Re: Local security settings - secedit

From: Glenn L (the.only(delete)_at_gmail.com)
Date: 11/27/04


Date: Fri, 26 Nov 2004 22:54:28 -0800


If the workstation has never had any changes made to the local, then you can
simply view C:\WINDOWS\security\templates\setup security.inf
This is the out of the box security template applied to all XP workstations.

-- 
Glenn L
CCNA, MCSE (2000,2003) + Security
"Steven L Umbach" <n9rou@N0sPaM-comcast.net> wrote in message 
news:iObpd.95395$5K2.65332@attbi_s03...
>I don't believe you can export the true local security settings of a domain
> computer. I found results similar to yours. For Windows 2003 when you are
> using the secedit /export command you really are exporting the "effective"
> settings for the computer's security policy . When you use the 
> /mergedpolicy
> switch you are exporting those security settings that are defined at the
> domain/OU level that are overriding the local settings. I suppose if you
> want to find the true local settings [other than password policy possibly]
> you could create an OU with block inheritance enabled on it and move your
> computer into it, refresh the Group Policy on the domain controller and
> reboot the domain computer you want to analyze.   --- Steve
>
>
> "ravi" <ravicreddy@gmail.com> wrote in message
> news:1101336638.982662.271510@f14g2000cwb.googlegroups.com...
>> Hello,
>>
>> Local security settings - secedit
>>
>> I am trying to export local security settings using secedit on windows
>> 2003.
>>
>> secedit /export /cfg local.inf /log local.log
>> secedit /export / mergedpolicy /cfg merged.inf /log merged.log
>>
>> My understanding is the first call gives local settings even if the
>> server is connected to domain and domain policy settings are
>> overriding.
>>
>> Second command gives the merged polices from domain based GPOs. The
>> number of settings are differenr in both cases, but the values always
>> seems to be domain values.
>>
>> Example:  If I have minimum password length set to 8 chars on local and
>> 10 chars on domain, both the above commands gives 10 chars.
>>
>> I take the server out of domain (make it a stand alone server) then I
>> get a value of 8 on both cases.
>>
>> Any one else see this behavior? How do I dump settings from local
>> secedit.sdb?
>>
>> Thanks
>>
>> Ravi
>>
>
> 


Relevant Pages

  • Re: CompanyWeb - Password Dialogue Box in Terminal Server only
    ... Configure trusted sites and security settings of IE using policy ... one XP workstation with the problematic user account and setup RDP session ...
    (microsoft.public.windows.server.sbs)
  • Group Policy Case Solved
    ... I began with the "Security Options" under the Computer ... I modified the group policy from my Windows XP Pro workstation using ... many more settings than Windows 2000 does; ...
    (microsoft.public.win2000.security)
  • RE: Remote Installation Services, DoOldStyleDomainJoin=Yes
    ... It appears that the policy had been set previoulsy but when the policy was ... > SP1 introduced additonal RPC and SAMR security and during the upgrade SP1 ... > updates that SP1 will be over written and thus the workstation will not have ... >> provide domain account credentials to join the computer account to the ...
    (microsoft.public.windows.group_policy)
  • Re: Loopback issues
    ... policy to be interrupted by changes in ACLing (something I ... Microsoft MVP (Windows Security) ... > I finally got this to work on a Windows 2000 workstation and a different ... >> none of the User Configuraiton portion of the policy is being applied. ...
    (microsoft.public.windows.group_policy)
  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... Server Security and Auditing Policy ... This list only includes links in the domain of the GPO. ... The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)