Re: OU GPO Corrupts 2003 Servers only??



Thanks for the reply Andrew. That was quite different.

"andrewjtx" <ajohnson@xxxxxxxxxxxxxx> wrote in message
news:1144326446.700427.40670@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Roger, thanks for the reply.

I just resolved the issue last night.

The MS support rep from HP had pointed me in the direction of the
"Impersonate a client after Authentication" and "Create Global Objects"
property. I had set these in the GPO to Administrators only. I was
unaware that SERVICE was required to had this permission as well. I
tested it out on another OU, just setting these two to Administrators
and was able to recreate the problem. Then I repaired the test OU GPO
and rejoined the test server to the domain. Problem did not present
itself again.

This goes to show what screwing around with the security policy can do
for you. I'll be sure to read all of the details of each setting next
time I want to make a change...



.



Relevant Pages

  • Re: OU GPO Corrupts 2003 Servers only??
    ... The MS support rep from HP had pointed me in the direction of the ... I had set these in the GPO to Administrators only. ... and rejoined the test server to the domain. ...
    (microsoft.public.windows.group_policy)
  • Re: Local admin through group policy and keep admin on local machi
    ... "Support" and it is a member of administrators ... My current GPO for the OU is: ... If you then add the per machine domain account as/where ...
    (microsoft.public.windows.server.active_directory)
  • Re: Local admin through group policy and keep admin on local machi
    ... "Support" and it is a member of administrators ... My current GPO for the OU is: ... If you then add the per machine domain account as/where ...
    (microsoft.public.windows.server.active_directory)
  • Re: Local admin through group policy and keep admin on local machine?
    ... The way I am hearing this is that you need a custom support ... in GPO for the custom support group, ... define as a Restricted Group "Support" (yes, not Administrators ... If you then add the per machine domain account as/where ...
    (microsoft.public.windows.server.active_directory)
  • Re: Help needed setting up roaming administrator
    ... >Administrators group (just type in Administrators, don't browse for it, ... >add your Roaming Local Admins group to the Members of this group section ... GPO associated with the OU that contains the computers I want to use ... restricted group and to define the groups the restricted group will ...
    (microsoft.public.win2000.security)

Loading