Group Policy Issues
- From: Arkane <Arkane@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 16 Aug 2005 11:01:06 -0700
Hi
We have a 3 forest single-site AD setup, all Windows 2003 Server.
2 of them are Windows 2003 Server SP1, one is not.
Up until recently, I've been able to modify any GP Object on any forest
without trouble. Today however I am able to view the GPOs, they apply on
computers but I cannot modify them. I'm a Domain Admin/Enterprise Admin and
am a member of Group Policy Creator Owners group also. The 'Default Domain
Controller Policy' is fine, I can edit that one, but any others I cannot
unless I recreate them.
When I try to edit, I can open them in GPMC, open them in the editor but
when I try to change a setting it says "Group Policy snap-in was unable to
save changes - Access Denied".
I have never seen this error before, I have checked the GPO ACLs (both on
the GPO itself and the file permissions in SYSVOL). They are indentical and I
have full permissions on the GP Objects.
Even if I login as Administrator (domain admin) on a PDC, I cannot edit the
GPOs as it gives me exactly the same error message. Even using our
'emergency' admin account (which has all permissions explicitly set), cannot
edit the policies.
They apply as normal (using GPRESULT/RSoP) however, just not modified by any
Admin user (whether that's an admin in our ITTeam security group or Domain
Admins).
If anyone has ANY ideas, no matter how far-fetched it may be, I'll be happy
to listen and try things - I'd much rather fix this up (and hopefully know
what caused it) than rebuild the entire raft of group policies that exist on
the site.
(On a seperate note, I assume that assigning rights using Delegation of
Control Wizard for our IT group, giving them full control on each DC with
GPOs is the correct way to give them the ability to edit GP objects
cross-forest?)
.
- Follow-Ups:
- RE: Group Policy Issues
- From: JSilva
- RE: Group Policy Issues
- Prev by Date: SBS email accounts
- Next by Date: RE: Setup GPO to map drive without using scripts
- Previous by thread: RE: Group Policy issues
- Next by thread: RE: Group Policy Issues
- Index(es):
Relevant Pages
|