Re: Trying to configure group policies on a stand alone server.

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



In news:1179109518.871016.44580@xxxxxxxxxxxxxxxxxxxxxxxxxxxx,
ttysnoop@xxxxxxxxx <ttysnoop@xxxxxxxxx> typed:
I'm trying to run a service as a user account on a stand-alone Win2k
server. When I try to run the service using 'net start srvname' i get:

"System error 5 has occurred.

Access is denied."

I quick google lead me to this KB article that i'm 90% sure is my
current problem: http://support.microsoft.com/?kbid=256299

It's resolution involves using 'Active Directory Users and Computers'
to reconfigure the permissions for the user and/or its group. When I
try to run dsa.msc I get an error message, 'To manage users and groups
on this computer, use local users and groups. To manage users, groups
and computers in a domain, log on as a user with Domain Administration
rights.'

'Local Users and Groups' doesn't seem to have any advanced permissions
tabs or ability to do much except add/remove users and change their
groups.

So my question is how do i edit group/user policies and add 'service
read' privileges to a user/group on a server without a domain
controller?

Thanks for any info, It's probably a simple answer involving a non-
default tool but I couldn't find anything on google.
-Zim


It really doesn't work that way with stand alone machines. However you can
get into the machine's local GP by typing 'gpedit.msc' and apply local
policy settings to local users only on a stand alone machine. The local
security policy can be accessed by going to Start, Administrative Tools,
Local Security Policy.

What type of settings were you looking for or expecting in a local user
properties compared to a domain user properties?


--
Regards,
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Directory Services
Microsoft Certified Trainer

Infinite Diversities in Infinite Combinations

Having difficulty reading or finding responses to your post?
Instead of the website you're using, try using OEx (Outlook Express
or any other newsreader), and configure a news account, pointing to
news.microsoft.com. Anonymous access. It's free - no username or password
required nor do you need a Newsgroup Usenet account with your ISP. It
connects directly to the Microsoft Public Newsgroups. OEx allows you
o easily find, track threads, cross-post, sort by date, poster's name,
watched threads or subject. It's easy:

How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164

"Quitting smoking is easy. I've done it a thousand times." - Mark Twain


.



Relevant Pages

  • RE: Backup local users
    ... I understand that you want to reinstall Win2k3 server and now your concerns ... are how to backup all local users and directory permissions. ... Microsoft Online Partner Support ...
    (microsoft.public.windows.server.migration)
  • Re: Fetchmail + Sendmail + Dovecot
    ... Are you suggesting me to replace, Sendmail with another MTA which has a good ... We already have remote server with domain name and mail setup, ... Local users can also check their mails through squid and web mail ... The default Dovecot configuration should work just fine. ...
    (Fedora)
  • Re: Creating users
    ... > created in the local Users group. ... Permissions to individual shares are ... without having to grant them access to everything. ... Administrator admin permissions to a server is normally very unwise. ...
    (microsoft.public.win2000.general)
  • Re: Migrate local users and groups to a domain saving his SID
    ... It´s a member server of a NT4 domain. ... I need only to migrate the local users and groups of this server to the ... I need to migrate all the files to a new cluster-fileserver 2003 ...
    (microsoft.public.windows.server.active_directory)
  • Re: Fetchmail + Sendmail + Dovecot
    ... We already have remote server with domain name and mail setup, where we have our website. ... Where as, for few local users I would like to download the mails to these users (at the same time few other users will be able to access their mails directly from the remote server, as they are roaming). ...
    (Fedora)