Re: Local Policy Update Using Remote Registry Edit



Keep in mind that domain profile settings apply only when domain computer
are connected to a network where they can find and access a domain
controller. You can edit local Group Policy remotely by selecting the mmc
snapin for Group Policy and selecting - another computer. Of course you
need to be a local administrator on the computer you want to do this to. I
find it always best to edit Group Policy instead of registry settings. You
can edit a registry setting [it does NOT edit Group Policy] and it should
work until the computer reapplies it's Group Policy settings if that setting
is defined. Group Policy administrative template registry settings are
stored in the \Windows\system32\grouppolicy\user or machine\registry.pol
file.

Steve


"Robert Lindholm" <RobertLindholm@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:CFC05AEF-0B48-4E99-AB13-BC44510BD655@xxxxxxxxxxxxxxxx
I'm trying to remotely add an IP address to the Remote Administration
settings [domain/local] on several Windows XP XP2 [with firewall enabled]
on
my network so I can make some remote adjustments to the Windows firewall
using "netsh" to ultimately run an install executable for a new AV
software
agent. I found what I believe to be the appropriate Registry keys
associated
with these network settings [see below] and have been able to remotely
update
the Registry, but this hasn't updated the local policy on the computer.
I've
tried performing an "gpupdate" and rebooting the system. Obviously I'm
missing something or there are additional Registry keys that need to be
edited or some other mechanism to update the local policy by editing the
Registry unless this is a unidirectional process [e.g. local policy
edit ->
Registry change only, not vice-versa]. I'm trying to avoid having to
locally
edit each workstation to make these changes, which brings up a few
questions:

1) Is there a way to remotely edit the local group policy of a Windows XP
computer remotely over the network [without AD]?

2) Will remote editing of the Registry alter the local group policy of a
machine and if so how is this accomplished?

Your suggestions are greatly appreciated...

Bob

P.S. Here are the Registry keys I edited:

Domain Policy

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings!Enabled,
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings!RemoteAddresses

Local Policy

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\RemoteAdminSettings!Enabled,
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\RemoteAdminSettings!RemoteAddresses
--
Robert Lindholm
University of Rcohester


.



Relevant Pages

  • Re: Applying zone settings on Pop-up Blocker
    ... I checked the registry and the settings is there! ... > Troubleshooting Group Policy in Microsoft? ...
    (microsoft.public.windows.group_policy)
  • Re: IE Advanced/Security settings
    ... I don't know of any templates offhand but it is possibly to apply changes ... to the registry via Group Policy startup or logon scripts once you find the ... registry changes that apply the desired setting. ... such a .reg file for a couple advanced security settings - enabling that ...
    (microsoft.public.windows.group_policy)
  • Re: Grpedit.msc from bootable cd
    ... On a working Windows XP machine snap the registry then do the changes in the Group Policy then re-snap the registry then do a compare for the differences between the two snaps. ... I think in the local group policy was the "local login" key disabled :-( I tried to reset this setting with ERD 2005 but I cant find this key in the registry. ...
    (microsoft.public.windowsxp.basics)
  • Re: Group Policy is preventing me from turning on Windows Firewall
    ... Most likely some malware or spyware has configured such via a registry mod ... Group Policy that will reverse what the registry ... The registry keys to add to disable Windows Firewall for both the domain and ... I went into the settings to ...
    (microsoft.public.windowsxp.security_admin)
  • Re: OneCare really pisses me off
    ... The normal interface to access the Group Policy settings is Gpedit.msc which is available on XP Pro, ... Almost all program installations make changes in the registry, and you don't give permisson each time. ... when you agree to allow the software to install. ...
    (microsoft.public.windowsxp.general)