Bypass Domain GPO when not connected to network?

From: Ross Luker (ross_luker_at_hotmail.com)
Date: 10/25/05


Date: 25 Oct 2005 01:36:08 -0700

Hi,

We have a problem where the "Log on locally" entry in the Default
Domain GPO was messed with (an entry was put in without specifying
other users). This was quickly fixed, as soon as we noticed users
being denied the right to log on. However, I've got several users that
were connected to our VPN when the GPO changed, and now when they
reboot they're denied access to the machine. Obviously, just
connecting the PC to the network will refresh to the working GPO, but
several users are in a different country - is there a way I can get
them logged in to the machine so that they can access the VPN and
refresh group policy?

TIA
Ross



Relevant Pages

  • Re: GP for setting the user runonce
    ... logfile when it sucessfully completes and I can then move them up the ou ... tree a notch where the runonce GPO doesn't apply. ... Logging is working, GPO is working. ... The trick on "runoce" is, that the entry is deleted, after process. ...
    (microsoft.public.windows.group_policy)
  • Re: What is the difference between "legacy" & "windows 2000" logon scripts
    ... Entry in the properties of the Userobjekt on Tab "Profile" ... or the logon/logoff folder of the GPO. ... To have a "single" store for all scripts, you can store GPO based scripts ...
    (microsoft.public.windows.group_policy)
  • Re: Maximum password age - Need Proof
    ... He wants something like an entry in Event Viewer showing the forcing of a ... Make a similar GPO and set the maximum password age very low, ...
    (microsoft.public.win2000.active_directory)
  • Re: XP SP2 ADM errors
    ... "The following entry in the [strings] section is too long and has been ... truncated" error message when you try to modify or to view GPOs in Windows ... > the gpo setting. ...
    (microsoft.public.windowsxp.setup_deployment)
  • Group membership / Kerberos tickets
    ... The obvious solution is to reboot the servers before linking the GPO. ... We would of course prefer to avoid rebooting dozens of servers, ... Aside from our current predicament, this seems to be a bit of a security hole-machines can actively receive GPOs to which they have been denied access, long after they are denied that access. ...
    (Focus-Microsoft)