program calling can run them as needed.

    BlackViper made also some improvements to default windows services but I wouldn't do those unless you
    really understand the full meaning of change a default service. Then use it as a tool to compare.

    Windows Services - list by default.
    http://www.blackviper.com/WinVista/servicecfg.htm

    WhatInStartup - free - disable/enable/remove of programs at Windows startup
    http://www.NirSoft.NET/utils/what_run_in_startup.html

    -----------------------------------------------------------

    Here are some tools that will help:

    Window Watcher - free - do you know what is running on your computer? Maybe not. The window Watcher says it all, reporting of any window created by all running programs, if the window is visible or not.
    http://www.KarenWare.com/PowerTools/ptwinwatch.asp

    Many excellent free tools and an excellent newsletter at Karenware
    http://www.KarenWare.com/

    Process Explorer - free - find out what are the files, registry keys and other objects processes have opened, the dll
    they loaded and much more. This exceptionally effective utility will show you even owned by each process.
    http://TechNet.Microsoft.com/en-us/Sysinternals/bb896653.aspx

    Autoruns - free - see what programs are configured to startup automatically when your system boots and you
    opening of session. Autoruns also shows you the full list of registry and file locations where applications can configure auto-
    start the settings.
    http://TechNet.Microsoft.com/en-us/sysinternals/bb963902.aspx
    Process Monitor - Free - monitor the system files, registry, process, thread and DLL real-time activity.
    http://TechNet.Microsoft.com/en-us/Sysinternals/bb896645.aspx

    There are many excellent free tools from Sysinternals
    http://TechNet.Microsoft.com/en-us/Sysinternals/default.aspx

    WhatsInStartUP - free - this utility displays the list of all applications that are loaded automatically when Windows
    starts. For each request, the following information is displayed: Startup Type (registry/Startup folder).
    The command - line String, product name, file Version, company name, location in the registry or the file system,
    and much more. It allows you to easily disable or remove unwanted programs that runs in your Windows startup.
    http://www.NirSoft.NET/utils/what_run_in_startup.html

    There are many excellent free tools to NirSoft
    http://www.NirSoft.NET/utils/index.html

    Hope these helps.

    Rob - bicycle - Mark Twain said it is good.

  • HP TouchSmart 520-1030: recovery of the disks are no longer available from the HP Support

    I am trying to help a friend who's HP TouchSmart 520-1030 hard disk is dead.  I have the HP support site, fill out forms to buy 5 DVD System Recovery Disk Set Kit for this system. He even asked for my credit card information. Only after that I entered all this information, the system told me that the recovery kit was no longer available for this system. I tried to download a Windows 7 from Microsoft, but because the key of Windows 7 has been an OEM key, they told me I'd get from HP. I called HP support and they said that they could not get the kit. I asked them if I bought a new copy of Windows 7, the drivers would be available at HP. The phone technology said he didn't know. I asked him if he could tell me how I could know, he says 'No, good night' and hung up. I was not rude or anything. Very professional, in my opinion. In any case, I'm stuck. I know that my friend should have the recovery disks, but it didn't. Does this mean that he should throw a 3 year, $750 all-n-one computer? Does anyone have any suggestions? Thanks in advance!

    If HP does no more, it is available here:

    http://www.computersurgeons.com/p-22059-Windows-7-64-bit-recovery-kit-a7c03av-for-HP-TouchSmart-desktop-PC-model-number-520-1030.aspx

  • You can mark the fields to show or hide based on user input?

    I have a 25 part form my users quite frequently - currently, it is stored in 25 documents Word and end users choose parts whatever they need and copy and paste into a form.  I am responsible for creating a form with all its 25 parts in there - not much, but the form should work so that the text they choose to is displayed and the rest is hidden. Is there a way to label conditional text field based on the selection of the end user?

    For example - there are checkboxes with a number followed by a text box with a sentence or 2 up to 5 or 6 short paragraphs. Users would select the required check boxes and have the text flow in a letter and the Coachman does not display areas of respective text that are disabled.

    Can I put each box and the following text in a subform and code somehow to display when the user wants?

    Thanks in advance for your help with this.

    R

    Sent the updated form a separately.

    Let me know if it helps.

    Thank you

    Srini

  • The manuals are no longer available from the Dell Support for my ' M17x... ?

    For a long time now, I have noticed that under what support I left dell/site support when entering my service tag that details under section of manuals / the manual for my m17x had gone missing and was there is always the manual but for servicng my m17x.

    But now I see even this repair has also been removed is there anyone who knows why it happpened thanks.

    Now all of a sudden the repair appeared and so I answer my own post it seems incredible things: P

  • Could not start the print job. Is available from the printer? Charge of CS3 on Windows 7 64 bit

    Hi all:

    I have a PC network. As part of their basic installation, I load on CS3. I started to integrate Windows 7 and found the following on each problem, but not on one of the XP.

    When my users try to print from Acrobat 8 that they receive the following message is displayed: "could not start the print job. I have a printer? ».

    This happens when trying to print to one of our printers, the printer HP designjet 1055. I have the drivers 32 bit and 64 bit installed on our print server.

    I read a post somewhere in program files common files could play up because there are 2 location of files of program on windows 7 - but I'm no more on this one here.

    I don't know there is a work around for this issue, recorded for the 101 others.

    Someone at - it ideas?

    CS3 has AA7 I think, maybe AA8. Compatibility Win7's AA9. Others may work, but the risk becomes yours. Adobe will tell you simply to upgrade. Several people have AA8 working most of the time. I think that a few may have succeeded with AA7, but I'm a little surprised.

  • How to configure the logo screen of handguns to several domain user time?

    How to configure the logo screen in time to punch to several domain like domain1\administrator, domain2\administrator and My-PC1\administrator user in windows 2007?

    Hello

    It is better suited for the IT Pro TechNet public. Please post your question in the TechNet Forums. You can follow the link to your question:

    http://social.technet.Microsoft.com/forums/en-us/w7itpronetworking/threads

    For reference:

    http://social.technet.Microsoft.com/forums/en/w7itpronetworking/thread/de5fea8e-E327-4D71-a599-546dea543149

    Hope this information helps.

  • Windows App Store available to all users of a computer.

    After I download an app on the App Store, I don't find this application to put on-screen of metro on the other usernames on the computer.  How can I make the apps I've downloaded available to all users on the computer?

    This answer is useful, but it seems to imply that each user who wants to use the app will have their own personal copy of the program on the same computer.

    It is good that an app should only be bought once for any device/computer/tablet, but it's still pretty stupid if on a given device, we still have wind upward with multiple copies of the app!

    Hello

    Each app is installed only once on each computer.

    When the administrator installs the application in a different user on the same computer account, giving that user access to the one already installed app and places a copy of the files of configuration apps in this personal user files so that the user can configure the application for their own personal needs.

    Concerning

  • Logged in as admin. Cannot change the domain users group to the domain administrator

    My domain administrator is defined as a domain user and I want to change it to domain administrator. The groups gathered outside the account > users > Admin > groups section.

    Hello Tripline,

    Please provide number and firmware version of your ReadyNAS model.

    What's your ReadyNAS built-in AD? The ReadyNAS will simply copy the accounts of the ADS in your ad. Existing domain user, 'Administrator' should be adjusted to have administrator rights. I guess you should change everything first, and then integrate the NAS again to the AD.

    Kind regards

  • The user - fields of resources search page

    Hello world.

    I want to add the resource to the advanced user search page.
    When I Anvanced-> Configuration-> Configuration-> configure the search user, I can't see selection of the resource to add the search parameter.

    How can I add a search of resource setting?

    Thank you.
    Kind regards.

    I don't think that attribute resource is available with the schema user vo. If the attribute does not exist in the schema you can make customization available.,.

    In this case you required for updating schema for this field.

    customizaion detail check below link * (25.6 adding or removing columns in the Console Tables) *.
    http://docs.Oracle.com/CD/E17904_01/doc.1111/e14309/uicust.htm

    I think it will be a tedious job for you

    -nayan

  • I'm unable to open one of my 'recent documents' document. It is said to make sure that the network resource is available.

    Original title: "Recent Documents".

    I'm unable to open one of my 'recent documents' document.  It is said to make sure that the network resource is available.  What does that mean?  And I can't find the document in "My Documents" is.  And I tried a search.

    Hello

    The error means either that the document no longer is located in the folder it was when it was finally opened or the location that the file was initially located in is no longer in the same place.

    Example 1: I open a document in the My Documents folder, then after closing the document, I moved manually the file to the desktop.

    Example2: I open a document located on a removable hard drive. After the closure of the paper, I then disconnect the removable hard drive of the PC.

    In these two examples, Windows would be able to find the Document using the "Recent Documents" list

    Step 1: I recommend that you check the trash or see if the document is located on a removable hard drive (or USB key) that is is more attached to the computer.

    Step 2: Use recovery software of the third party to recover the document.
     
    THIRD WARNING:
    Using third-party software, including hardware drivers can cause serious problems that may prevent your computer from starting properly. Microsoft cannot guarantee that problems resulting from the use of third-party software can be solved. Software using third party is at your own risk.

  • Not able to see the fields within a custom resources optimization

    Hi all

    I am not able to see the fields within a custom value.

    Here is my code for the custom resource optimization:

    public class CustomContentContainer extends VerticalFieldManager{
    
        String content_header;
        int container_height;
        int displayWidth = Display.getWidth();
        int displayHeight = Display.getHeight();
    
        public CustomContentContainer(String content_header,int height){
            super(Manager.NO_VERTICAL_SCROLL | Manager.NO_HORIZONTAL_SCROLL);
            this.content_header = content_header;
            container_height = displayHeight-height;
        }
    
        protected void sublayout(int maxWidth, int maxHeight) {
            super.sublayout(maxWidth, container_height);
            setExtent(maxWidth,container_height);
        };
    
        protected void paint(Graphics graphics)
        {
            int X_POS = 20;
            int Y_POS = 20;
    
            int width = displayWidth;
            int height=container_height;
            int[] xPts = {0, width, width, 0};
            int[] yPts = {0, 0, height, height};
            int[] colors = { 0xffffff, 0xf7f7f6, 0xd4d0cc, 0xb0a9a2 };
            graphics.drawShadedFilledPath(xPts, yPts, null, colors, null);
    
            graphics.setColor(0xc0c0c0);
            graphics.drawRoundRect(X_POS, Y_POS, getWidth()-40, container_height-40, 10,10);
    
            int stringWidth = getFont().getAdvance(content_header);
            graphics.setColor(0xF8F8F8);
    
            graphics.fillRect(35, 5, stringWidth+10, 30);
    
            graphics.setColor(0xFF0000);
            graphics.drawText(content_header, 40, 5);
        };
    
    }
    

    Here is the Code inside the class from the main screen

    settingsContainer = new CustomContentContainer("Settings",vodavaultLogo.getHeight());
            contentContainer = new VerticalFieldManager(Manager.VERTICAL_SCROLL|USE_ALL_WIDTH);
    
            passwd1 = new CustomEditField();
            passwd2 = new CustomEditField();
            contentContainer.add(passwd1);
            contentContainer.add(passwd2);
            contentContainer.setMargin(35,35,35,35);
    
            mainContainer.add(vodavaultLogoField);
            settingsContainer.add(contentContainer);
            mainContainer.add(settingsContainer);
            add(mainContainer);
    

    You must call the super.paint (.) in your paint (...) optimization of resources, if you paint all areas which are added.

  • An error occurred when trying to share < folder name >. There is no end point for more available from the endpoint mapper. The shared resource was not created at this time

    Original title: sharing folder error

    How to solve this error message when I am trying to share a folder: "an error has occurred when trying to share . There is no end point for more available from the endpoint mapper. The shared resource was not created at this time. »

    Hello

    Were there any changes made on the computer before the show?

    I suggest to see the link and try to run the Troubleshooter:

    Share files with anyone

    http://Windows.Microsoft.com/en-us/Windows7/share-files-with-someone

    See also:

    File sharing essentials

    http://Windows.Microsoft.com/en-us/Windows7/file-sharing-essentials

  • "The memory resources available in the pool of resources of the parent are insufficient for the operations." ... Really?

    Hello

    We have three virtual machines on a host computer. They need to be pinned to this host and with reserved memory: 1 GB, 4 GB, 8 GB.

    We are talking about 13 GB of RAM on a physical server that has 16 GB of physical RAM.

    When I Power On last VM, I get the following error:

    "The memory resources available in the pool of resources of the parent are not enough for the operation."

    I have a second host with the same size of memory and use reach 14GB of memory.

    I know that each virtual machine wants more memory than what we have configured, but I would like to know if it's a "bug" or

    something we can fix via vCenter configuration, or we really need more physical memory.

    Please find attached the config of memory for the virtual machine and the host State.

    Thanks in advance for your help.

    Host needs some memory as well for things like vmkernel, drivers and other components and you will not be able to touch this area with reserves of VM. It is not a bug, more like a fuse. You will not be allowed to book all of the physical RAM to VMs and / or resource pools.

    In your case, you should either decrease the reserves (why are you booking 100% memory for your virtual machines? What you're trying to achieve with this setting? Is it an obligation of the seller to App?) or increase the amount of physical RAM on the host.

    Of course this depends on your specific requirements and management policies of the resources, but in most cases I've seen, reservations are only affected when there is a heavy statement memory and using actions alone is not enough. Even so, reservations are usually configured only for very high priority / criticality VMs and not 100%, but rather a little before "stable / persistent peak memory Active" value. F.x. If a particular virtual machine has more mem use regularly on Wednesday 1-3 PM and memory active value for this period is 3 GB, a reservation is usually set to something like 4GB.

    I hope this helps.

Maybe you are looking for