#Requires -Version 5.1 <# JbTecWiz Support Centre -- read-only diagnostic Fault : Group Policy events 1058 and 1030 -- cannot read gpt.ini Source: https://jbtecwiz.com/support/srv-gpo-1058 This script CHANGES NOTHING. It runs only the inspection commands from the write-up -- the Get-, Test- and Resolve- calls that establish which cause is in play -- and prints what each returned. Anything that writes, deletes, starts or stops is excluded by construction, not by judgement. Read the output alongside the write-up, then pick the fix that matches. Each fix has its own script on the same page. -------------------------------------------------------------------- NO WARRANTY - USE AT YOUR OWN RISK This script is provided by JbTecWiz as-is and with no warranty of any kind, express or implied. You run it entirely at your own risk. JbTecWiz accepts no liability for any loss or damage arising from its use, including but not limited to data loss, downtime, or configuration changes that turn out to be wrong for your system. You are responsible for reading this script before running it, for satisfying yourself that it suits the machine in front of you, and for having a working backup first. Some steps cannot be undone. -------------------------------------------------------------------- #> [CmdletBinding()] param([switch]$Transcript) $ErrorActionPreference = 'Continue' if ($Transcript) { $log = Join-Path $env:USERPROFILE ("jbtecwiz-srv-gpo-1058-" + (Get-Date -Format yyyyMMdd-HHmmss) + ".txt") Start-Transcript -Path $log | Out-Null Write-Host (' Saving a transcript to ' + $log) } function Write-Rule { param([string]$Text) Write-Host '' Write-Host ('-' * 70) -ForegroundColor DarkGray if ($Text) { Write-Host $Text -ForegroundColor Cyan } } function Probe { param([string]$Label, [string]$Fix, [scriptblock]$Command) Write-Rule (" " + $Label) Write-Host (" from: " + $Fix) -ForegroundColor DarkGray Write-Host '' foreach ($l in ($Command.ToString().Trim() -split "`n")) { Write-Host (" " + $l.Trim()) -ForegroundColor DarkGreen } Write-Host '' try { $out = & $Command 2>&1 | Out-String if ([string]::IsNullOrWhiteSpace($out)) { Write-Host ' (returned nothing)' -ForegroundColor DarkGray } else { foreach ($l in ($out.TrimEnd() -split "`n")) { Write-Host (" " + $l.TrimEnd()) } } } catch { Write-Host (" could not run: " + $_.Exception.Message) -ForegroundColor Yellow } } Write-Rule Write-Host ' Group Policy events 1058 and 1030 -- cannot read gpt.ini' -ForegroundColor White Write-Host ' Read-only diagnostic -- nothing is changed.' -ForegroundColor Green Write-Rule Probe -Label 'Test both forms of the path from the client. The difference tells you whether it is DFS or the share.' -Fix 'Restore the SYSVOL path and its DFS namespace' -Command { Test-Path \\example.local\SYSVOL\example.local\Policies Test-Path \\DC01\SYSVOL\example.local\Policies } Probe -Label 'If they are missing, SYSVOL has not finished its initial replication -- check for the SYSVOL ready flag.' -Fix 'Restore the SYSVOL path and its DFS namespace' -Command { Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters' -Name SysvolReady } Probe -Label 'Confirm the machine''s secure channel to the domain is intact.' -Fix 'Fix authentication and SMB hardening on the SYSVOL path' -Command { Test-ComputerSecureChannel -Verbose } Probe -Label 'Repair it if broken.' -Fix 'Fix authentication and SMB hardening on the SYSVOL path' -Command { Test-ComputerSecureChannel -Repair -Credential (Get-Credential) } Probe -Label 'Confirm Authenticated Users still has Read on the policy objects -- a delegation change that removes it breaks every client at once.' -Fix 'Fix authentication and SMB hardening on the SYSVOL path' -Command { Get-GPO -All | ForEach-Object { $g=$_; Get-GPPermission -Guid $g.Id -All | Where-Object { $_.Trustee.Name -eq 'Authenticated Users' } | Select-Object @{n='GPO';e={$g.DisplayName}}, Permission } } Write-Rule Write-Host ' Diagnostic finished. Nothing was changed.' -ForegroundColor Green Write-Host '' Write-Host ' Compare the output above with the write-up, then run the' Write-Host ' script for the fix that matches:' Write-Host ' https://jbtecwiz.com/support/srv-gpo-1058' Write-Rule if ($Transcript) { Stop-Transcript | Out-Null }