Re: GPO Error



On Jun 8, 6:20 am, Novell Guy <Novell G...@xxxxxxxxxxxxxxxxxxxxxxxxx>
wrote:
New Windows 2003 SP3 Domain Controllers (have 2 DCs)

Configured GPO on an OU 2 levels under the domain object called folder
redirection Folder Redirection - it appears to be OK

Configured a 2nd GPO on the the parent OU (1 level under the domain object)
called Client Security and set a couple of things in the computer section of
the GPO. There were more settings needed but I noticed many of the folders
were missing and when I go to edit the GPO I now get an error referencing a
problem with line 62. I can list that message in its entirity but I am
hoping someone has seen this before.

In my research for troubleshooting I ran across an artical stating that only
custom Group Policy Templates should be edited yet this is the first I have
read of this requirement.

Right now I am sick to have a near perfect domain with event error-free
servers if I truly have an irreversable issue with the GPO/GPT, etc.

Any suggestions for getting the GPO/GPT back right or just point me in a
good direction would be helpful

Thanks in advance

hello..

the error you stated points to a syntax error in one of the adm files
you have got loaded. i am presuming you have not created your own
custom templates. if so suggest thats where the error lies. just open
with notepad and go down to line 62.

if you have not created custom adm's then it looks as if some
corruption has taken place in one of the default adm's. if you open up
the policy and r click administrative templates folder, then remove
one template at a time. saving and closing the policy. the re-opening
it. to see when the error stops that will tell you what adm file is at
fault. best bet then if you are not familiar with the syntax of adm
files would be to open the faulty one and a good one sidebyside in
notepad and compare line 62.

another possible fix would be to open the policy and undo any changes
you have made. that quite often works.

you should not edit the default adm files two reasons. one the default
domain contollers policy and default domain policy are critical to the
health of your domain. so its good practice to leave alone. the second
reason is that if you spend ages modifying your default policies you
could loose them if you service pack your dc's sometime. as they might
get overwritten.


dave


.



Relevant Pages

  • Re: User Profiles
    ... You can use Folder redirection for the Start Menu, ... Exactly what icons are you getting from the Default Domain Policy, ... and in which GPO setting are they defined? ... MCSE, CCEA, Microsoft MVP - Terminal Server ...
    (microsoft.public.windows.terminal_services)
  • Re: Remove ADM Files from the Sysvol Folder - how ?
    ... As far as I understand it, that policy,"Always Use Local ADM Files for Group ... just ignores the policy and goes looking for the ADMs in SYSVOL as normal. ... > user which will edit GPO and to the workstation which he uses. ...
    (microsoft.public.windows.group_policy)
  • RE: xp pro sp2 post install screen saver problem
    ... Download and install the Group Policy Management Console with SP1 ... Two policy settings area available to help with management of ADM files. ... updating an existing GPO does not result in ADM ...
    (microsoft.public.windowsupdate)
  • Re: GPO Error
    ... I did compare the adm files and could find no different. ... Configured GPO on an OU 2 levels under the domain object called folder ... custom Group Policy Templates should be edited yet this is the first I have ...
    (microsoft.public.windows.group_policy)
  • Re: GPO Management Delegation
    ... I checked the permissions on the Policy ... permission on that folder. ... grayed out and it will ask for the name of the new GPO. ...
    (microsoft.public.windows.server.active_directory)