RE: Group Police problem i need help



thanks for reply , exactly this what happen with me . the domain security
police failed , i shall try the DCGPfix tool , what is the reson can be .
why the templete file of GP become faulty ? how is happen ?
i shall let you know about the result


"Steven Zhu [MSFT]" wrote:

Hi Roma,

Thanks for posting here.

From your post, my understanding on this issue is: you cannot open Domain
Security Policy and Domain Controller Security Policy. If I am off base,
please feel free to let me know.

Based on your description and my knowledge, please let me know whether you
get the "Windows cannot open template file" error message when you open
Domain Security Policy. If so, it's seems the Default Domain Controller
Policy is corrupted. In Windows 2003, DCGPOFIX can by use to reset the
Default Domain Controller Policy as well as the Default Domain Policy.
However, you need to reconfigure the two policies after resetting them. For
details regarding the DCGPOFIX command-line switch, type DCGPOFIX /?.

NOTE: Please backup the two policies before reset them! For details, please
refer to the following MS KB article:

833783 The Dcgpofix tool does not restore security settings in the Default
http://support.microsoft.com/?id=833783

HINT: For general backup and restore of the Default Domain Policy and
Default Domain Controller Policy, and also for other GPOs, Microsoft
recommends that you use the Group Policy Management Console (GPMC) to
create regular backups of these GPOs. You can then use GPMC in conjunction
with these backups to restore the exact security settings that are
contained in these GPOs.

For more information about the GPMC, visit the following Microsoft Web site:
http://www.microsoft.com/windowsserver2003/gpmc/default.mspx

Hope the information above is helpful!

Best Regards,

Steven Zhu
MCSE
Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security
======================================================
PLEASE NOTE the newsgroup SECURE CODE and PASSWORD were
updated on February 14, 2006.? Please complete a re-registration process
by entering the secure code mmpng06 when prompted. Once you have
entered the secure code mmpng06, you will be able to update your profile
and access the partner newsgroups.
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
======================================================








.



Relevant Pages

  • Fwd: Oh Dear, Where to start?!
    ... It seems to me you need two things: an organizational policy, ... finish college and break into the real world of computer security. ... experience in the field of network security and policy ... updates, driver updates, and recommended updates. ...
    (Security-Basics)
  • RE: [fw-wiz] PIX vs Checkpoint vs Sonicwall vs Netscreen - comme nts?
    ... All NetScreen appliances rely on custom-designed ASICs (Application ... Specific Integrated Circuits) for security policy enforcement. ... supports a finite number of "rules" or "policies". ...
    (Firewall-Wizards)
  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
    (microsoft.public.windows.server.sbs)
  • RE: [fw-wiz] PIX vs Checkpoint vs Sonicwall vs Netscreen - comme nts?
    ... The report you cite is CheckPoint originated and deals with older NetScreen ... All NetScreen appliances rely on custom-designed ASICs (Application ... Specific Integrated Circuits) for security policy enforcement. ...
    (Firewall-Wizards)
  • Re: No Shut Down or Restart for Domain Admins
    ... run rsop.msc from your DC and check which policy is responsible to this. ... I have created a group policy in a development network and imported it ... NT AUTHORITY\Authenticated Users Read (from Security Filtering) No ... Enforce user logon restrictions Enabled ...
    (microsoft.public.windows.server.active_directory)

Loading