Microsoft KB Archive/319352

= Event ID 1000 and event ID 1202 are logged to the event log every five minutes in Windows 2000 Server =

Article ID: 319352

Article Last Modified on 10/30/2006

-

APPLIES TO


 * Microsoft Windows 2000 Server

-



This article was previously published under Q319352



SYMPTOMS
On your Microsoft Windows 2000 Server-based computer, both of the following event IDs may be logged to the application event log every five minutes: Event Type: Warning

Event Source: SceCli

Event Category: None

Event ID: 1202

Date: 02/19/2002

Time: 10:13:10 am

User: N/A

Computer:

Description: Security policies are propagated with warning. 0x5: Access is denied. Please look for more details in TroubleShooting section in Security Help.

Event Type: Error

Event Source: Userenv

Event Category: None

Event ID: 1000

Date: 02/19/2002

Time: 10:13:11 am

User: NT AUTHORITY\SYSTEM

Computer:

Description: The Group Policy client-side extension Security was passed flags (17) and returned a failure status code of (5).

If verbose error logging is enabled during Group Policy processing in your domain, the following entries may be logged to the application event log every five minutes: Security policies are propagated with warning. 0x5: Access is denied. Please look for more details in TroubleShooting section in Security Help.

The Group Policy client-side extension Security was passed flags (81) and returned a failure status code of (5).

Windows cannot process extension Security ProcessGroupPolicy. Return value (0x5).

If Security Configuration Client logging is enabled during Group Policy processing in your domain, the following entry is logged in the winlogon.log file: Process GP template gpt00000.dom.

This is not the last GPO.

---

02/19/2002 12:34:08 Administrative privileged user logged on.

Invoke Registry Value Delay Filter.

Analyze machine\software\microsoft\driver signing\policy.

Analyze machine\software\microsoft\non-driver signing\policy.

...

Analyze MACHINE\System\CurrentControlSet\Control\Lsa\SubmitControl.

Parsing template C:\WINNT\security\templates\policies\gpt00000.dom.

Warning 5: Access is denied.

Error deleting SCP.

Configuration engine is initialized with error.

Un-initialize configuration engine...

The Winlogon.log file of other domain controllers in the domain may display messages with error code 1450 (ERROR_NO_SYSTEM_RESOURCES).

Note The corresponding description of the code 1450 error message is as follows: Insufficient system resources exist to complete the requested service.



RESOLUTION
To resolve this issue, change the domain mode from mixed mode to native mode. To do so, follow these steps.

Note This is not the recommended method to resolve this issue. Microsoft is researching this issue and will post new information in the Microsoft Knowledge Base when that information is available.
 * 1) Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Domains and Trusts.
 * 2) Right-click the domain that you want to change, and then click Properties.
 * 3) On the General tab, click Change Mode under domain operations mode, and then click Yes.

Note Make sure that all the domain controllers in the domain are upgraded to Windows 2000 Server before you change the domain to native mode. After you change to native mode, you cannot change back to mixed mode.



STATUS
Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the &quot;Applies to&quot; section of this article.

