JSI Tip 4555. Windows XP Autoenrollment cannot reach an Active Directory domain controller?

Jerold Schulman

December 16, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today


Event ID 15 is logged every 8 hours in the Application event log:

Event Type: Error Event Source: AutoEnrollment Event Category: None Event ID: 15 Date: dateTime: timeUser: N/A Computer: computer nameDescription: Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b).             The specified domain either does not exist or could not be contacted. Enrollment will not be performed.

If your Windows XP is a member of a Windows NT 4.0 domain, the is no Active Directory.

If Windows XP is joined to a Windows NT 4.0 domain:

1. Start / run / gpedit.msc / Enter.

2. Navigate to Computer Configuration / Windows Settings / Security Settings / Public Key Policies.

3. Double-click Autoenrollment Settings.

4. Select Do not enroll certificates automatically.

5. Press OK.

6. Close the Group Policy window.

If your Windows XP is a member of a Windows 2000 or later domain:

1. Control Panel / Network Connections / Local Area Connection / Properties.

2. Insure that the correct DNS address is entered into the Preferred DNS server box.

3. Press OK.



Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like