I am hoping you can help me with this problem. We are migrating from NT4 to
W2K3. Presently I have two AD domain controllers on a separate network (i.e.
x.x.2.x)from our NT domain (i.e. x.x.1.x). I have configured external trusts
between the domain and am able to migrate user accounts and SID History from
the NTDomain to the W2K3 domain successfully.
When a user logs in to either domain, a Novell server runs a logon script
using net use drive_letter: \\servername(in the NT domain)\share name
account password
persistent:no.
We have two XP TEST workstations that are in the NT domain's network
(x.x.1.x). I have created an OU for the desktops and our Security team has
put together a GPO I have applied to that OU. Then I moved those two
workstations into it.
Problem: Testers (mainly developers at this point) are able to log in and
test their applications without issue. The drive gets mapped successfully.
However if they switch between the NTDomian production file server share and
the NTDomain Test file server share, (either by logging off/on or by
disconnecting/remapping drives), the drive will no longer map at all and
eventually the error below is returned when logging back onto the XP Machine.
The only way to resolve it is to remove the XP machine from the W2K3 domain
and add it back.
Error: The account is not authorized to log in from this station
Manually runnning net use from a command prompt results in: System Error
1314 has occurred. A required privilege is not held by the client.
I have added the A records and associated PTR records in DNS for each
machine, but that does not seem to help. We would like to be able to map
drives between the two servers without having to remove/add back the machines
to the domain. Any suggestions?
-Sham
|