Re: Remove SID/User from a local Group Policy

From: Justin (j.searles_at_verizon.net)
Date: 03/10/05


Date: 10 Mar 2005 13:40:08 -0800

I had the "Local Policy Setting" unchecked. I've run secedit, and
rebooted but to no avail. The sids continue to hang around. The
"Effective Policy Setting" is always checked and grayed out. The
output from gpresuts is (slightly edited for security):

*******************************************************************************
*******************************************************************************

Microsoft (R) Windows (R) 2000 Operating System Group Policy Result
tool
Copyright (C) Microsoft Corp. 1981-1999

Created on Thursday, March 10, 2005 at 4:28:38 PM

Operating System Information:

Operating System Type: Server
Operating System Version: 5.0.2195.Service Pack 4
Terminal Server Mode: Remote Administration

###############################################################

  User Group Policy results for:

  Domain Name: DOMAIN
  Domain Type: Windows 2000
  Site Name: Default-First-Site-Name

  Roaming profile: (None)
  Local profile: C:\Documents and Settings\Administrator.DOMAIN

  The user is a member of the following security groups:

        DOMAIN\Domain Users
        \Everyone
        BUILTIN\Users
        BUILTIN\Administrators
        NT AUTHORITY\INTERACTIVE
        NT AUTHORITY\Authenticated Users
        \LOCAL

###############################################################

Last time Group Policy was applied: Thursday, March 10, 2005 at 3:33:59
PM

###############################################################

  Computer Group Policy results for:

  Domain Name: DOMAIN
  Domain Type: Windows 2000
  Site Name: Default-First-Site-Name

  The computer is a member of the following security groups:

        BUILTIN\Administrators
        \Everyone
        NT AUTHORITY\Authenticated Users

###############################################################

Last time Group Policy was applied: Thursday, March 10, 2005 at 3:34:55
PM
Group Policy was applied from: ipcs-dev4.DOMAIN.com

===============================================================

The computer received "Registry" settings from these GPOs:

        Local Group Policy

===============================================================
The computer received "Security" settings from these GPOs:

        Local Group Policy

===============================================================
The computer received "EFS recovery" settings from these GPOs:

        Local Group Policy

This is a pretty simple group of lab machines three machines in all

******************************************************************************
******************************************************************************

Does this tell us anything about whether the policy is being overriden.
 I did look through the domain policies and everything appeared to be
"Not Defined" I specifically check the "Log on as Service" policy and
I'm sure that one is "Not Defined" at the Domain Level. I've installed
these few machines myself and they are in their own forest. As far as
I know there are no overriding policies. How would I check at the next
level up (the OU)?

Thanks again for your time.
-Justin



Relevant Pages

  • Re: lockdown desktop without Group Policy
    ... Group Policy settings. ... Logon as an administrator ... Right-click on the GroupPolicy folder and Properties - Security ... and enter "Edit Group Policy" for the name ...
    (microsoft.public.windows.terminal_services)
  • Re: Routing and Remote Access
    ... If it still does not work, it could be a Local Group Policy ... > far as security policy if you are having problem accessing a Remote Access ... > server while logged onto it you may be lacking privileges. ...
    (microsoft.public.windows.server.security)
  • Windows Shortcut Keys and "ALT+TAB" not working because of GPO
    ... We've got an issue with a machine policy which prohibits us of using Windows ... Deny access to this computer from the network Support_388945a0, ... Policy Setting ...
    (microsoft.public.de.german.windowsxp.gruppen.richtlinien)
  • RE: Auditing Workstation logons from DC
    ... You have already configured Domain Security Settings for Audit account ... the both Default Domain Controllers Policy and Default Domain Security ... GPO may be overriding the audit policy setting that you configured. ...
    (microsoft.public.windows.server.sbs)
  • IPSec and Group Policy
    ... I am trying to use Group Policy to apply IPSec policy to an Organizational ... W2k domain, as the local administrator, and set the Local Security Policy to ...
    (microsoft.public.win2000.security)