Re: Rolling back GPO changes



Craig-
When you say, put things back the way they were, do you mean you left the policy unconfigured? If that is the case, then that won't work. Security policies "tattoo" target systems. You can't undo a change by simply removing it. You would need to add all of the groups back into that user right on the GPO for their state to be returned to normal. So, I think this would include: Administrators, Users and Backup Operators by default.

Darren

--
Darren Mar-Elia
MS-MVP-Windows Server--Group Policy

Simplify Group Policy Troubleshooting with the NEW GPExpert Troubleshooting Pak 1.0 at http://www.sdmsoftware.com/products.php

Visit the GPOGUY: http://www.gpoguy.com -- The Windows Group Policy Information Hub:
FAQs, Training Videos, Whitepapers and Utilities for all things Group
Policy-related



"Craig Chin" <CraigChin@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:4EECFB83-0281-4F97-9B4B-921FF3B48E32@xxxxxxxxxxxxxxxx
I applied a change to my domains default GPO adding a group to the log on
LOCALLY SECTION OF USER RIGHTS ASSIGMENT. i BELIEVED THAT ADDING THE GROUP
WOULD STILL ALLOW DOMAIN USERS TO LOG ON TO THEIR pcs AND ALSO THIS NEW GROUP
to access the PCS too.

i FOUND THAT USERS WERE BEING DENIED THE RIGHT TO LOG ON TO THEIR pcs so i
removed the group and put back things to how they were. Even after doing so
and doing a GPUPDATE on the clients they are not removing the group i gave
access to log on locally and now only this group and domain admins can log on
to the PCS on the network,what should i do to resolve this ?

.



Relevant Pages

  • Re: Need Troubleshooting tips for GP deployment failure
    ... it indicates that the correct Policies are ... >> run into a hitch with Port exceptions to the firewall that are needed ... >> being delivered via Group Policy to some but not all PCs. ...
    (microsoft.public.win2000.group_policy)
  • Re: Applying user GPO to computers
    ... > to specific COMPUTERS, rather than ... > USERS (there are several PCs which are exempt from this policy)" ie I'd ... Mike Brannigan ...
    (microsoft.public.windows.server.active_directory)
  • Group policy not taking effect on some users
    ... Our DC is in our office and we have a few PCs that connect remotely through ... If a user logs in as a local admin on those PCs they are able to ... However, when a user logs into the system it lets them in, but only ... I have a mapped drive policy in Group policy ...
    (microsoft.public.windows.group_policy)
  • Re: Frage zu GPOs
    ... Ich habe an der gleichen Stelle eine andere Richtline (Outlook ... Richtlinien die für die DomainUser OU konfiguriert sind. ... ob die PCs der anderen Domain den Wert ConfirmFileDelete in der Registry stehen haben. ... Will nur mal sehen ob die Policy prinzipiell funktioniert. ...
    (microsoft.public.de.german.windows.server.general)
  • Re: Software Restrictions
    ... When I denied Project Users Read & Apply Policy, ... user could not access any of the restricted applications to include Project. ... >>I want to implement 2 GPOs to restrict certain software. ... >> be applied to the Domain Users security group. ...
    (microsoft.public.windows.server.active_directory)