Policy change kills access to template

From: Peter J. Persing (peter_at_persing.org)
Date: 10/12/03


Date: Sun, 12 Oct 2003 13:58:55 -0600

On a Windows 2003 domain controller, if I go into either Domain Security
Policy or Domain Controller Security Policy, local policies, and make ANY
changes in Audit Policies, User Rights Assignment or Security Options the
changes appear to complete successfully. But if I close the snap-in, and
reopen it I get a message "Windows cannot open the template file". In the
event log I get Event 1001 from SecCli that says "Security policy cannot be
propagated. Cannot access the template. Error code = -536870656". The error
message then gives the path to the relevant GptTmpl.inf file, which I can
access just fine. It does not appear to be corrupt, and in fact before
making any changes, all existing security policies are applied just fine.

When I say ANY changes can cause this, I mean something as minor as removing
or adding an audit policy.

Anyone run into this before?



Relevant Pages

  • RE: Security Policy-Please help
    ... your Masters in Systems & Network Security, ... Before you begin writing policies, you deffinetly want to make sure you've ... SANS Security Policy Project at http://www.sans.org/resources/policies/. ... L0phtcrack is one of the better tools for testing password ...
    (Security-Basics)
  • Re: MICROSOFT_AUTHENTICATION_PACKAGE
    ... Is the security option "additional restrictions for anonymous connections" - ... changes to the Local Security Policy of a domain controller, ... then examine the settings in the Local Security ... domain machine if you changed domain security policy. ...
    (microsoft.public.win2000.security)
  • Re: CIFS and Windows Server 2003
    ... digital signing in both default domain policies. ... Choose Domain Controller Security Policy | Local Policies | Security ... > Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: auditing logging on
    ... of security policy for a domain controller is in the Domain Controller Security ... >> logs for failed events after you enable auditing for it. ...
    (microsoft.public.win2000.security)
  • Re: Password Problem
    ... explicit anonymous permissions is not enable in the Local Security Policy on any ... domain controller or in the Domain Controller Security Policy. ... > permissions to change their passwords. ...
    (microsoft.public.win2000.security)