[Samba] Weird GPO issue with Win11 clients

Andreas Oster aoster at novanetwork.de
Fri Jul 26 05:54:00 UTC 2024


Hi all,

for some time now I am struggling with an odd GPO issue which only seems 
to affects Windows 11 but not Windows 10 clients.

When installing a new Windows 11 client and joining it to the domain  
the client fetches and applies all the configured computer GPOs. After 
this initial step the client is no longer able to update its assigned 
GPOs as the Default Domain Policy can not be accessed on startup ( 
ErrorCode 1326, username or password wrong). As mentioned the Windows 10 
clients do not seem to face this issue.

The only way to get the Win11 clients to update the GPOs is to remove 
them from the domain and to re-join them again. This is obviously not an 
ideal solution.

Did someone out there have a similar problem and/or knows a solution to 
this ?

We are running samba version 4.20.3-GIT  with 2019 schema and 2016 
function/forest level

Thank you for your kind help.

Best regards
Andreas
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <http://lists.samba.org/pipermail/samba/attachments/20240726/cc3789ab/OpenPGP_signature.sig>


More information about the samba mailing list