Event Id | 1109 |
Source | Microsoft-Windows-GroupPolicy |
Description | The user account is in a different forest than the computer account. The processing of Group Policy from another forest is not allowed. Group Policy will be processed using Loopback Replace mode. The scope of the user policy settings will be determined by the location of the computer object in Active Directory. The settings will be acquired from the User Configuration of these policies. |
Event Information | According to Microsft : Cause : This event is logged when the user account is in a different forest than the computer account. Resolution : Enable cross-forest user Group Policy processing 1.Open the Group Policy Management Console (GPMC). 2.Create a new Group Policy object (GPO) or select an existing one. 3.Edit the GPO and enable the following policy setting:AllowCross-Forest User Policy and Roaming User Profiles (located in Administrative Templates\System\Group Policy). 4.Log off and restart the computer. Verify : Group Policy applies during computer startup and user logon. Afterward, Group Policy applies every 90 to 120 minutes. Events appearing in the event log may not reflect the most current state of Group Policy. Therefore, you should always refresh Group Policy to determine if Group Policy is working correctly. To refresh Group Policy on a specific computer: 1.Open the Start menu. ClickAll Programs and then clickAccessories. 2.ClickCommand Prompt. 3.In the command prompt window, type gpupdate and then press ENTER. 4.When the gpupdate command completes, open the Event Viewer. |
Reference Links | Event ID 1109 from Source Microsoft-Windows-GroupPolicy |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.