Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1010 Source: MsGina

Failed to set the user's home directory (Drive <drive letter>: connected to Share \\<computer name>\<share name>).

0000: 55 00 00 00
We had a similar problem but found that the client was mapping the F: drive to their home folders which was available on their workstations but logging into the terminal server, the F: drive was already allocated to the CD-ROM drive.

Ensure that if you do folder redirection or profiles that the drive letter is not already taken by a physical disk or rom drive.
See EV100131 (MsGina event 1010 errors) for an article about this problem (and how it was fixed).

The data portion of the event contains the error code encountered during the attempt to map the drive. This can be an important clue as to what went wrong. For example, if the data contains 55 00 00 00, this corresponds to Error code 0x55 or Error code 85 (0x55 in hex is 85 decimal) and that means "The local device name is already in use". This error indicates that the drive letter that was attempted to be mapped was already in use.

Data: b3 04 00 00 - corresponds to Error code 0x4b3 or Error code 1203 in decimal meaning "No network provider accepted the given network path." - this may indicate that the path specified for the mapped drive is invalid.
I also had this issue and managed to resolve it. My environment consisted of a Terminal Server TS1, a Domain Controller and an Exchange/File Server SBS1. One user (out of several tens), after changing his password and logging in on the SBS1 server could not access any resources on SBS1, be that Exchange or files/folders. The user received an authentication question were no passwords were accepted. To fix the problem I opened the password applet from Control Panel -> User Accounts -> Stored User Names and Passwords and I removed the entry for SBS1.
An old ASP web admin application was used for user admin, which made use of the wts_Config.dll. When creating new users the TerminalServicesHomeDrive value was incorrectly set to T instead of T: . A script was created to query all AD user accounts and amend the value if incorrect. After this, we no longer receive this error.
This problem occured after installing Windows 2003 SP1 (terminal server). Users were not connected to their home drive (H:) and this event was logged. In the user profile, the home folder path pointed to a CNAME dns record instead of the real server. After changing this, the event was gone and the user could connect to its own H: drive during logon.

See the information for Error code 1203 (the decimal for 0x4b3).

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.