Windows DatabaseebooksStatistical Information

LWE10084 : User Domain - Login fails or has errors due to too many group memberships

Symptom:

User cannot login or misses resources provided by loginskript or group policies

Cause:

User has too many group memberships for default kerberos token size

Solution:

Errormessage upon user-logon:

"Error browsing user memberships - Error loading user object for user: <DOMAIN>\<USER>." and something like 'not sufficient memory for this task.' 

Other errors can be, that group policies (GPO) are not applied.

The solution can be to change the value for "MaxTokenSize" in your registry:

HKLM\System\CurrentControlSet\Control\LSA\Kerberos\Parameters

DWORD "MaxTokenSize" --> 0xFFFF (decimal 65535)

!!! this key changes kerberos authentication. The default value is 12000 (decimal).
!!! changing this key to values greater than 0xFFFF (or 65535) can cause "Timeout expired" errors in MS SQL Server communication or WBEM / RPC issues as SMS administrator

Nach einem Neustart können alle Gruppenmitgliedschaften ausgelesen werden.


Disclaimer:

The information provided in this document is intended for your information only. Lubby makes no claims to the validity of this information. Use of this information is at own risk!
Copyright © 2004-2011 Lubby (V3.0.10 Aug 2011)
Sponsored by Keskon.
Statistical information by Google Analytics