How to fix problem in the “DCOM: Machine Access Restrictions” and “DCOM: Machine Launch Restrictions”.
If you see pool of errors with DCOM 10024 in System log then proceed with followng steps to fix this:
Log Name: System Source: Microsoft-Windows-DistributedCOM Event ID: 10024 Task Category: None Level: Error Keywords: Classic Description: The machine wide group policy Launch and Activation Limits security descriptor is invalid. The security descriptor is defined as an invalid Security Descriptor Definitions Language (SDDL) string. The requested action was therefore not performed. Please contact your administrator to get the security descriptor corrected in the Group Policy settings. The machine wide group policy Access Limits security descriptor is invalid. The security descriptor is defined as an invalid Security Descriptor Definitions Language (SDDL) string. The requested action was therefore not performed. Please contact your administrator to get the security descriptor corrected in the Group Policy settings.
- Check the Security policy if DCOM: Machine Access Restriction/Machine Launch Restriction are configured as “Not Defined”
- Then open regedit and navigate to:
- Problem should be fixed! No more errors in system log with invalid SDDL DCOM permissions. No reboot is required.