Page 1 of 2 12 LastLast
Results 1 to 16 of 17

Thread: Group Policy Disaster!!

  1. #1
    Senior Member
    Join Date
    Aug 2003
    Posts
    508
    Thanks
    0
    Thanked
    0 times in 0 posts

    Group Policy Disaster!!

    I was 'playing' with the group policies of my server2003 domain earlier, thinking that my user account (which I use for all administrative duties) was in an OU with no policies applied.

    However, upon logging out and back in, I discovered that I am completely locked down and cannot do anything or make any changes to anything.

    I have locked down all MMC snap-ins, meaning I can't change the group policy.

    Is there any way out of this (short of rebuilding my DC).

    My domain consists of one DC and 2 workstations. The Administrator account on all PCs has been disabled and the only account which isn't affected is my local account on one fo the workstations...

    Oops!

  2. #2
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    could be a job for ERD commander to create another account ?
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  3. #3
    Senior Member
    Join Date
    Aug 2003
    Posts
    508
    Thanks
    0
    Thanked
    0 times in 0 posts
    I've locked down application installs and all drives as well!!

  4. #4
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    what about on boot ?

    ERD is a boot CD.
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  5. #5
    Senior Member
    Join Date
    Aug 2003
    Posts
    508
    Thanks
    0
    Thanked
    0 times in 0 posts
    yeah, just checked it out, bloody expensive though!! (for something that I will probably only use the once, having learnt my lesson!)

  6. #6
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    ah I thought there might be an evaluation edition.

    Did you install the recovery console ?
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  7. #7
    Oh no!I've re-dorkalated! Jiff Lemon's Avatar
    Join Date
    Jul 2003
    Location
    Sunny MK
    Posts
    2,504
    Thanks
    80
    Thanked
    44 times in 41 posts
    You tried booting the Dc into safe mode?

  8. #8
    Oh no!I've re-dorkalated! Jiff Lemon's Avatar
    Join Date
    Jul 2003
    Location
    Sunny MK
    Posts
    2,504
    Thanks
    80
    Thanked
    44 times in 41 posts
    Or possibly boot a workstation into safe mode as Software restriction policies don't apply when Windows is started in Safe Mode Safe Mode

    Log on as a local administrator, modify the policy, run gpupdate, restart the computer, and then log on normally.

    Have you got the 2003 Group policy editor installed on a machine?

  9. #9
    Senior Member
    Join Date
    Aug 2003
    Posts
    508
    Thanks
    0
    Thanked
    0 times in 0 posts
    Quote Originally Posted by Jiff Lemon
    Or possibly boot a workstation into safe mode as Software restriction policies don't apply when Windows is started in Safe Mode Safe Mode

    Log on as a local administrator, modify the policy, run gpupdate, restart the computer, and then log on normally.

    Have you got the 2003 Group policy editor installed on a machine?
    Right, Booting the DC in safe mode doesn't work - policies still applied!

    I'm currently logged onto the workstation with my local account and can access the hard disks of the DC...

    I don't have Server 2003 Group Policy Editor on this workstation.

  10. #10
    Oh no!I've re-dorkalated! Jiff Lemon's Avatar
    Join Date
    Jul 2003
    Location
    Sunny MK
    Posts
    2,504
    Thanks
    80
    Thanked
    44 times in 41 posts
    Did you modify the default domain policy or apply the policy to the Computers OU?

  11. #11
    Senior Member
    Join Date
    Aug 2003
    Posts
    508
    Thanks
    0
    Thanked
    0 times in 0 posts
    Modified the default

  12. #12
    Oh no!I've re-dorkalated! Jiff Lemon's Avatar
    Join Date
    Jul 2003
    Location
    Sunny MK
    Posts
    2,504
    Thanks
    80
    Thanked
    44 times in 41 posts


    You got the admin tools installed on the machine? I'm presuming when if you try and connect to the Active Directory users and computer MMC, the policy gets applied and you get stuffed?

  13. #13
    Senior Member
    Join Date
    Aug 2003
    Posts
    508
    Thanks
    0
    Thanked
    0 times in 0 posts
    No, I can;t connect to the AD because I am logged on with a local workstation account, not a domain account..

    I can see the SYSVOL from here tohugh, if that's any help?

  14. #14
    Oh no!I've re-dorkalated! Jiff Lemon's Avatar
    Join Date
    Jul 2003
    Location
    Sunny MK
    Posts
    2,504
    Thanks
    80
    Thanked
    44 times in 41 posts
    Well, you could try renaming (NOT deleting!) the Policies folder. However I suspect the exisiting policies will remain in place, as there's nothing to overide them.

    Clutching at straws, you could try manually editing the policies (make a copy, edit the copy with notepad, rename the original).

    A blank *default* GPO has a machine folder (empty), User folder (empty) and a gpt.ini file with the following entry.

    [General]
    Version=0
    displayName=New Group Policy Object

    Now if you could work out which GPO was the default (hopefully by looking at the modified date), you may be able to replace it..... But we're clutching at straws!
    Last edited by Jiff Lemon; 14-06-2004 at 11:25 PM.

  15. #15
    Senior Member
    Join Date
    Aug 2003
    Posts
    508
    Thanks
    0
    Thanked
    0 times in 0 posts
    Ok, got it sorted...

    What I did was to rename the Policies directories from the workstation.

    Then, created a batch file which ran dcgpofix and gpudate (couldn't access a run command on the dc to do this)

    I put that batch file into the start menu of my Domain account on the DC (couldn't use any other hard-disk location because they were locked down).

    I ran the batch file on the DC and it seems to have worked...

    Thanks for the advice guys

  16. #16
    Oh no!I've re-dorkalated! Jiff Lemon's Avatar
    Join Date
    Jul 2003
    Location
    Sunny MK
    Posts
    2,504
    Thanks
    80
    Thanked
    44 times in 41 posts
    Whew!

    Now remember the golden rule....

    "Thou shalt not modify the default domain policy"

    if you've not already got it, get the group policy editor from MS

    Linky

    Make playing with Group policy a lot more fun.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. ADSL router modem 48 + del group buy anyone?
    By prehensile in forum Retail Therapy and Bargains
    Replies: 0
    Last Post: 13-05-2004, 09:00 PM
  2. Group LCD buy over at Moddin.net
    By Theo in forum Retail Therapy and Bargains
    Replies: 5
    Last Post: 27-02-2004, 09:06 AM
  3. Anyone heard about another shuttle disaster ?
    By Agent in forum General Discussion
    Replies: 20
    Last Post: 25-08-2003, 01:02 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •