Re: Managing Group Policy on XP SP2

From: d mac (dmac_at_discussions.microsoft.com)
Date: 09/23/04


Date: Thu, 23 Sep 2004 16:13:03 -0700

Hi there,

I downloaded the 842933 patch before opening the GPO on the XP SP2
workstation, so I haven't had any of the "The following entry in the
[strings] section is too long and has been truncated" errors. But I still
have the issue where not all the policies are showing up on the Windows 2000
Server vs. the XP SP2 workstation. Is this a known issue?

I will try Hunter's suggestion on manually importing the ADM files on the
Windows 2000 server to see if that updates all the policies on the domain
controllers to match the same amount showing on the XP SP2 workstation.

I'll let you know how it goes.

Thanks

d mac

"Bruce Sanderson" wrote:

> http://support.microsoft.com/?kbid=842933 documents this problem and has a
> patch available.
>
> --
> Bruce Sanderson MVP
>
> It's perfectly useless to know the right answer to the wrong question.
>
>
> "Hunter" <anonymous@discussions.microsoft.com> wrote in message
> news:1b9601c4a1a0$6a628fa0$a401280a@phx.gbl...
> > You might try gathering up the XP .adm templates, copying
> > them to temp folder on the 2000 DC. Then opening the A/D
> > Group policy on the 2000 box right click on the
> > Admisitrative templates container, choose add snap-in.
> >
> > It'll show the ones currently in use in the wnnt/inf
> > folder, Browse over to the new ones in the temp folder
> > and select add, it should ask you about overwriting etc.
> >
> > Choose yes.
> >
> > Once the new ones are copied in you will probably get a
> > bunch messages stating the new ones are too long or
> > something, but you'll have to hunt down an update for this
> > I think I found it at microsoft tech experts page on XP,
> > but it didn't seem to want to be found with search.
> >
> > Anyways, maybe that will help.
> >
> > Regards
> >
> > Hunter
> >
> >
> >
> >>-----Original Message-----
> >>I updated our GPO on our Windows 2000 domain controllers
> > with the latest ADM
> >>files from XP SP2. I did this by opening up the GPO on a
> > Windows XP Pro
> >>workstation with SP2 and it automatically replicated the
> > ADM files to our
> >>domain controllers. See document at
> >>http://www.microsoft.com/technet/prodtechnol/winxppro/main
> > tain/mangxpsp2/mngdepgp.mspx
> >>
> >>However, it seems like not all of the ADM files are
> > replicating to the
> >>Windows 2000 servers. For example, in the policy
> > path "Administrative
> >>Templates\Network\Network Connections\Windows
> > Firewall\Domain Profile" there
> >>are only 12 policies listed on the Windows 2000 Server
> > but on the XP SP2 box,
> >>there are 14 policies. The two that are missing are:
> >>
> >>Windows Firewall: Define program exceptions
> >>Windows Firewall: Define port exceptions
> >>
> >>Is this by design or is there something wrong with the
> > replication process?
> >>It would be nice to be able to define program exceptions
> > because there are a
> >>couple programs within our environment that won't work
> > unless we can exclude
> >>them. It would be preferable to do this through GP
> > instead of manually going
> >>to each machine and defining the program exceptions.
> >>
> >>Thanks,
> >>
> >>d mac
> >>.
> >>
>
>
>



Relevant Pages

  • RE: MSBLASTER Infecting despite 03-026 patch?
    ... I have been using the Retina DCOM scanner and it is ... but I found a workstation that had the ... > IIS vulnerabilities ... > scanning for the patch ...
    (Incidents)
  • RE: MSBLASTER Infecting despite 03-026 patch?
    ... http://eEye.com/SecureIIS - Stop known and unknown IIS vulnerabilities ... | Subject: RE: MSBLASTER Infecting despite 03-026 patch? ... but I found a workstation that had the ...
    (Incidents)
  • Re: HP & Windows XP S2; patch to ensure System Restore (SP26352.ex
    ... it's their shared responsibility to properly administer this patch - and she ... imperative to back-up all files prior to downloading and installing SP2. ... So, basically, you can wait a few weeks for all these SP2 problems to sort ... It would not install on ...
    (microsoft.public.windowsxp.general)
  • Re: Need to COMPLETELY disable Windows firewall
    ... patch for a patch for a patch. ... It is a widely known fact among Netware admins that Micro$oft has always ... better job of it with XP and especially with SP2. ... Yet another is that in Netware Services, Netware Server I only see servers I am attached to instead of all NW servers on ...
    (microsoft.public.windowsxp.general)
  • Re: POLL: SP2 - My Music issue; Respond only if you have experienc
    ... It does looks like the HP registry patch works fine for the HP (and some ... so I think you are probably safe by first applying the ... In the vast majority of cases where SP2 caused ...
    (microsoft.public.windows.mediacenter)