Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

You may receive an "Access is denied" error message when you try to query some WMI objects on a Windows Server 2003 Service Pack 1-based domain controller


View products that this article applies to.

Symptoms

You try to query some Windows Management Instrumentation (WMI) objects on a Microsoft Windows Server 2003 Service Pack 1 (SP1)-based domain controller. If you are not logged on to Windows Server 2003 as an administrator, you may receive an "Access is denied" error message. For example, when you use the Ultrasound tool to try to collect information from a Windows Server 2003 SP1-based domain controller, you may receive an error message that is similar to the following:
Access to the Ultrasound WMI provider is denied. You may need to redeploy the provider. Also it may be a clock skew more then 5 minutes between controller and provider machines.

↑ Back to the top


Cause

This issue occurs because Windows Server 2003 SP1 adds some new DCOM security features. These new features provide maximum security access to DCOM objects that are based in the new "Distributed COM Users" group. This group is a built-in group. Because all domain controllers in a domain share all the built-in groups, Windows Server 2003 SP1 does not add this group on each domain controller that is installed in the domain. Windows Server 2003 SP1 adds the new built-in group only on a Windows Server 2003 SP1-based primary domain controller (PDC).

↑ Back to the top


Resolution

To resolve this issue, make sure that you install Windows Server 2003 SP1 on the PDC first. When you do this, WMI queries do not stop working when you install Windows Server 2003 SP1 on other domain controllers.

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

↑ Back to the top


More information

Ultrasound monitoring is based on the WMI provider. The WMI provider queries a DCOM object. If the monitoring box does not have rights to access the DCOM object, the queries fails.

For more information, click the following article number to view the article in the Microsoft Knowledge Base:
903220� Description of the changes to DCOM security settings after you install Windows Server 2003 Service Pack 1

↑ Back to the top


Keywords: KB914023, kbprb, kbdomain, kbtshoot

↑ Back to the top

Article Info
Article ID : 914023
Revision : 5
Created on : 10/11/2007
Published on : 10/11/2007
Exists online : False
Views : 236