Re: Administrator Denied Access to Local Security Policy

From: Danny Thames (dthames@carolina.rr.com)
Date: 07/07/02


From: "Danny Thames" <dthames@carolina.rr.com>
Date: Sun, 07 Jul 2002 01:47:14 GMT


See http://support.microsoft.com/search/preview.aspx?scid=kb;en-us;Q263166

After that, to keep policies from applying to the admin do the following
(there's another recommended way from MS, but this works easier for me):

Just deny the admin read access to the Group Policy folder (hidden) in
winnt|system32. Should you have to go back into Gpedit, you need to take
that checkmark off and click okay, no reboot involved.



Relevant Pages

  • Re: MMC - admin locked out too
    ... just use the Deny trick to exempt ... from an admin account before it can edit policy, ... > Limit access to Regedit, MMC, command line, etc. & ... > restrict such items to Administrators only. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: deleting users my document folders after disabling redirection
    ... Kinda like the modern day 'logon locally, or deny logon localy", eh. ... that changing ownership is a right that could be taken away from ... Logging in as administrator and following your directions I still ... Why would my system admin account be restricted? ...
    (microsoft.public.windows.server.sbs)
  • Re: Windows 2000 - Local policy - deny logon loccaly
    ... Map the Admin$ or C$ share as an admin, then set a Deny ... of Full for Administrators on system32\GroupPolicy in the ... > Local policy settings -- deny logon locally. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: ***Admin LockedOut of GPEDIT.MSC***
    ... access the NTFS security dialog for system32\GroupPolicy ... set a Deny of Full Control for Administrators on this folder ... log back in as an admin ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Moving DCs From Default OU ?
    ... if I'm an admin (domain admins, administrators, enterprise admin, ... etc) you can deny whatever you want to. ... although I don't have permissions I can change them back so I do ...
    (microsoft.public.windows.server.active_directory)