Recommended Posts

Hi guys

Have a bit of mistery issue that has cropped up and I'm trying to assit to look into it, but want to seek advice as so far nothing has stuck out.

The setup is a Windows 7 clients, mixture of 32 and 64bit SP1. Domain controller is Windows 2008 R2 SP1.

Domain controller is hosted on a VPS, no local DC on site. There is a S2S vpn between the office to the VPS server with a good up/down link between the two.

PC's are joined to the domain and functioning, its only this 1 niggly thing that has cropped up now when a user changes the password via CTRL + ALT + DELETE and it takes over 2 minutes from hitting the arrow to submit the change to getting a confirmation to say the password was changed. If you hit CTRL + ALT + DELETE whilst the screen is stuck on "Changing Password" with the wheel spinning then you get the confirmation that the password was changed and password definitely gets updated.

Anybody have any ideas on why the password change has a delay if you leave it to complete by itself?

Link to comment
https://www.neowin.net/forum/topic/1090377-slow-password-change-on-domain/
Share on other sites

I would start by checking the following:

  • DNS: Can it resolve the domain and all domain controllers? Are the IP addresses correct?
  • Run a diagnostic check for active directory. I can't remember how exactly but dcdiag sounds right.
  • Check event viewer on the domain controller and clients for any clues on related errors.
  • What domain functional level is the forest and domain? May want to raise them to Server 2008 R2 if not already.
  • How is the latency and bandwidth between the DC and client site?

I would start by checking the following:

  • DNS: Can it resolve the domain and all domain controllers? Are the IP addresses correct?
  • Run a diagnostic check for active directory. I can't remember how exactly but dcdiag sounds right.
  • Check event viewer on the domain controller and clients for any clues on related errors.
  • What domain functional level is the forest and domain? May want to raise them to Server 2008 R2 if not already.
  • How is the latency and bandwidth between the DC and client site?

Thanks for the response.

Latency between DC and client is around the 10ms mark average.

PC's can resolve the domain and DNS is correct with the settings being picked up from the server.

No issues found with DCDiag and event logs on server and client are clean with no obvious errors to highlight the cause of the delay.

At the moment my suggestion has been to put a local DC onsite which can then replicate to the VPS DC.

We had similar problems in our remote office. about 200 pc.s there XP SP3 and Windows 7 32/64-bits.

First we tried Slowlink mode and that helped much, but final solution was that we added RODC, now everything works nicly there.

  • 5 months later...

Can I bump this for a revisit for your thoughts please

I'm basically still experiencing the same issues as what I've already highlighted in my previous posts and what this user has posted here -> http://social.technet.microsoft.com/Forums/en-US/itprovistanetworking/thread/06dce842-c6dc-4e1f-9f86-7fd7a0a55191

We have implemented a DC locally and there is a DC in a remote site linked via S2S, I've checked the PC logon server and it is the local server, not the remote server. But yet when I try and do a password change. IT JUST TAKES an age...

If there's a firewall between the computers and the DC, I would look at that... Typically dynamic RPC ports allocation. Try to restrict the ports used for RPC by the domain controllers and make sure the now fixed tcp port range is open on the firewall.

Have a look at these KBs

http://bensjibberjabber.wordpress.com/2011/07/26/configuring-domain-controllers-to-use-fixed-rpc-ports-behind-firewalls/

http://support.microsoft.com/kb/832017

http://support.microsoft.com/kb/154596

Something doesn't sound right withy the network setup. Could be active directory, could be Dns, could be replication..... Any event logs on the servers (system, application, security, Dns, replication).

Well AD replication tests out fine, No critical errors in my dcdiag and also dcdiag /test:dns and repadmin /showrepl * /errorsonly comes back clean. I can PM or post the outputs if it will help.

With regars to event logs, apart from some errors that may have been caused when I was changing some of the settings. There is nothing that stick out from the server end. Once again, I'm happy to get this posted if it will help. From the client (workstation) side, everything event wise is so clean, I wish something was erroring out.. :(

If there's a firewall between the computers and the DC, I would look at that... Typically dynamic RPC ports allocation. Try to restrict the ports used for RPC by the domain controllers and make sure the now fixed tcp port range is open on the firewall.

Have a look at these KBs

http://bensjibberjab...hind-firewalls/

http://support.microsoft.com/kb/832017

http://support.microsoft.com/kb/154596

Well the local DC and workstation are now all within the same network with obviously a firewall protecting that whole network. So don't think if the above will help, but will keep in mind.Windows firewall is disabled.

This topic is now closed to further replies.
  • Posts

    • The 2TB Samsung 990 PRO NVMe SSD hits lowest price in over three months by Sayan Sen Yesterday, we covered a really good deal wherein you can get a 4TB TeamGroup T-FORCE G50 NVMe PCIe Gen4 SSD for a low price of just $400 with a special discount coupon. That's just $100 per TB, making it a very good offer during these hard times. The deal is still live, so you can check it out in its dedicated article here if you do not want to miss out. Meanwhile, if you don't have that kind of budget but still wish to buy an SSD for a good price, the 2TB variant of the TeamGroup SSD at $280 its lowest price in over three months. Meanwhile, those seeking 2TB but faster performance can check out Samsung's 990 PRO, which has hit the lowest price also in the last quarter or so, as it's on sale for $370 (purchase links under the specs table down below). Thus, you want a faster drive, get the 990 Pro, or you want more capacity, grab the TeamGroup 4TB linked in the first para. The 990 PRO is a PCIe Gen4 NVMe SSD and still one of the fastest drives available today for under $500. Speaking of fast, sequential reads and writes are rated at 7450 MB/s and 6900 MB/s, respectively. The random throughputs for reads and writes are 1400K IOPS and 1550K IOPS, respectively. The 990 PRO is based on Samsung's 7th Gen V-NAND flash, and it too is TLC. It packs 2 gigs of LPDDR4 DRAM cache, which helps the random performance. The endurance rating for this is 1200 TBW (terabytes written), which should be sufficient for most users. The Samsung 990 PRO is compatible with the PlayStation 5, but if you are going to use the 990 PRO on a PC, check out the Samsung Magician app that lets you track your drive's health, update its firmware, customize various settings, and more. The tech specs are given below: Specification TeamGroup T-FORCE G50 2TB Samsung 990 PRO 2TB Interface PCIe 4.0 x4, NVMe 1.4 PCIe Gen 4.0 x4, NVMe 2.0 Form Factor M.2 2280 M.2 2280 Controller InnoGrit Controller Samsung In-house Controller NAND Flash 3D TLC 3D TLC DRAM Cache None (HMB supported) 2GB LPDDR4 Sequential Read (Max) 5,000 MB/s 7,450 MB/s Sequential Write (Max) 4,500 MB/s 6,900 MB/s Random Read (4K) Up to 600,000 IOPS Up to 1,400,000 IOPS Random Write (4K) Up to 700,000 IOPS Up to 1,550,000 IOPS TBW (Endurance) 1,300 TBW 1,200 TBW MTBF 3,000,000 hours 1,500,000 hours Operating Temperature 0°C to 70°C 0°C to 70°C Storage Temperature -40°C to 85°C -40°C to 85°C Shock Resistance 1,500G / 0.5ms 1,500G / 0.5ms Heatsink Patented Graphene Heat Spreader No Get them at the links below: Samsung 990 PRO SSD 2TB (MZ-V9P2T0B/AM): $369.99 (Sold and Shipped by Amazon US) TEAMGROUP T-Force G50 2TB SSD (TM8FFE002T0C129): $279.99 (Sold by TeamGroup, Shipped by Amazon US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • If you can't spell a simple word that 2nd graders learn, your entire argument is suspect.
    • And here goes the "Won't someone think of the children" brigade. Get stuffed mate. This has NOTHING to do with making the internet safe. It's about tracking adults, spying on your online activity, and sending the boys around when they don't like something you post. Also, again, parliament have voted TWICE against this, and Starmer is going ahead anyway. THAT is anti-democratic bullsh**. They will use this law to track you, they will use this law to control you, and they will use this law to punish you if they don't like what you do, even if it's legal. And your data? Say bye bye to that. It'll be on the darkweb in weeks. I'm not some rando online. I've been an IT professional for 40 years, many of it in security. I know exactly what this means and what will happen to your data. I do not consent and I will not comply.
    • "...but it may not be Microsoft's fault" seems like a reasonable way to tease what is going on without leaving the user with a false impression that an update is the problem. A title isn't a summery, it is meant to entice the user to read the article. It should not contain a misleading premise; which this title does not. You could maybe complain that the first paragraph should have included that detail. The writing style popularized over 100 years ago in newspapers will cover the most important information as soon as possible with details and nuance added later; the idea being that with each new paragraph you have less of the reader's focus.
    • Samsung Galaxy XR arrives in the UK with new AI and enterprise features by Fiza Ali Samsung is bringing its Galaxy XR headset to the UK several months after the device made its debut as the first headset built on Google's Android XR platform. The headset was first teased in late 2024 alongside Google's introduction of Android XR before making its commercial debut in 2025. Developed in collaboration with Google and Qualcomm, Galaxy XR combines mixed reality experiences with Gemini-powered AI features, allowing users to interact with digital content using voice, gestures, and visual inputs. While the hardware itself remains largely unchanged from the version Samsung unveiled last year, the company is using the UK launch to spotlight several software enhancements that have arrived through recent updates. Among the most notable additions is deeper integration with Google's ecosystem. Galaxy XR users can explore destinations through Google Maps' Immersive View, receiving AI-powered recommendations and contextual information from Gemini while navigating virtual environments. Furthermore, entertainment experiences have also expanded; users can watch 180-degree and 360-degree videos on YouTube, browse spatial content converted into 3D, and ask Gemini questions about on-screen content without interrupting playback. Samsung is also highlighting mixed-reality features such as Circle to Search, which allows users to identify real-world objects through hand gestures while using the headset's video pass-through mode. Another feature automatically converts photos and videos into spatial 3D experiences. Moreover, the headset now also supports Android Enterprise, allowing organisations to manage deployments using existing Android management tools. Annika Bizon, Vice President, Product and Marketing, Mobile Experience, Samsung UK & Ireland, talked about the device, stating: The headset is powered by Qualcomm's Snapdragon XR2+ Gen 2 platform and features dual 4K Micro-OLED displays. The tech giant says that users can expect up to 2.5 hours of battery life. Samsung also confirmed that Galaxy XR will continue receiving software and security updates as the company works alongside Google and Qualcomm to expand the Android XR ecosystem. Galaxy XR is now available for pre-order and will go on sale on 8 July. Customers interested in trying the headset before launch can visit Samsung KX in London and selected Samsung Experience Stores from 17 June. Finally, the company will also host a livestream on 19 June showcasing the headset's capabilities and answering questions from prospective customers.
  • Recent Achievements

    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
    • Week One Done
      Prasann earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      519
    2. 2
      +Edouard
      174
    3. 3
      PsYcHoKiLLa
      92
    4. 4
      Steven P.
      82
    5. 5
      ATLien_0
      70
  • Tell a friend

    Love Neowin? Tell a friend!