Re: Error trying to copy Default Domain Policy



Ok....but how do I know what most of the settings should be set at? For
example, ...

1) are all the Services set to not defined originally in the Default Domain
and Domain Controllers Policy?

2) if I set some services back to not defined, will the services revert to
whatever they were by default(like Disabled) or will they stay as Automatic
because the old policy changed them to Automatic?

3) if I set my own user logon settings in a new policy at the top level,
what should I set same settings for in the other OUs? I would like to have
them set to default so I don't get confused when I am looking at these
policies. I don't know what the defaults are? Are they set to not defined
by default?


--
Thanks!







"Florian Frommherz [MVP]" <florian@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote
in message news:eNQJDOtUIHA.748@xxxxxxxxxxxxxxxxxxxxxxx
Howdie!

Saucer Man schrieb:
I recently came on board here and found that the GPOs have been modified
by prior staff that wasn't 100% sure of Group Policy Management. They
made changes in the Default Domain Controller Policy, the Default Domain
Policy, and others. They made redundant changes for logon restrictions
in multiple policies, changed service StartUp behaviors, blocked
inheritance, etc.

I understand. But rather than wiping out the Default Domain Policy and the
Default Domain Controllers Policy, I'd go for the work and try to crawl
through the mess they left you alone with. Although I haven't had any
major issues with dcgpofix, I'd use that only in disaster situations .

For example, I tried to set the License Logging service to disabled in
our 2003 domain but it reverted back to automatic. I found that the
default policies had this service changed to automatic. Then I found
that many services were changed. They made so many changes that they are
not sure what they did. I don't know of any other way reset them and
just implement the changes that we need because they modified all the
default policies.

I'd start with making a plan of all settings and policies in place. GPMC
scripting helps you out with this. Based on that, you start all over and
plan your own design - before implementing, you can use GPMC to back up
all the policies (in the Group Policy Objects node, right-click the
policy, "Back up...") and then start all over. Replace the old settings
step by step with your new ones rather than wiping everything out at once
(~ but that depends on your strategy and the size of the organization,
number of policies, etc.)

I'm quite sure you won't come around building a test environment and
working it all over piece by piece.

cheers,

Florian
--
Microsoft MVP - Windows Server - Group Policy.
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.



.



Relevant Pages

  • Re: Registry tatooing
    ... I'm working on a utility that will clean up GP policies and preferences. ... Speed Group Policy Troubleshooting with the NEW GPHealth Reporter tool at http://www.sdmsoftware.com/products.php ... Administrative policies work very similar to NT4 System Policies. ... Well, to his disliking, the settings remained. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Local GPO refreshes outside of refresh interval
    ... I looked through my GPO's Windows Settings section ... > Some policies, including IE policies, have a checkbox that defines if this ... > it should apply EVEN if the value defined in GPO did not change since the ... we are talking about one particular policy: ...
    (microsoft.public.windows.group_policy)
  • Re: Registry tatooing
    ... It can list and clean true policies, ... Speed Group Policy Troubleshooting with the NEW GPHealth Reporter tool at http://www.sdmsoftware.com/products.php ... Well, to his disliking, the settings remained. ...
    (microsoft.public.windows.server.active_directory)
  • Re: New Password Policy Implementation Problem
    ... Default Domain Group Policy object. ... > able to implement the following settings via the Default Domain ... > Enforce Password History ... > These policies were enforced for all domain users and we verified the ...
    (microsoft.public.windows.group_policy)
  • Re: New Password Policy Implementation Problem
    ... Default Domain Group Policy object. ... > able to implement the following settings via the Default Domain ... > Enforce Password History ... > These policies were enforced for all domain users and we verified the ...
    (microsoft.public.win2000.group_policy)

Loading