Enterprise Domain Controllers group got lost



On my native mode Windows 2003 Active Directory, while running

GPMC SP1, I get this error message:

"The Enterprise Domain Controllers group does not have read access to
this GPO. The Enterprise Domain Controllers group must have read
access on all GPOs in the domain in order for GP modeling to function
properly..."

I can't find "Enterprise Domain Controllers" in my 2003 active
directory. This AD started out as Win 2000 and had some Group
policies. It was then upgraded to 2003.

Found this info:
http://www.jsifaq.com/SUBR/tip8800/rh8872.htm

This says to run the below (not done yet): I want to find this group first.

Cscript GrantPermissionOnAllGPOs.wsf "Enterprise Domain Controllers"
/Permission:Read /Domain:mydomain

More searching found this:
http://techrepublic.com.com/5208-6287-0.html?forumID=39&threadID=168872

This says to look for SID: S-1-5-9. So, in ADU&C, after turning on
"View Advanced Features", I found it as described in the above
article. It is in "Foreign Security Principles".

How do I put it back in place now that I found it?



TIA, Devin


.



Relevant Pages

  • Re: GPO question
    ... Is the DFS service running? ... when I click on a GPO object: ... The Enterprise Domain Controllers group must have read access on all ...
    (microsoft.public.windows.server.migration)
  • Re: GPO question
    ... Is the DFS service running? ... when I click on a GPO object: ... The Enterprise Domain Controllers group must have read access on all ...
    (microsoft.public.windows.server.security)
  • Re: GPO question
    ... Is the DFS service running? ... when I click on a GPO object: ... The Enterprise Domain Controllers group must have read access on all ...
    (microsoft.public.windows.server.general)
  • Re: GPO question
    ... Is the DFS service running? ... when I click on a GPO object: ... The Enterprise Domain Controllers group must have read access on all ...
    (microsoft.public.windows.server.active_directory)
  • RE: GPO error after upgrade
    ... What you'r not saying is IF the group "ENTERPRISE DOMAIN CONTROLLERS" has ... You can check by going to GPO and select "Properties". ... "Taylor" wrote: ... > GPO's in the domain in order for Group Policy Modeling to function properly. ...
    (microsoft.public.windows.server.general)