VMware Cloud Community
hons
Contributor
Contributor

Cannot logon w/ domain a/c in virtual DC

Hi,

I setup a MS network w/ 1 DC, 1 FS and several PCs in Vsphere 5.1. After I setup everything, if I'm in the Vsphere's console, I can logon to all the VMs w/ Domain A/C without any problem. But, if I use Remote Desktop from a physical PC, I can logon w/ a local A/C but not w/ a Domain A/C. Does anybody have the similar problem like this???

I also found that if I use the Vsphere console to logon to the VMs, I can logon but they won't create the user in the "USERS" folder.

Anybody can help????

Thanks.

Reply
0 Kudos
12 Replies
lakshya32
Enthusiast
Enthusiast

Hi hons

Welcome to the forum.

what about rights ?

Have you added those domain user to remote desktop user group ?

and make sure password should nt be blank if so then you will not able to take control.

"When you fail to plan, you plan to fail."
Reply
0 Kudos
Josh26
Virtuoso
Virtuoso

Sounds like the DNS is pointing somewhere other than the domain controller.

Paste an ipconfig /all from your DC and FS.

Reply
0 Kudos
wklemish
Contributor
Contributor

Hello,

I am currently out of the office. If you need assistance, please contact the Tampa Media Group Help Desk through the Help Desk icon on your desktop. For Business Critical issues, please call the help desk at 813-259-8182.

Thank You,

Emma Chambers

Reply
0 Kudos
hons
Contributor
Contributor

Thanks for your reply.

I did add the users to the RD users group. I can use the same A/C to logon to the DC but not other servers. Even when I use the "Administrator" A/C got the same result. If I logon with "domain\administrator" to the file server it will say "Your Credentials did npt work. It will go through if I use "PC\Administrator".

Any idea???

Reply
0 Kudos
hons
Contributor
Contributor

To Josh26,

I checked the DNS is running OK. It resolved names and IPs correctly. The problem is, when I use any domain A/C to logon, it won't create an user. (When an user logon to the machine, the server or PC should create a user int the C:\USERS\. For example,if a local A/C then "PCUSER". If it's a domain A/C then should be "PCUSER.domain). But when I check the servers and PCs, I didn't found any of the A/Cs' folder created. Don't understand why.

Reply
0 Kudos
hons
Contributor
Contributor

I just tested on "Virtual Box" got the same result. Anyone have the same experience?? I try to explain one more time to see if I can make it clear.

1)  I setup 2 VMs (All 2k8 r2 sp1) : 1 setup and promoted to domain controller (AD) while the other one configured as file server. Both VMs disabled firewall and enabled remote desktop access to all.

2)  After the AD setup, checked the servers can access each other and DNS is function OK.

3)  Created several admin A/Cs (adadmin1, adadmin2...) in the AD (grouped into Domain Admin, Ent Admin and Administrators).

4)  When I'm in the VMs, I can logon with every A/Cs.

5)  When I use another physical PC or VM PC to logon to the file server via remote desktop, I get the error message (even with the domain\administrator account).

2134824.png

Anybody know about this problem??

Thanks.

Reply
0 Kudos
Josh26
Virtuoso
Virtuoso

This surely isn't a VMware issue.

Some suggestions..

Note, you say "domain\administrator" however your screenshot doesn't list the domain. In this case, you may find it attempting to use the local administrator. Test "use another account" and type in the full domain\administrator username.

You say "DNS is fine", but paste us an ipconfig /all from that file server because it still may not be

Run a dcdiag on the server and paste the output

Review the security and application event logs on your file server. If it receives the connection at all, it should log something, and mention why it failed

Reply
0 Kudos
hons
Contributor
Contributor

Josh26,

Thanks for your reply. I attached the files. I also made another shot the show the A/C is a domain admin.

2134824.png

Thanks again for your help.

Reply
0 Kudos
Josh26
Virtuoso
Virtuoso

Try logging on as..

administrator@ui.local

Reply
0 Kudos
hons
Contributor
Contributor

Did try, got the same error.

I tried : UI\administrator and UI.LOCAL\Administrator got the same result. It lloks like the server doesn't accept any domain A/C login.

Reply
0 Kudos
hons
Contributor
Contributor

Josh26,

The following screens are the result. Any idea??  Thanks.

2135361-1.png2135361-2.png

Reply
0 Kudos
hons
Contributor
Contributor

Problem solved.

The problem was when I created the VMs, I created a master 2008r2 VM and then cloned into a DC and FS. After everything setup, the VMs have the same SID so when I tried to use a domain A/C to logon, it gives SID error in the log.

I recreated the VMs and did the "Sysprep" to each VM the first time strat up. Setup the AD and everything running OK.

Thanks for your help.

Attached the links for some more info.  as reference.

http://www.brajkovic.info/windows-server-2008/windows-server-2008-r2/how-to-change-sid-on-windows-7-...

Reply
0 Kudos