Re: Problems since SP1 (Server 2003) - 2nd request for help



The question I would ask is how are you pulling up those policies? If it's
GPEDIT.MSC and your settings are actually set in a GPO, then no, you will
not be able to edit it. Find the GPO that is applying this policy and edit
that.

Jeff Pitsch
Microsoft MVP - Terminal Server

Forums not enough?
Get support from the experts at your business
http://jeffpitschconsulting.com

"TP" <tperson.knowspamn@xxxxxxxxxxxxxxx> wrote in message
news:uk6uhHSaGHA.1228@xxxxxxxxxxxxxxxxxxxxxxx
Did you run gpupdate after making the change to the Domain Controller
Security policy? If so, did you check the event log for errors in
applying the policy?

Changes made to a domain GPO are not immediately applied to the applicable
computers and/or users. This is why you need to run gpupdate after making
a change if you need it to be applied sooner than the next Group Policy
refresh interval.

I realize that from your perspective it may seem like "Why doesn't TP
understand me!! If only I could just edit the list of users in the Local
Security Policy everything would work. Clearly the server is using the
list that is displayed in the Local Security Policy screen to determine
who can logon."

I will check back periodically today and respond to you as needed. With
your help, we will get this thing fixed shortly.

Thanks.

-TP

Mel wrote:
Ok, we're getting close here. But I don't think I've made it clear
enough. I CAN go through the Group Policy and change (or add to this
setting)
and it DOES ABSOLUTELY NOTHING.

***NEXT LINE EXTREMELY IMPORTANT****
The ONLY ones who can successfully log on to TS are those whose names
appear in: Local Policy->Windows Settings->Security Settings->Local
Policies->User Rights Assignment->Allow Logon through Terminal
Services And of course, this is the one we can't change.

A user was added just a few days before the update and that person has
access. Nobody added since SP1 can have access it appears because of
this. Can we remove SP1?

Thanks

Mel





.



Relevant Pages

  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... Server Security and Auditing Policy ... This list only includes links in the domain of the GPO. ... The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)
  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... > Server Security and Auditing Policy ... > This list only includes links in the domain of the GPO. ... > The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)
  • Re: GPO not picking up computer settings
    ... to the domain container with the password/account settings you want. ... for password/account settings and from what GPO. ... buying any of the highly rated AD or Group Policy books you see at Amazon or ... I have changed all the passwords back to what they were so users are now ...
    (microsoft.public.windows.server.security)
  • Re: Local GPO refreshes outside of refresh interval
    ... I looked through my GPO's Windows Settings section ... > Some policies, including IE policies, have a checkbox that defines if this ... > it should apply EVEN if the value defined in GPO did not change since the ... we are talking about one particular policy: ...
    (microsoft.public.windows.group_policy)
  • Re: IE Maintenance Group Policy Settings Issue
    ... If you configure a GPO to set the proxy to blank, ... be identified as a change to the policy and it will be re-applied to the ... This would be a GPO change and the settings ...
    (microsoft.public.win2000.group_policy)

Quantcast