Re: GPO w/ Security Filter creates WMI disaster

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Problem #1 is as expected. Security policy does not undo itself because it
does not keep track of what its state was before, obviously you could have
any local group membership in place before you applied restricted groups so
it doesn't keep track of that. You have to explicitly change the group
membership, either with another policy or a script, to "undo" the policy.

Problem #2 sounds weird. Did you do anything else in that GPO other than the
aforementioned restricted group policy? It almost sounds like a combination
of things. For example, Windows Firewall being enabled with no exceptions
would result in remote RSOP or remote desktop not working and WMI not being
remotely accessible, but that is not related to restricted groups.

Darren

--
Darren Mar-Elia
MS-MVP-Windows Server--Group Policy
Check out http://www.gpoguy.com -- The Windows Group Policy Information Hub:
FAQs, Whitepapers and Utilities for all things Group Policy-related
And, the Windows Group Policy Guide is out from Microsoft Press!!! Check it
out at http://www.microsoft.com/mspress/books/8763.asp
GPOGUY Blog: http://blogs.dirteam.com/blogs/gpoguy



"KH" <KH@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:A0603A28-B4FA-4859-B6CA-1044E6C4B2B2@xxxxxxxxxxxxxxxx
( FYI : This is a new AD domain setup w/ an equally new SMS 2003
deployment )

I created a simple GPO that only does one thing - performs a "Member of"
Group Restriction to add domain group "Temp Local Admins" to the local
Administrator group.

I filter this GPO based on Computer name and used a couple of workstations
in a lab OU. If there is a better way to apply a GPO to a subset of
computers based on their NetBIOS name, I'll do it. Using the security
filter
in the GPMC seemed the most straight forward method, but it's really
created
a big mess.

Problem 1 :

GPO works properly when assigned and the filter works initially, but when
I
change the Security Filter, say to take out one of the two lab PC's to
verify
the setting doesn't stick, the setting still sticks to the system no
longer
in the security filter list. The change is still there after verifying w/
gpresult that the GPO should filter out.

Problem 2 :

The following errors appeared on every PC the GPO was applied to. Systems
in the lab OU that never met the filter criteria do not have any of these
errors. Along w/ these error messages, GPO's were not applied, I couldn't
view my XP firewall settings, and I couldn't Remote Desktop into either
PC.

Windows couldn't log the RSoP (Resultant Set of Policies) session status.
An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

**

Windows cannot perform filter check for Group Policy object cn=

**

WinMgmt could not initialize the core parts. This could be due to a badly
installed version of WinMgmt, WinMgmt repository upgrade failure,
insufficient disk space or insufficient memory.

( tried JSI #7751 to fix this, but no good )

**

Windows cannot display the properties of this connections. The Windows
Management Instrumentation (WMI) information might be corrupted. To
correct this, use System Restore to restore Windows to an earlier time
(called a restore point). System Restore is located in the System
Tools folder in Accessories.

**

When viewing network properties, receive "WMI might be corrupted..."

( JSI #7080 does fix this problem )


.



Relevant Pages

  • Re: Help with using GPO to configure XP Firewall
    ... I guess my first question is what objects are in the OU to which the policy ... the Windows Firewall comes with some default exceptions. ... I still cannot get the GPO to work though. ... > installed Server 2003 Administration Pack on my Windows XP SP2 PC. ...
    (microsoft.public.win2000.active_directory)
  • Re: Help with using GPO to configure XP Firewall
    ... I guess my first question is what objects are in the OU to which the policy ... the Windows Firewall comes with some default exceptions. ... I still cannot get the GPO to work though. ... > installed Server 2003 Administration Pack on my Windows XP SP2 PC. ...
    (microsoft.public.win2000.active_directory)
  • Re: Help with using GPO to configure XP Firewall
    ... I guess my first question is what objects are in the OU to which the policy ... the Windows Firewall comes with some default exceptions. ... I still cannot get the GPO to work though. ... > installed Server 2003 Administration Pack on my Windows XP SP2 PC. ...
    (microsoft.public.win2000.active_directory)
  • Re: Exchange OWA 2003 Trusted Root Certificate
    ... understanding that I can "filter" a particular GPO from the Domain Level to ... statement on Chapter 4 - How Group Policy Works in the Windows 2000 Server ... > not filter computer configuration policy be user but you could for specific ...
    (microsoft.public.win2000.security)
  • Re: Windows 2003 Server - Group Policy
    ... Group Policies refresh time is 90-minute intervals by default. ... For Windows 2000 Computers see the follow KB: ... Policy Inheritance can be set to this OU it means no policies from higher ... You can also set No Override to a particular GPO. ...
    (microsoft.public.win2000.active_directory)