Microsoft KB Archive/896983

= You cannot apply Group Policy settings after you rename a Windows Server 2003-based domain =

Article ID: 896983

Article Last Modified on 11/1/2006

-

APPLIES TO


 * Microsoft Windows Server 2003, Standard Edition (32-bit x86)
 * Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
 * Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)

-





SYMPTOMS
After you rename a Microsoft Windows Server 2003-based domain, you cannot apply Group Policy settings on the member server of this domain. Additionally, the following event may be logged in the Application event log:

Event Type: Error Event Source: Userenv Event Category: None Event ID: 1058 Description: Windows cannot access the file gpt.ini for GPO CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC= ,DC=com. The file must be present at the location <\\ \sysvol\ \Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>. . Group Policy processing aborted.



CAUSE
This issue occurs if you use the original release or the April 15, 2003 release of the Rendom.exe utility to rename the domain after you perform one of the following procedures:
 * You convert a child domain into the root of a domain tree.
 * You convert the root of a domain tree into a child domain.

The Rendom.exe utility incorrectly handles the rootTrust and trustParent attributes on the cross-ref object of renamed domains.



RESOLUTION
To resolve this issue, download version 1.4 of the Rendom.exe utility, and then perform the domain-renaming operation. To download version 1.4 of the Rendom.exe utility, visit the following Microsoft Web site:

Note There is no plan to update the Rendom.exe utility in Windows Server 2003 Service Pack 1 (SP1). Version 1.4 of the Rendom.exe utility only prevents the issue that is described in the &quot;Symptoms&quot; section. This version of the Rendom.exe utility does not help you recover from the problems that are caused by the original release of the Rendom.exe utility.



WORKAROUND
To work around this issue, modify the rootTrust and trustParent attributes. To do this, use one of the following methods:
 * Use the ADSIEdit tool to delete the rootTrust attribute on the cross-ref object. Then, re-add the rootTrust attribute. Also use the ADSIEdit tool to delete the trustParent attribute on the cross-ref object. Then, re-add the trustParent attribute..
 * Use the ADSIEdit tool to assign different values to the rootTrust and trustParent attributes. Then, change these values back to their previous settings.

After the metadata is replicated, this issue is resolved.

For more information about the ADSIEdit tool, visit the following Microsoft Web site:

http://technet2.microsoft.com/windowsserver/en/library/ebca3324-5427-471a-bc19-9aa1decd3d401033.mspx

Keywords: kbprb kbinfo KB896983

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.