Event 1202 error

Scott

Distinguished
Apr 1, 2004
1,356
0
19,280
Archived from groups: microsoft.public.win2000.group_policy (More info?)

I'm running W2K Server (SP4) on a domain controller.
Fairly simple setup, one server and six workstations
running either W2K Prof. or Win XP Prof. Just recently I
started getting an Event 1202 error in the application log:

Event Type: Warning
Event Source: SceCli
Event Category: None
Event ID: 1202
Date: 6/2/2004
Time: 3:10:45 PM
User: N/A
Computer: PREMIER-SERVER
Description:
Security policies are propagated with warning. 0x4b8 : An
extended error has occurred.

For best results in resolving this event, log on with a
non-administrative account and search
http://support.microsoft.com for "Troubleshooting Event
1202s".


I enabled logging per a MS troubleshooting KB article and
after refreshing policy settings this is the log file
generated every five minutes:

Error 0 to send control flag 1 over to server.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )

[Mapping] gpt00000.dom = Default Domain Policy
-------------------------------------------
06/02/2004 05:45:40
Invoke Registry Value Delay Filter.
Analyze machine\software\microsoft\windows
nt\currentversion\setup\recoveryconsole\securitylevel.
Analyze machine\software\microsoft\windows
nt\currentversion\setup\recoveryconsole\setcommand.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatecdroms.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatedasd.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\allocatefloppies.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\cachedlogonscount.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\passwordexpirywarning.
Analyze machine\software\microsoft\windows
nt\currentversion\winlogon\scremoveoption.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\disablecad.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\dontdisplaylastusername.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\legalnoticecaption.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\legalnoticetext.
Analyze
machine\software\microsoft\windows\currentversion\policies\
system\shutdownwithoutlogon.
Analyze
machine\system\currentcontrolset\control\lsa\auditbaseobjec
ts.
Analyze
machine\system\currentcontrolset\control\lsa\crashonauditfa
il.
Analyze
machine\system\currentcontrolset\control\lsa\fullprivilegea
uditing.
Analyze
machine\system\currentcontrolset\control\lsa\lmcompatibilit
ylevel.
Analyze
machine\system\currentcontrolset\control\lsa\restrictanonym
ous.
Analyze
machine\system\currentcontrolset\control\print\providers\la
nman print services\servers\addprinterdrivers.
Analyze
machine\system\currentcontrolset\control\session
manager\memory management\clearpagefileatshutdown.
Analyze
machine\system\currentcontrolset\control\session
manager\protectionmode.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\autodisconnect.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\enableforcedlogoff.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\enablesecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanserver\para
meters\requiresecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\enableplaintextpassword.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\enablesecuritysignature.
Analyze
machine\system\currentcontrolset\services\lanmanworkstation
\parameters\requiresecuritysignature.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\disablepasswordchange.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\requiresignorseal.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\requirestrongkey.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\sealsecurechannel.
Analyze
machine\system\currentcontrolset\services\netlogon\paramete
rs\signsecurechannel.
Analyze
MACHINE\System\CurrentControlSet\Control\Lsa\SubmitControl.
Analyze MACHINE\Software\Microsoft\Non-Driver
Signing\Policy.
Analyze MACHINE\Software\Microsoft\Driver
Signing\Policy.
Error 1208: An extended error has occurred.
Error deleting SCP.
----Configuration engine is initialized with error.----


----Un-initialize configuration engine...
**************************


I am not receiving an Event 1000 error.

Sorry for the long post but this is over my head. I have
not changed any active directory settings in the recent
past. Anyone have any suggestions? Thanks in advance.
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.group_policy (More info?)

See if this helps:
http://www.eventid.net/display.asp?eventid=1202&eventno=348&source=SceCli&phase=1
--

Adrian Grigorof
www.eventid.net

"Scott" <scott@premier-pallets.com> wrote in message
news:1747901c448d8$16e070c0$a401280a@phx.gbl...
> I'm running W2K Server (SP4) on a domain controller.
> Fairly simple setup, one server and six workstations
> running either W2K Prof. or Win XP Prof. Just recently I
> started getting an Event 1202 error in the application log:
>
> Event Type: Warning
> Event Source: SceCli
> Event Category: None
> Event ID: 1202
> Date: 6/2/2004
> Time: 3:10:45 PM
> User: N/A
> Computer: PREMIER-SERVER
> Description:
> Security policies are propagated with warning. 0x4b8 : An
> extended error has occurred.
>
> For best results in resolving this event, log on with a
> non-administrative account and search
> http://support.microsoft.com for "Troubleshooting Event
> 1202s".
>
>
> I enabled logging per a MS troubleshooting KB article and
> after refreshing policy settings this is the log file
> generated every five minutes:
>
> Error 0 to send control flag 1 over to server.
> GPLinkDomain GPO_INFO_FLAG_BACKGROUND )
> GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )
>
> [Mapping] gpt00000.dom = Default Domain Policy
> -------------------------------------------
> 06/02/2004 05:45:40
> Invoke Registry Value Delay Filter.
> Analyze machine\software\microsoft\windows
> nt\currentversion\setup\recoveryconsole\securitylevel.
> Analyze machine\software\microsoft\windows
> nt\currentversion\setup\recoveryconsole\setcommand.
> Analyze machine\software\microsoft\windows
> nt\currentversion\winlogon\allocatecdroms.
> Analyze machine\software\microsoft\windows
> nt\currentversion\winlogon\allocatedasd.
> Analyze machine\software\microsoft\windows
> nt\currentversion\winlogon\allocatefloppies.
> Analyze machine\software\microsoft\windows
> nt\currentversion\winlogon\cachedlogonscount.
> Analyze machine\software\microsoft\windows
> nt\currentversion\winlogon\passwordexpirywarning.
> Analyze machine\software\microsoft\windows
> nt\currentversion\winlogon\scremoveoption.
> Analyze
> machine\software\microsoft\windows\currentversion\policies\
> system\disablecad.
> Analyze
> machine\software\microsoft\windows\currentversion\policies\
> system\dontdisplaylastusername.
> Analyze
> machine\software\microsoft\windows\currentversion\policies\
> system\legalnoticecaption.
> Analyze
> machine\software\microsoft\windows\currentversion\policies\
> system\legalnoticetext.
> Analyze
> machine\software\microsoft\windows\currentversion\policies\
> system\shutdownwithoutlogon.
> Analyze
> machine\system\currentcontrolset\control\lsa\auditbaseobjec
> ts.
> Analyze
> machine\system\currentcontrolset\control\lsa\crashonauditfa
> il.
> Analyze
> machine\system\currentcontrolset\control\lsa\fullprivilegea
> uditing.
> Analyze
> machine\system\currentcontrolset\control\lsa\lmcompatibilit
> ylevel.
> Analyze
> machine\system\currentcontrolset\control\lsa\restrictanonym
> ous.
> Analyze
> machine\system\currentcontrolset\control\print\providers\la
> nman print services\servers\addprinterdrivers.
> Analyze
> machine\system\currentcontrolset\control\session
> manager\memory management\clearpagefileatshutdown.
> Analyze
> machine\system\currentcontrolset\control\session
> manager\protectionmode.
> Analyze
> machine\system\currentcontrolset\services\lanmanserver\para
> meters\autodisconnect.
> Analyze
> machine\system\currentcontrolset\services\lanmanserver\para
> meters\enableforcedlogoff.
> Analyze
> machine\system\currentcontrolset\services\lanmanserver\para
> meters\enablesecuritysignature.
> Analyze
> machine\system\currentcontrolset\services\lanmanserver\para
> meters\requiresecuritysignature.
> Analyze
> machine\system\currentcontrolset\services\lanmanworkstation
> \parameters\enableplaintextpassword.
> Analyze
> machine\system\currentcontrolset\services\lanmanworkstation
> \parameters\enablesecuritysignature.
> Analyze
> machine\system\currentcontrolset\services\lanmanworkstation
> \parameters\requiresecuritysignature.
> Analyze
> machine\system\currentcontrolset\services\netlogon\paramete
> rs\disablepasswordchange.
> Analyze
> machine\system\currentcontrolset\services\netlogon\paramete
> rs\requiresignorseal.
> Analyze
> machine\system\currentcontrolset\services\netlogon\paramete
> rs\requirestrongkey.
> Analyze
> machine\system\currentcontrolset\services\netlogon\paramete
> rs\sealsecurechannel.
> Analyze
> machine\system\currentcontrolset\services\netlogon\paramete
> rs\signsecurechannel.
> Analyze
> MACHINE\System\CurrentControlSet\Control\Lsa\SubmitControl.
> Analyze MACHINE\Software\Microsoft\Non-Driver
> Signing\Policy.
> Analyze MACHINE\Software\Microsoft\Driver
> Signing\Policy.
> Error 1208: An extended error has occurred.
> Error deleting SCP.
> ----Configuration engine is initialized with error.----
>
>
> ----Un-initialize configuration engine...
> **************************
>
>
> I am not receiving an Event 1000 error.
>
> Sorry for the long post but this is over my head. I have
> not changed any active directory settings in the recent
> past. Anyone have any suggestions? Thanks in advance.