Re: Oddity with updates



Yeah, I found that information too. The cause was Exchange 2003. It
changed the domain policy and added Exchange Enterprise Admins or something
like that to the policies. And of course, administrators weren't included
in it. A rather obnoxious thing. Installing a mail server really shouldn't
cause a problem like this, but apparently, I'm not the only one that's had
it do this. It of course propagates across the entire domain, so updates
are broken globally.

I'm really anti-exchange 2003 right now. For starters, it lets you install
in an environment that it won't operate in without giving you any sort of
notification. The errors in the error log don't tell you as much either,
even if you hit the "more information" link. The only way you find out is a
google on part of the error. Then of course how it modiies policy without
doing it correctly. But that's enough of a rant for now.


"Simmo" <fake.email@xxxxxxxxxxxxx> wrote in message
news:53B6EFD7-A81C-472F-AE9F-B00CA22A5774@xxxxxxxxxxxxxxxx
>I have seen this a few times before, it was because the following 4
> permissions (under localsecurity policy/group policy | Computer settings)
> were set incorrectly:
>
> - Logon locally
> - Generate Security Audits
> - Manage Auditing & Security Log
> - Restore Files & directories
>
> There is a technet article that describes the situation I had (but i
> completely forgot the number!)
>
>
> Hope that helps
>
> Cheers, Simmo
>
> "Jason Kontkanen" wrote:
>
>> I did a fresh install of Windows 2003. So naturally, I went to do
>> updates.
>> The odd thing is, some of them successfully applied, but a bunch didn't.
>> I
>> manually downloaded one, but it failed too, saying I didn't have
>> permission.
>> It did this both under the local administrator account as well as the
>> domain
>> administrator account. On a hunch, I took the server out of the domain.
>> All the updates applied fine then.
>>
>> Has anyone had this happen to them? I'm happy I was able to get the
>> updates
>> done, but it has me wondering. I never had this problem installing the 4
>> other 2003 installs I've done. The only difference I can think of is
>> that
>> when I joined the domain, I didn't use the domain administrator account.
>> I
>> used a domain admin account, just not the administrator account. If this
>> somehow caused the problem, that has me rather confused.
>>
>>
>>


.



Relevant Pages

  • Re: Remote Client Configuration
    ... > Thanks for quickly updates. ... > group policy will not be updates, instead it will use the old policy that ... > will be applied after the user logon in order to reduce the logon process. ... > laptop to connect to SBS domain first; currently we have no other better ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote Client Configuration
    ... Thanks for updates. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... |> group policy will not be updates, instead it will use the old policy ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote Client Configuration
    ... Thanks for quickly updates. ... Just as I know, if you only logon the domain with cache credential, the ... group policy will not be updates, instead it will use the old policy that ... dial up VPN connection to logon SBS domain once-in-a-while for the group ...
    (microsoft.public.windows.server.sbs)
  • Re: Event Application Errors related to Group Policy
    ... longer needed the policy so I removed it and the errors went away. ... > It appears that this issue is related to WSUS. ... > | child DC's. ... > | to the Parent DC in my Forest Root to get the updates. ...
    (microsoft.public.windows.server.general)
  • Re: GPO errors in application eventlog
    ... The rename administrator account policy was not enabled. ... 1202 - SceCli "Security policies were propagated with warning. ... Check if the "Rename Administrator Account" security policy is enabled. ...
    (microsoft.public.windows.server.sbs)

Loading