Re: DC with a Local Computer Policy and greyed out security settin

Tech-Archive recommends: Fix windows errors by optimizing your registry



so you think installing the admin tools and GPMC on a PC may allow me to see
the DDP? interesting idea.
The GPO I edited the admin name in is the one that says local GPO. should
the local GPO be in C:\WINDOWS\system32\GroupPolicy? the data in this folder
does not appear to match what GPMC says the local GPO has in it.

i still don't get what has caused this mix up.



"Darren Mar-Elia" wrote:

I wouldn't recommend editing the inf file directly. If you can get to the
policy from another machine, then I would recommend using that to make the
edits rather than doing it on the DC.

As far as the administrator rename, what GPO did you deploy that in? Maybe
you deployed it against the local GPO when you thought it was the DDP?



--
Darren Mar-Elia
MS-MVP-Windows Server--Group Policy

Script Group Policy Settings with the GPExpert Scripting Toolkit for
PowerShell!
Find out more at http://www.sdmsoftware.com/products2.php

Visit the GPOGUY: http://www.gpoguy.com -- The Windows Group Policy
Information Hub:
FAQs, Training Videos, Whitepapers and Utilities for all things Group
Policy-related

"=pathfinder=" <pathfinder@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:BB018568-0C44-4D0E-BDFB-1CBDD339C274@xxxxxxxxxxxxxxxx
thanks for the suggestion, it opened the same local computer policy again
though. On my othe domain it does open the default domain policy, so i
dont
get what the issue is here.

I browsed through the filesystem and found this

[Unicode]
Unicode=yes
[System Access]
MinimumPasswordAge = 1
MaximumPasswordAge = 42
MinimumPasswordLength = 7
PasswordComplexity = 0
PasswordHistorySize = 24
LockoutBadCount = 0
RequireLogonToChangePassword = 0
ForceLogoffWhenHourExpire = 0
ClearTextPassword = 0
[Kerberos Policy]
MaxTicketAge = 10
MaxRenewAge = 7
MaxServiceAge = 600
MaxClockSkew = 5
TicketValidateClient = 1
[Version]
signature="$CHICAGO$"
Revision=1
[Registry Values]

under
\\domain\sysvol\domain.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Microsoft\Windows
NT\SecEdit\GptTmpl.inf. it has not been edited since 2/17/06 and appears
to
be what i am looking for. Can i edit this file to overcome my immediate
issues like LockoutBadCount = 0?

Another weird thing with this is that i was able to rename the local admin
name, but the contents above to don't show it, again on my other damain
the
inf file shows NewAdministratorName = "ECantona".


.



Relevant Pages

  • RE: Password expiry
    ... password policies are defined in either the local GPO if you are not on a ... domain or on the Domain GPO. ... Select the "Group Policy" Tab ... settings will be on the domain servers. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Einstellung wird nicht angewendet
    ... Dieser hat ja keinen Lokalen Admin mehr. ... Was ja darauf hin deutet das die GPO ... Default Domän Policy greift auch direkt auf die AD zu. ...
    (microsoft.public.de.german.windows.server.active_directory)
  • Re: ACL on GPO link
    ... prevent them from unlinking your GPO. ... The gpLink attribute is monolithic in that each link ... A person who can manage links everywhere is aswell an admin ... ... I conclude that you cannot prevent an AD administrator from ...
    (microsoft.public.windows.group_policy)
  • Re: Manually added user rights assignments
    ... Are you attempting to set this is a GPO of AD that is applied ... OU (containing the servers) not to the domain and are ... Also, if you have TS installed in admin mode on W2k, or you ... > Have been trying to add the buit-in Admin accounts of my members servers ...
    (microsoft.public.windows.group_policy)
  • Re: ACL on GPO link
    ... To take it a step further from what Mark has said, if, for example, an administrator was not domain admin equivalent and could not take ownership of any AD object and change its permissions, you could prevent them from the writing the gpLink attribute on the domain NC head. ... But, because of the way links are stored, they would also not be able to add any new links to the domain, nor remove other GPO links. ...
    (microsoft.public.windows.group_policy)