Re: Locked out of group policy on domain controller

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hello Bruce,

If the policy is limited only to user configuration part/settings, i would try to built a GPO, linked to a new OU with all the users that should apply it, so that only the users aregetting the setting's, that should get it. Do not set any machine policies for the users on the DC OU.
But again, you should really avoid this kind of configuration. All GPO's linked to DC OU can easily kick yourself off from the system.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

Hi Meinolf,

Thanks for your reply.

My group policy to lock down the terminal server/domain controller
removed normal acces to ADUC through settings on the start menu and
the shortcut I put on the desktop to Administrative Tools says it is
restricted.

Luckily I had an icon for ADUC in my quick start which allowed access
so I could disable the GPO. I noticed this after posting my question.
I only have two servers. One is my PDC the other is a backup DC and I
need to run Terminal Server to utilize our Practice Management
software from remote offices.

Short of adding a third server to handle Terminal Server business, is
there a way to prevent my group policy from locking down the
Administrator who is logging on locally to the Server?

Thanks

"Meinolf Weber" wrote:

Hello Bruce,

So what happens if you open ADUC, properties of Domain controllers
OU, Group policy tab and doubleclick the policy or edit it?

BTW, making a DC terminal server is a really unlucky decision. You
should really prevent this, if possible. Normal users shouldn't work
on DC's for security reasons. Use only member servers, so that you
configure policies in a way, that it can work only on TS.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
I was in the process of locking down my users that access my servers
(which are also domain controllers) with terminal server sessions by
following Q278295. Apparently it worked too well since I am now
locked out of group policy, run command, my computer, etc. At first
i applied this new policy to users which created a few issues that
now appear minor compared to the issues I am having after reapplying
it to my domain controller OU.

I am able to logon locally as domain admin but don't know how to
regain access to group policy to correct this.

Thanks in Advance



.



Relevant Pages

  • Re: Group Policy Template for Terminal Service
    ... 192794 How to apply System Policy settings to Terminal Server ... Go into the Properties for that GPO and add Read and Apply Group Policy ... "Hide the dropdown list of recent files" settings. ...
    (microsoft.public.win2000.group_policy)
  • Re: GPOs and Security
    ... Policy info that you may find helpful. ... 250842 Troubleshooting Group Policy Application Problems ... 247811 How Domain Controllers Are Located in Windows ...
    (microsoft.public.win2000.security)
  • Re: Cant access default group policy
    ... Remove the duplicate link for the ddcp. ... that the policy files are all present under the sysvol folder. ... > Going through Properties on the Domain Controllers OU, ... > The Group Policy Editor MMC opens fine, ...
    (microsoft.public.win2000.group_policy)
  • Re: Local GPO
    ... I'm doing studies on Windows 2003 Group Policy, and would like to know how to find out the RSOP for a server from Group Policies. ... But Local GPO for Domain Controllers applies to restore mode only. ... The Local Security Settings shows the current settings, ...
    (microsoft.public.windows.group_policy)
  • Re: Problem logging onto TS via RWW
    ... locally" and "Allow log on through Terminal Services" on the local Security ... Policy on the terminal server box as I requested in my previous post. ... Remote Desktop Users Group. ...
    (microsoft.public.windows.server.sbs)