Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Desperate Emergency. Please help

Status
Not open for further replies.

jwillard

IS-IT--Management
Apr 29, 2004
74
US
Emergency...

An admin applied a group policy to the domain level which restricts all users. Even domain admins. How can I remove this policy, if I cant get to it?

Boycott Sony
 
Just an idea - not sure if this will work but you could maybe....

Log on to a Client PC as a LOCAL admin (not a domain admin/user) and install Group Policy Management Console with Service Pack 1

Use this to edit Group Policy on your server (if it will let you connect to it without being logged into the domain) and edit the GP.

Good Luck
 
This does not work. Cnat edit DC's policy.

Will Directory Services Restore also restore the older policies?

Boycott Sony
 
I don't know...

Does Win2003 have safe mode? If it does, perhaps you can boot to that and edit the policy??
 
I can log on but I cant open any MMC's or dos prompt

Boycott Sony
 
This is also considered an MMC and I can not run it. Good thought though. I do see a tool that will reset the policies. Its called dcgpofix. Its supposed to reset all the policies to default. Kionda saving it as a last resort though. Anyone had experience with this tool?

Boycott Sony
 
I got it Halley-looya (i know its spelled wrong).

If anyone ever runs into this:

What I ended up doing was-
Downloading an executable reg editor (beceuse I couldnt use regedit or 32 on any machines) which luckily I was still able to open and use, and editing the registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\MMC to a value of 0. Then I immediately open my GP Managment console and deleted the offending GP from the domain. After that I logged off and back on again and all was well.

That was the most trying moment I've had yet as an admin.

Boycott Sony
 
Thanks very much to all who replied and tried to help me. I really appreciate it.

Boycott Sony
 
Glad to see you got it fixed...and thanx for sharing the solution. I'm gonna tuck that one into my bag of tricks in case I ever need it.

Did you have a nice talk with the Admin who did this?

JB
 
Yes. What had happened was, he was creating a small policy to direct our machines to an update server. Only problem was he copied a policy that is for our most limited of users and created it from there. He will not be accessing any policy settings for a while.

Just goes as a reminder, ALWAYS ALWAYS test your GP's with a test OU and some Test users in that OU.

Boycott Sony
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top