Re: Registry Changes through Group Policy

Tech-Archive recommends: Fix windows errors by optimizing your registry




"Kevin Mertel" <KevinMertel@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:40399A74-F39E-4010-A2AE-218FE8C94595@xxxxxxxxxxxxxxxx
I have a security appliance that requires a domain user account with access
to the registry of all of the servers in my domain. The security appliance's
documentation says to use the Domain Security Policy MMC to add a registry
key (MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg)
and
then grant read permission to that key to a specific security group.

I would NOT use the "Default Domain Security policy" but rather one created
for this purpose and I would (attempt to) link it to ONLY the GPO(s) where
those servers were located rather than to apply it to every machine in the
domain.

In
addition they have you go into Advanced settings an enable "Allow
inheritable
permissions." which does not seem to be the default when I reviewed this
key
on a sample of my member servers. What I'm uncertain of is, if I use the
"Default Domain Security" MMC on my domain controller to add a registry
key
and modify it's permissions, and that registry key already exists on a
member
server, would that add to the existing registry key's security or replace
it
entirely?

I have never tested this but it should take just a few minutes to test.
I believe it replaces -- i.e., sets ALL of the permissions according to
the GPO -- and is not additive.


--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)

The document I'm following can be found below beginning on page 5.

http://www.rac.cz/rac/homepage.nsf/CZ/Qualys-Pictures/$FILE/QG-Trusted_Scanning_Windows_060601.pdf

Thanks,

Kevin Mertel



.



Relevant Pages

  • Some services wont start
    ... At some point changes to permissions ... months back and I had fixed it by putting back an ACE in the registry at ... the current servers are different ones than before by the way). ... various parts of the HKLM/Machine registry branch and modifying the ...
    (microsoft.public.win2000.active_directory)
  • Re: Some services wont start
    ... Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA ... All previous permissions will be reset back to the original ... both in registry and file system. ... >>> the current servers are different ones than before by the way). ...
    (microsoft.public.win2000.active_directory)
  • Re: Some services wont start
    ... All previous permissions will be reset back to the original ... > build of the server itself during setup. ... both in registry and file system. ... >> the current servers are different ones than before by the way). ...
    (microsoft.public.win2000.active_directory)
  • Re: Registry Permissions on Win2K and XP Servers
    ... Not specific to servers but rather to NT-based versions of Windows. ... > To handle my registry tasks, I've been using the cRegistry class on ... > used in my software on Win2K and WinXP servers. ... The user still needs the proper permissions as defined by the group the user ...
    (microsoft.public.vb.winapi)
  • Re: Server registration lost after domain password change
    ... Servers in SQL Enterprise Manager. ... the fix in XP service pack 1 only works if the registry key "MasterKeyLegacyNt4Domain" is ...
    (microsoft.public.sqlserver.tools)