Event ID - 1109

Event Id1109
SourceMicrosoft-Windows-GroupPolicy
DescriptionThe user account is in a different forest than the computer account. The processing of Group Policy from another forest is not allowed. Group Policy will be processed using Loopback Replace mode. The scope of the user policy settings will be determined by the location of the computer object in Active Directory. The settings will be acquired from the User Configuration of these policies.
Event InformationAccording to Microsft :
Cause :
This event is logged when the user account is in a different forest than the computer account.
Resolution :
Enable cross-forest user Group Policy processing
1.Open the Group Policy Management Console (GPMC).
2.Create a new Group Policy object (GPO) or select an existing one.
3.Edit the GPO and enable the following policy setting:AllowCross-Forest User Policy and Roaming User Profiles (located in Administrative Templates\System\Group Policy).
4.Log off and restart the computer.
Verify :
Group Policy applies during computer startup and user logon. Afterward, Group Policy applies every 90 to 120 minutes. Events appearing in the event log may not reflect the most current state of Group Policy. Therefore, you should always refresh Group Policy to determine if Group Policy is working correctly.
To refresh Group Policy on a specific computer:
1.Open the Start menu. ClickAll Programs and then clickAccessories.
2.ClickCommand Prompt.
3.In the command prompt window, type gpupdate and then press ENTER.
4.When the gpupdate command completes, open the Event Viewer.
Reference LinksEvent ID 1109 from Source Microsoft-Windows-GroupPolicy

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.