Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Domain Conrtoller Security Error 1

Status
Not open for further replies.

sword123

Technical User
May 21, 2003
2
IN
Hi all
I have a problem in Domain Controller Policy,"I have checked the displayed fix in this forum, but nothig helped" It throw permission deneyal error. I have tried all related fix regarding this from the microsoft site. When i spoke to microsoft connect customer. Level one support, they told me to transfer all the five rolles to another server and re-run dcpromo, My query is, when i run dcpromo again, while transferring the gpo plicy from the other additional domain controllers server, will it not pull the old currupted GPO policy's to the new server again. I use Windows 2003 as ADs SErver with DNS and aditional domain controller's as Windows 2000 server, Is there any way to fix the error.
or ever after putting new Domain controller, what is the garunty that it will not replicate the same GPO error again. because of this error iam not able to apply any group policy to any OU. "There is no note pad Icon in the Police container of the system so iam not able to use the sujection in the teck tip to change the permission".Pls help me to fix the error.
Thanks in Advance.
Regards
Luke
 
can you describe the problem ?
and the error message ?

Mohamed Farid
[green]Know Me No Pain , No Me Know Pain !!![/green]
 
In active directory, set the view to advanced.

right click the domain and select properties, then group policy tab. Highlight your policy and select properties, then the security tab. See if you can adjust your security settings to allow you to do what you need with this policy.

See what you can do from other angles. Can you dissable the user and computer settings on policy property pages? Can you create a temporary OU and block the policy inheritance on that temp OU? If yes, move your computer and user account to it, then reboot your client (should block you from getting policies other than ones you create for this temp OU).


Start, Help. You'll be surprised what's there. A+/MCP/MCSE/MCDBA
 
Don't know if this will help, but the policies are replicated through the sysvol share. You would have to know the GUID to the policy you need removed and I'm not even sure it would let you or what effects it would have.

Start, Help. You'll be surprised what's there. A+/MCP/MCSE/MCDBA
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top