Re: Please help GPO's - MVP's

From: Herb Martin (news_at_LearnQuick.com)
Date: 10/16/04


Date: Sat, 16 Oct 2004 13:14:39 -0500


"davran" <davran@discussions.microsoft.com> wrote in message
news:1E2E9ED1-61EF-4479-BACB-35067A638264@microsoft.com...
> Network is Win2000 advanced servers.
>
> I have a domain with 12 servers. I configured the security section of
> default domain security policy but these setting are not showing on the
> member servers when I look at the local policy and look at the effective
> settings.

First it is generally a bad idea to modify the default domain
poilicy (at least inititally) but rather it is preferred to add an
additional policy so that you may distinguish your own changes
from the MS provided defaults -- and differentially disable them
if that ever becomes necessary.

> I have even configured local policies using 'security and configurayion
> analysis' and defined Password policies, account policies, user rights and
> assignments and security options..All these are fine and work except the
> security options which still show default settings.

Local policies for "Security Account Policies" (including Password)
are only going to affect Local Account logon (not domain accounts.

Domain "Security Account Policies" can only be effectively Linked
at the DOMAIN level but you seem to have done that by chaning the
Default Domain Policy.

> Anyone know why my configured security options are not showing.? Also

Several possibilities are obvious for your first checks:

    1) The GPO was edited didn't replicate to the other (authenticating) DCs
    2) The machines are not members of the domain
    3) The machines are members but not authenticating properly or failing
        to retrieve the GPO from the DC.
    4) It isn't really domain linked (e.g., using Def. DC policy by mistake)
    5) A later policy (on the domain in this case) is overriding
    6) Permission problems -- user/computer must have Read & Apply_Policy

#5 and #6 are unlikely to happen by accident but are included for
completeness. #1 and #3 are usually DNS problems. #2 is trivial
to check as is #4.

> I have configured the warning message on the default domain policy to
> display a warning message. This is displayed OK on the domain controllers
but
> do not display on the members servers...anyone know why..?

Perhaps you used the "Default Domain CONTROLLER policy" for
these?

Since it appears to be affecting the DCs but not the domain wide
machine and user logons...this seems a strong possibility and is
quick to (double) check.

You might also run DCDiag to confirm you DC/DNS setup and
ensure replication.

-- 
Herb Martin
> Please help
>


Relevant Pages

  • Fwd: Oh Dear, Where to start?!
    ... It seems to me you need two things: an organizational policy, ... finish college and break into the real world of computer security. ... experience in the field of network security and policy ... updates, driver updates, and recommended updates. ...
    (Security-Basics)
  • Re: Preventing users from c onnecting to shares NOT on the domain..
    ... First condition would be to set "Require Security" policy to "Restricted ... These computers could be excluded by IP address, ... > The servers might be located on the same subnet of some of the clients. ...
    (microsoft.public.win2000.networking)
  • Re: Preventing users from c onnecting to shares NOT on the domain..
    ... First condition would be to set "Require Security" policy to "Restricted ... These computers could be excluded by IP address, ... > The servers might be located on the same subnet of some of the clients. ...
    (microsoft.public.win2000.security)
  • RE: [fw-wiz] PIX vs Checkpoint vs Sonicwall vs Netscreen - comme nts?
    ... All NetScreen appliances rely on custom-designed ASICs (Application ... Specific Integrated Circuits) for security policy enforcement. ... supports a finite number of "rules" or "policies". ...
    (Firewall-Wizards)
  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
    (microsoft.public.windows.server.sbs)