On my SBS2003 install, I'm logged on as the Administrator, on the server
itself. I have recently added a new member server (Windows 2003) to act as a
second file server and also be an additional controller in the AD. The
server is based in a small office some 20 miles away.

Every time I open up the properties sheet for the new server, and tick the
"Trust computer for delegation", I get the following error message
"Your security settings do not allow you to speicfy whether or not this
account is to be trusted for delegation".
In addition, Event 577 is logged inthe security log (entry listed below)

I've googles on this quite a bit, and as far as I can tell...
a) I am a member of the domain admin group and the schema admin group
b) I've created a GPO for the default domain policy, and under "computer
configuration", "Windows settings", "Security settings", "Local Policies" and
then "User Rights Assignement", I have explicity added in "Administrators" to
the "Enable computer and user accounts to be trusted" and also the server's
machine name (PS-SVR$).
Server has been rebooted recently.

I don't know why it didn't work first time, my other SBS2003 network has a
member server acting as a second AD controller, and it works just fine. Can
anyone suggest anything that I can do? Otherwise it looks like a reinstall
of the SBS server.

Thanks,

Adrian





Event Type: Failure Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 577
Date: 14/12/2004
Time: 16:46:46
User: JOHN-LEWIS\Administrator
Computer: JL-SVR
Description:
Privileged Service Called:
Server: Security Account Manager
Service: Security Account Manager
Primary User Name: JL-SVR$
Primary Domain: JOHN-LEWIS
Primary Logon ID: (0x0,0x3E7)
Client User Name: Administrator
Client Domain: JOHN-LEWIS
Client Logon ID: (0x0,0x5511918)
Privileges: SeEnableDelegationPrivilege

Re: Can't set the "trust for delegation" flag by Jim

Jim
Tue Dec 14 18:34:48 CST 2004

Does this link provide any clues?
http://www.eventid.net/display.asp?eventid=577

"Adrian Procter" <AdrianProcter@discussions.microsoft.com> wrote:

>On my SBS2003 install, I'm logged on as the Administrator, on the server
>itself. I have recently added a new member server (Windows 2003) to act as a
>second file server and also be an additional controller in the AD. The
>server is based in a small office some 20 miles away.
>
>Every time I open up the properties sheet for the new server, and tick the
>"Trust computer for delegation", I get the following error message
>"Your security settings do not allow you to speicfy whether or not this
>account is to be trusted for delegation".
>In addition, Event 577 is logged inthe security log (entry listed below)
>
>I've googles on this quite a bit, and as far as I can tell...
>a) I am a member of the domain admin group and the schema admin group
>b) I've created a GPO for the default domain policy, and under "computer
>configuration", "Windows settings", "Security settings", "Local Policies" and
>then "User Rights Assignement", I have explicity added in "Administrators" to
>the "Enable computer and user accounts to be trusted" and also the server's
>machine name (PS-SVR$).
>Server has been rebooted recently.
>
>I don't know why it didn't work first time, my other SBS2003 network has a
>member server acting as a second AD controller, and it works just fine. Can
>anyone suggest anything that I can do? Otherwise it looks like a reinstall
>of the SBS server.
>
>Thanks,
>
>Adrian
>
>
>
>
>
>Event Type: Failure Audit
>Event Source: Security
>Event Category: Privilege Use
>Event ID: 577
>Date: 14/12/2004
>Time: 16:46:46
>User: JOHN-LEWIS\Administrator
>Computer: JL-SVR
>Description:
>Privileged Service Called:
> Server: Security Account Manager
> Service: Security Account Manager
> Primary User Name: JL-SVR$
> Primary Domain: JOHN-LEWIS
> Primary Logon ID: (0x0,0x3E7)
> Client User Name: Administrator
> Client Domain: JOHN-LEWIS
> Client Logon ID: (0x0,0x5511918)
> Privileges: SeEnableDelegationPrivilege

Jim B. SBS Community Member
remove the mvp to send email