Re: Problem configuring services via Group Policy.

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Have you seen this article--that talks about changes to DCOM security in 2003, SP1 and above?

http://support.microsoft.com/kb/903220/en-us

That might be your issue.

--
Darren Mar-Elia
MS-MVP-Windows Server--Group Policy

Script Group Policy Settings with the GPExpert Scripting Toolkit for PowerShell!
Find out more at http://www.sdmsoftware.com/products2.php

Visit the GPOGUY: http://www.gpoguy.com -- The Windows Group Policy Information Hub:
FAQs, Training Videos, Whitepapers and Utilities for all things Group
Policy-related

"Jason H." <JasonH@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:82F65DB7-5BEA-4FE1-8A7A-F3BC7C56D14C@xxxxxxxxxxxxxxxx
Yes it does. I know the policy is taking effect due to the start up type of
the service being changed, if I change the start up type then run gpupdate
/force it changes back to what is dictated in the policy. Also I am just
adding this to an existing policy so it is not new, the policy that I am
adding this to is one that is and has been applied to the servers for quite
some time.

My issue is - if I know the policy is working and applying to the server why
can't the users connect remotely to the machine use a Computer Management
snap in within MMC on their machines. That is where I still get the Access
Denied error message. Is there something else I need to do in W2K3 to allow
remote "Computer Management" access?

"Florian Frommherz [MVP]" wrote:

Howdie!

Jason H. schrieb:
> the servers as possible. I have gone through the steps to configuring > the
> services as needed and ran a gpupdate /force on the target machine. I > know
> the policy refreshes because the start up type changes.
>
> As one of the users added to the group policy I still cannot connect to > this
> box via Computer Management. I can remotely connect to the box, expand
> Services and Applications, but when I select Services I get an "Access
> Denied" error message.

The policy does apply to the computers (you have the computer account(s)
in the OU you linked the policy to)? If you run rsop.msc on one of the
target machines, does the policy you created show up?

cheers,

Florian
--
Microsoft MVP - Windows Server - Group Policy.
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.


.



Relevant Pages

  • Re: Superannuated passwords
    ... > In Policy editor, I have max password age set to 42. ... > In the Admin Tools, go to Computer Management> System Tools> ... Stan Brown, Oak Road Systems, Tompkins County, New York, USA ...
    (microsoft.public.windowsxp.customize)
  • Assign Domain Security Policy/Manage remote computer
    ... I've just setup active direcotry, and added other computers to the new ... I defined it in the Domain Security Policy section on my AD server. ... I tried to do Computer Management on one of the domain members, ...
    (microsoft.public.win2000.security)
  • Re: Manage from My Computer indicates Access Denied
    ... If so, a Group Policy ... may be in place to prevent access to Computer Management. ... Make sure the value data for NoManageMyComputerVerb is 0 ... Remove the Manage item from the Windows Explorer context menu ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Rename Admin in Local Policy or Users/Groups
    ... the domain/OU/domain controller policy can override any local machine settings ... configured either via security policy or through Computer Management and enforce ... > Settings>Security Options versus renaming thru Computer ...
    (microsoft.public.win2000.security)
  • Re: Account Lockout threshold
    ... All are window 2000 advanced servers with Service pack 3, ... Domain Contoller Security Policy - Account lockout threshold ...
    (microsoft.public.security)