Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Group Policy mess up

Status
Not open for further replies.

rrdavis07

MIS
Jun 2, 2004
88
US
Well, I've effectively shot myself in the foot by inadvertantly removing access to the default GPO object.

Let me explain: I've implemented Automatic Update for our network, but did not want our server to be automatically updated (I didn't want them to auto-reboot, if that was necessary). Well, implementing AU requires the use of a Group Policy. For the servers to be excluded from that policy, I copied the default GPO (my first mistake) and changed its name, security access and the AU policy.

Some of you may already see where this is leading...

When I copied the default Domain Policy, another policy was listed, but it was really just another instance of the GPO that was already on the list. When I changed (what I thought was) the new policy, I was actually changing the ONLY policy. Thinking it was a newly created policy, I removed all names from the security tab except CREATOR OWNER (thinking that was me) and the names of the servers I was creating this new policy for. So now, I have a group policy in effect that has AU disabled, but nobody really has access to it. Evidently, I am not the CREATOR OWNER. As administrator, I would have thought that I would have the rights to "Take Ownership" of the GP Object, but can't find any options that will allow me to do that.

The only good thing about this is that we didn't have any special policy settings, except for AU.

So...

How can I correct my mistake? Can I correct my mistake? Should I just submit my 2-week notice now???

Randy Davis, MCP
Data Analyst

 
word to the wise (after having done something similar myself)

always apply GPO settings to the lowest possible container in the heirachy...

for my PDC, laptops, workstations....each has its own container and group policy for settings like auto updates...

at any rate if you are looking into managing updates check out SUS from microsoft


dirt simple to set up and works great..plus it adds a new template to the automatic updates options with a bunch of new and useful features
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top