Re: Default Domain Group Policy



"KJacks" <KJacks@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:EB21624F-2E0A-46DF-92BE-E8ED8E43B4E9@xxxxxxxxxxxxxxxx
> Windows 2000 domain
> When I go into Users and Groups and I go to the default domain group
> policy
> and try to open it up, I get error after error stating it has to
> concatnate
> items because of security. I think this happened because I promoted a
> Win2003
> server as a domain controller and then demoted, but I'm not positive about
> that.
> I was wanting to know if there is a way to delete the current default
> policy
> and put a clean one in its place, or if there is some other fix to this
> problem.
> Any help is appreciated.

DCFixGpo.exe will put Both of the default policies
(Domain and Domain Controller Defaults) back to the
original state.

I don't know if it will fix you current access. I would
run this from a Win2003 DC if the domain has been
upgraded but I don't have specific knowledge that this
is necessary.

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]


.



Relevant Pages

  • Re: Unable to access \domainSYSVOL but able to access \serverSYSVO
    ... Long before you fix this issue, you'll need to fix the other issue. ... The permissions are correct on the GPOs. ... When I attempt to edit any GPO, including the Default Domain Policy, I get ... Configuration information could not be read from the domain controller, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Add a domain user group to local computer administrator group
    ... To add users easily create a domain group and add it to RG. ... So you would add to a policy under the appropriate OU a separate GPO with RG ... The excellent thing here is it will keep local admins from adding anything ... >>> I used a script like the one you gaves, but the script didn't work on ...
    (microsoft.public.windows.server.scripting)
  • Re: Group policy snap-in
    ... group policy editor works!! ... still sending the report though. ... >> suggested fix and this may actually be a bug. ... was to roll back a couple of weeks using the XP ...
    (microsoft.public.windowsxp.security_admin)
  • Re: SElinux
    ... similar denials requires quite a bit of knowledge and analysis. ... I've seen references to audit2allow that make me think this tool should help identify what needs to be changed to fix any particular denial. ... only to see my work invalidated when a policy update ... how to stop SELinux blocks from happening. ...
    (Fedora)
  • Re: PKI - Issue Publishing to AD DS
    ... These surfaced when trying to publish my root ... and policy CA certs into my AD. ... Brian's fix, is to run the following command: ... the currently issued cert, and then go through my setup on my policy box ...
    (microsoft.public.security)