When you open an Active Directory Snap-in you receive:
-
-or-
-
-or-
When you open the Exchange System Manager, you receive:
These errors may occur if the Kerberos realm is NOT equal to the NetBIOS domain name.
To fix this problem:
1. Use the Regedt32 to navigate to HKEY_LOCAL_MACHINE\SECURITY.
2. Use the Security / Permissions menu to grant Full Control to Administrators.
3. Navigate to HKEY_LOCAL_MACHINE\SECURITY\Policy\PolAcDmN.
4. Select the <No Name> Value Name and press Display Binary Data on the View menu.
5. The ASCII text in the Binary Data is the Kerberos realm, which must be the same as the NetBIOS domain name. To check it, navigate to HKEY_LOCAL_MACHINE\SECURITY\Policy\PolPrDmN, select the <No Name> Value Name and press Display Binary Data on the View menu. Select the Byte option on the Binary Data dialog. The ASCII text is the NetBIOS domain name. If the Kerberos realm is equal to the NetBIOS domain name, exit this procedure.
6. Double-click the <No Name> Value Name at HKEY_LOCAL_MACHINE\SECURITY\Policy\PolPrDmN.
7. Press CTRL+C to copy the data from the Binary Editor to the clipboard.
8. Double-click the <No Name> Value Name at HKEY_LOCAL_MACHINE\SECURITY\Policy\PolAcDmN.
9. Press CTRL+V to paste the NetBIOS domain name from the clipboard to the Kerberos realm in the Binary Editor.
NOTE: After making the above change, repeat steps 3 through 5 to verify that the Kerberos realm and the NetBIOS domain name are equal.
NOTE: You must shutdown and restart your server for these changes to take effect.