Firewall Service does not function after joining to a domain
Weare testing acouple workstations running Windows Vista RC1 and after joining the PC to our domain and logging in as the domain Administrator, we cannot start or restart the Windows Firewall service. After reinstalling Vistathe first time, we joined the PC to the domain and logged in as a standard user in our IT group and could use the firewall, but once we logged in as domain Administrator, we started getting the message "Windows cannot start the Windows Firewall service.
September 26th, 2006 12:35am

Got the same problem, after joining domain. when trying to start the service manually we get Error 1297: A privilege that the service requires to function properly does not exist in the service account configuration....... What does this mean? any suggestions ?
Free Windows Admin Tool Kit Click here and download it now
October 24th, 2006 4:06pm

I a using rc2 and have nothad this issue. are there any group policies on the domain controler for firewalls
November 3rd, 2006 11:11pm

I have the exact same problem. After joining the domain, i can nolonger start the windows firewall. How can i disable the group policy?
Free Windows Admin Tool Kit Click here and download it now
December 23rd, 2006 9:43am

Is there firewall policies on the GPO on the domain., are you an admin or a user ? check this link for info on group policies http://forums.microsoft.com/TechNet/ShowPost.aspx?PostID=1000379&SiteID=17
December 23rd, 2006 11:09pm

I, too, have this issue. Vista, after joined to a domain, refuses to start the firewall service and gives me the same errors as above. I've disabled our domain policy and rebooted multiple times, as well as run gpupdate on the Vista workstation. Gpedit.msc shows all firewall policies as being "Not configured". I have disconnected the affected Vista machine from the domain and made sure the Domain Profile for "Prohibit use of" setting is "Not configured".We are testing Vista for our domain and absolutely need to remote desktop access to Vista, but can't because of the firewall not working. Moreover, we absolutely do not want a firewall in Vista at all on our domain.
Free Windows Admin Tool Kit Click here and download it now
December 29th, 2006 1:38am

What version of Vista are you running? My firewall service is started.
January 2nd, 2007 8:08pm

W are using Vista RC1... the firewall runs but after joining to our domain it doesn't anymore. Maybe there is something conflicting in group policy.
Free Windows Admin Tool Kit Click here and download it now
January 2nd, 2007 8:30pm

Interestingly enough I am having this same problem with the Telephony service after joining my machine to the domain today. I am using the RTM release so if this is a problem it is a problem in the final release. I joined the domain however I am not part of an OU or any GPO's other than the default domain policy which I'm checking into now. Cheers.
January 3rd, 2007 4:42am

Ok after some more investigation it turns out that it is indeed the default domain policy affecting the services login accounts or DCOM possibly. I'm not sure yet which policy it is yet. What I did was create a OU with Policy Inheritence disabled. I removed my machine from the domain and moved the computer account to the new OU.Iran a gpupdate /force to re-enable the local default GPO and rebooted. Then re-attached to the domain and functionality has remained. Cheers, Kevin
Free Windows Admin Tool Kit Click here and download it now
January 3rd, 2007 6:54am

Kevin, Have you figured out what GP it was? What is an OU? I am having these issues also and cannot find an answer.
January 17th, 2007 7:13pm

I had this same problem and found it was a problem with the user rights for the local service account. Make sure the group policy has both LOCAL SERVICE and NETWORK SERVICE listed for the Adjust Memory Quotas for a Process right. I had to reboot my Vista PC after pulling the new policy but all services started. Hope this helps...
Free Windows Admin Tool Kit Click here and download it now
January 25th, 2007 9:40pm

gergy9 wrote:Kevin, Have you figured out what GP it was? What is an OU? I am having these issues also and cannot find an answer. Quick 30'000 ft view: GP = Group Policy - "templates" to centrally configure and administer resources in the domain (security, desktop settings, etc.)OU = Organization Unit- used to group similar resources together to simplify administration There are all terms related to Active Directory (AD). Windows Vista, like Windows XP, are workstation clients (desktop or laptop) that can be joined to an AD domain and managed using some of these technologies / techniques. Hope this helps. Please let us know. Thanks!
January 26th, 2007 12:34am

Jason340 wrote:I had this same problem and found it was a problem with the user rights for the local service account. Make sure the group policy has both LOCAL SERVICE and NETWORK SERVICE listed for the Adjust Memory Quotas for a Process right. I had to reboot my Vista PC after pulling the new policy but all services started. Hope this helps...I completed these steps, updated the GP, rebooted the local PC twice and still cannot start the firewall service due to the service missing some privilege.
Free Windows Admin Tool Kit Click here and download it now
February 7th, 2007 5:17pm

I have this same problem but am using Vista Business. No Beta. I was wondering if this was ever figured out to the point that the GP was actually identified and the problem was resolved. I have tried the steps of no inheritance and that worked but as soon as I rejoinn the domain it goes back to the same problem. Any Help?
February 7th, 2007 10:26pm

No, I never figured out the GP's. I did however find a work around. After imaging the machine immediately turn off the firewall. Then go into firewall with advanced security and turn off the other 2. Now join it to the domain. Windows firewall will still no longer work but atleast you can use the pc on the network with no problems. We use Bit Defender with a local firewall anyway so i could care less if windows firewall works or not. Stupid way of doing things though. Hope this helps.
Free Windows Admin Tool Kit Click here and download it now
February 8th, 2007 12:48am

When I was having this problem, I narrowed it down to a right missing in group policy. Before I joined the PC to the domain (and the firewall servcie worked) I wrote down all rights that Network Service and Local Service had on the PC by looking at the local group policy. Then I joined the PC to the domain, let the domain policy apply and then compared what was applied to the pre domian policy I wrote down. Doing this I was able to narrow it down to two policies on the domain that I had to add the Local Service and Network service to (It may be different for you depending on the domain policy). Remember to add the rights at the appropriate place in the domain policy and not the local policy. A quick gpupdate and reboot and it should work....Hope this helps further...
February 8th, 2007 6:52pm

What policies where yours. I added those to users to the Adjust Memory quotas for a process but cant figure out where else to add those users.
Free Windows Admin Tool Kit Click here and download it now
February 9th, 2007 10:52pm

here this should help http://www.microsoft.com/technet/community/columns/cableguy/cg0106.mspx and http://www.windowsdevcenter.com/pub/a/windows/2006/03/07/group-policy-in-windows-vista.html
February 13th, 2007 12:21am

I added LOCAL SERVICE to 'Adjust memory quotas for a process' AND 'Allow log on locally' - that did the trick for me.
Free Windows Admin Tool Kit Click here and download it now
February 13th, 2007 11:05pm

I had to add Local Service and Network Service to "Replace a process level token" to get mine to work.
February 15th, 2007 4:52am

Neither of those links are of any use, because you cant change firewall settings if the darn thing will not start.I added LOCAL and NETWORK SERVICEervice to both "Adjust memory quotas" and "Replace a process level token" and "Allow log on locally". Successfully ran gpupdate on the server, then rebooted the workstation. Confirmed on the workstations the permissions propagated, and still cannot get the firewall service to start. This is particularly annoying because the "Diagnostic Policy Service" also fails to start with the same error.Is there somewhere i can go to lookup what specific rights Windows Firewall service needs in Vista to end all this guessing?
Free Windows Admin Tool Kit Click here and download it now
February 26th, 2007 10:46pm

This problem has affect one more services.I'am using Vistasince Beta2 and sice that Betathe WMDC doesn't reconice my smartphone/PDA afterjoining a domain. Now, the telephony services won't start (after joining the domain) because its missing a qualification that is needed to work propperly(error 1297).Remote access auto connectiom manager and remote acces connection manager are depending on this services. So, they won't start either.Al this is working under the network services account. I cannot imagen that this problem is not well known by the engineers of microsoft.
March 1st, 2007 11:56am

Alright, the workarround from Kevin aka Spd_Demon worked for me. "What I did was create a OU with Policy Inheritence disabled. I removed my machine from the domain and moved the computer account to the new OU. I ran a gpupdate /force to re-enable the local default GPO and rebooted. Then re-attached to the domain and functionality has remained." Only the part of re-enable and re-attached to the domain was not necessery for me.It's obvious that there must be some adjusting to the domain policy. I read that there are security templates for Vista (and longhorn) but normaly extends those templates the defaults possibility's. (i thought ) Grtz. Hans P.s. I'am ashamed RTFM http://www.microsoft.com/downloads/details.aspx?FamilyID=a3d1bbed-7f35-4e72-bfb5-b84a526c1565&DisplayLang=en
Free Windows Admin Tool Kit Click here and download it now
March 1st, 2007 5:17pm

I ran the install again to get mine working. Kind of drastic but frustration set in! Matt.
March 12th, 2007 1:09pm

Hi finally got this to work with the below. The problem started when I installed Vista Ultimate as an upgrade from an OEM disk from Windows XP on our domain. Not only did the firewall break but so did other services such as Remote Access Connection ManagerError:7000Service Control ManagerError:7000These stopped the Telephony Service from launching which seemed to have a knock on effect on the dependencies, I managed to get allof these services working and then finally the firewall service started by following the below. I opened our domain group policy (If you don't know how, I added below) and added Added "Local Service" & "Network Service" to these User rights assignments...Act As part of the operating systemAdjust memory Quotas for a processAllow Log On LocallyLog on as a serviceReplace a process level token(If you are using AD on 2000 Serverthen some of the names vary, they are similar and work the same) On your vista pc open a command prompt and run gpupdate /forceThis will update your group policy locally, re-boot and see if the services have started, if not as mine didn't, from run type secpol.msc and see if the user rights under local policies are in there, you can also see the icons are different shades for policies that have come over from the group policy which helps you to see which ones might have changed or may need changing.Now open services run-> services.msc and open windows firewall service and put in "Local Service" no password and close and try starting it.If it still fails you need to check through the policies again and see if Local Service is in the ones that came over from the Group Policies. Mine finally started after I hadre-booted with the firewall service set to manual and then I entered "Local Service" and started it successfully, I have no idea why it didn't start on Automatic, but now it does itfine. How to open your Domain Group Policy.On your Domain Controller, start->Run-> type mmc and hit enterConsole Add/Remove SnapinClick AddFind group policy and selectBrowse for your domain policy and choose it (If its not there then you don't have one)OK & FinishExpand -> Computer Configuration->Windows Settings->Security Settings->Local Policies->User Rights Assignment.Make the adjustments to the rights as above.
Free Windows Admin Tool Kit Click here and download it now
March 13th, 2007 2:04pm

Thanks for pointing me in the right direction. Iexperienced this problem with the Windows Firewall after joining Vista Business to a Windows 2000 Domain. In 2000, the user right 'Adjust memory quotas for a process' is simply called 'Increase quotas'
March 14th, 2007 4:42pm

Thanks WayneITDude!"gpupdate /force" did not work for me even with a reboot and retrying it multiple ways.After leaving the domain and re-joining did the firewall service start without errors.P.S. If you do not set a password for local admin, the account is disabled by default (unlike XP).P.S.S. If you leave a domain, make sure you have a enabled local account or you will not be able to log in, except in safe mode.
Free Windows Admin Tool Kit Click here and download it now
March 20th, 2007 5:26pm

look for domainpolicy...etc..Firewall policy for windows XP SP2PCmake error in ViSTA PC
April 10th, 2007 3:11pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics