Re: Please Help! Windows 2000 GPO Local Mess



"=?Utf-8?B?b2ZhbmdlZDE=?=" <ofanged1@xxxxxxxxxxxxxxxxxxxxxxxxx> said

> I have recently taken on a client whom said they have small problems. I
> have come to find out, by connfession, the mistake made was in the Group
> Policy editor the default local computer policy has been set to
> "Restrict users to the explicitly permitted list of snap-ins" and no
> snap-ins have been defined,

What do you mean by 'default local computer policy'? Is this a local policy
or an AD group policy?
If it's only a local policy just add another computer to the domain and
connect to the affected workstation from there and change it back.

> hence locking all snap-ins including
> gpedit.msc. Sytem manager and active directory and adsiedit have also
> been locked. I am wondering if anyone knows a way to reset all gpo's to
> the default other than with an in-place upgrade or reinstall. I cannot
> use the method to do this through the registry editor since I am locked
> out of this console as well. Inside the sysvol I have found only a
> limited number of settings I can reset dealing with password wolicy and
> kerberos, but nothing from the administrative templates.
>
> I have realized this company not only has a misconfiguration on the dc
> but the domain name is also not anything near proper (ie.
> "company1.company2"). There is also another server possibly a previous
> one running as a dc in its own domain ("company2.salescenter"). It has
> users in active directory and I have all access to its consoles. could I
> possibly push local policy from this second dc to the first one even
> though they are in different domains? Or am i stuck with a reload and
> disaster recovery after calling microsoft for too much money?
>
> Any help will be much apriciated
>

If it's an AD group policy problem try RecreateDefPol.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=b5b685ae-b7dd-
4bb5-ab2a-976d6873129d&DisplayLang=en

or

http://tinyurl.com/3yyr3

"Overview
RecreateDefPol.exe is a tool developed for the restoration of the Default
Domain and Default Domain Controllers policy files, in case of accidental
deletion. This tool is for use exclusively on Windows 2000 Server, Advanced
Server, and DataCenter Server. Do not use this tool on Windows Server 2003;
use Dcgpofix.exe instead (included in Windows Server 2003).

This tool is intended for use only in disaster recovery situations, where
either the Default Domain Policy, the Default Domain Controllers Policy, or
both have been damaged or deleted, and no other backup is available. This
should be considered a tool of last resort. "

--

Andy.
.



Relevant Pages

  • Re: How to allow users to create groups and shares
    ... Add the user/group to the Computer configuration, windows settings, security settings, Local policies, "Allow logon locally" in the Default domain controllers policy and on a existing or new created policy for the member servers. ... Filtering: Not Applied ... check with GPMC on the server or from a client the policy settings. ...
    (microsoft.public.windows.server.active_directory)
  • Domain Controller Security Policy errors
    ... Security Policy or the Domain Controller Security Policy. ... The DC is also a print and file server. ... The domain controller for Group Policy operations is not available. ...
    (microsoft.public.win2000.active_directory)
  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
    (microsoft.public.windows.server.sbs)
  • Re: Security Logon/Logoff Events
    ... I haven't yet set password policy or configured account lockout policy so I ... will do that in due course to fully secure the server. ...
    (microsoft.public.windows.server.sbs)
  • Re: Move W2K3 server to its own OU seperate from SBS (MyBusiness) OU
    ... OU and move the member server to so that it does not inherit it's GPO from ... policies from inheriting the default domain policies of the SBS ... section of the default domain policy. ... In direct answer to your question, you would need to filter this ...
    (microsoft.public.windows.server.sbs)