Re: using secpol.msc on win2k3



Per your instructions, I downloaded and installed the Group Policy Management
Console. I went to Group Policy Management -> Forest -> Domains ->
domain.local -> Domain Controllers -> Default Domain Controller Policy ->
Settings -> Computer Configuration -> Window Settings -> Security Settings ->
Local Policies/User Rights Assignment. Right clicked Access this computer
from the network -> Edit. I get the following error:

Failed to open the Group Policy Object. You may not have appropriate rights.
Details: Logon failure: the user has not been granted the requested logon
type at this computer.

Almost the same error as before.


"Roger Abell [MVP]" wrote:

Well, you are really not using the most convenient tool

Oh, to answer you, on a domain controller you do use an AD based GPO,
not necessarily one of the two default GPOs though.

You should navigate via
www.microsoft.com/gp
to download GPMC and try (right click on to) editing the GPO from there.


"jerrydy" <jerrydy@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:2C94C88C-40B2-470C-87E2-A483ABB26785@xxxxxxxxxxxxxxxx
I have a domain controller running win2k3. I ran secpol.msc and under
Security Settings -> Local Policies -> User Rights Assignment -> Access
this
computer from the network Properties, I am unable to add any user or
group.
The checkbox for enabling this policy is not visible. I assume because
this
is a domain controller so I'm supposed to use "Domain Controller Security
Policy" tool instead. Can anybody verify that.

Here's the problem that I encounter. When I use Domain Controller Security
Policy, then go to Security Settings -> Local Policies -> User Rights
Assignment -> Access this computer from the network Properties and define
the
policy setting by adding users or groups, I get the error that "An
extended
error has occurred. Failed to save
\\domain.local\sysvol\domain.local\Policies\{...}\Machine\Microsoft\Windows
NT\SecEdit\GptTmpl.inf".

Well, I did try to use Explorer and go to \\domain.local\sysvol and I get
the error "\\domain.local\SYSVOL is not accessible. You might not have
permission to use this network resource...". If instead I use
\\server.domain.local\sysvol, then I'm able to drill down correctly.

Right now, the server has shared folders and none of the clients are able
to
access them. The only thing I remember doing between now and the last time
this was working was I updated the Domain Function Level and the Forest
Functional Level to Windows Server 2003. But I can't rollback so unless I
solve this, none of the clients can do map the shared drives.

Any help would be appreciated! Thanks!

-Jerry



.



Relevant Pages

  • Windows 2003R2 Group Policy Errors
    ... Policy from our oldest domain controller to other domain controllers. ... All servers are running Windows 2003 R2 32-bit standard edition. ... Group Policy was working fine for several months, ...
    (microsoft.public.windows.server.active_directory)
  • Re: EventID 1054 from Userenv for startup script
    ... in the right window "Group policy Inheritance tab", ... Those two contain the requirement to "Wait for network before ... where the startup script did run but the deployment GPO would not. ...
    (microsoft.public.windows.group_policy)
  • Re: Logon Scripts Acrossed VPN
    ... This error looks specific to the computer account rather than user account and I'm guessing its related to GP computer processing firing off before the network to the DC is available. ... Group Policy processing aborted. ... Scripts are a pain the you-know-what to troubleshoot but here are a few ...
    (microsoft.public.windows.group_policy)
  • Re: using secpol.msc on win2k3
    ... edit will be local, not using network login rights. ... Oh, to answer you, on a domain controller you do use an AD based GPO, ... The checkbox for enabling this policy is not visible. ...
    (microsoft.public.security)
  • Re: Failed to open the Group Policy Object
    ... Now gpotool dosent't detect any errors. ... But the initial error (Failed to open the Group Policy Object ... > domain controller default Group Policy for instance. ...
    (microsoft.public.security)