Re: Security Templates

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 06/24/05


Date: Fri, 24 Jun 2005 07:27:11 -0700

Oh boy, am I ever glad Steve is back ! I completely overlooked
signifigance of mention this is W2k3.

I would in that case suggest using GPMC to back-up the most
heavily used (carrying the most policy settings) or the one into
which you are intending to import. This backup may then be
"cloned", i.e. imported (unlinked) under new names. To one
of these you may import. With the other of these you might
import the rollback obtained as Steve advised.

Now, here is where I would expect "got-ya" type things
might arise (if any), in preferences (the tattoo settings that
are not 'true policies"), in extensions like IPsec or Software
Restriction, or in adm extension settings (in other words,
the "mainline" true policy settings in Security section would
be handled well. So, just to be safe I would analyze with
the intended new template and then check that the GPO that
was built from the backup for potential use to roll back did
in fact have policy setting sufficient to reverse what the
analysis showed would be changed.

-- 
Roger Abell
Microsoft MVP (Windows  Security)
"News Microsoft" <thestig@nobody.com> wrote in message
news:esi9Wi$dFHA.2128@TK2MSFTNGP14.phx.gbl...
> Hi
>
> Is there any way of rolling back the installation of security templates on
> Windows 2003. I am about to deploy them to a live system after testing on
a
> test system bit would like some way of rolling back.
>
>
>


Relevant Pages

  • Re: XP Repairing System.
    ... neglecting the fact that the 'so called' security ... then run internet from non-admin account. ... can then utilises the security features and ADS of NTFS to secure itself ... policy settings not available for FAT32, ...
    (uk.comp.homebuilt)
  • Re: re-applying local security policy
    ... secedit /refreshpolicy will refresh local policy settings as well ... > additional local privileges (usually local administrator) on their Win ... > find ways to force application of domain / AD GPO security policies on ...
    (microsoft.public.win2000.security)
  • no mapping between account and security id
    ... Security policies are propagated with warning. ... After a while i searched in the local security policy settings, ... I cleared the checkbox of that SID " Local Policy ... but after a restart the Effective Policy Settings are still on that SID. ...
    (microsoft.public.win2000.security)
  • Re: Out of the box Security
    ... Drill in and find the security guidance papers, ... Windows Server 2003 Security Guide ... for very many policy settings. ...
    (microsoft.public.windows.server.active_directory)