Well, if you have accidentally locked yourself out of a Windows 2000 or Windows 2003 Server Group Policy, don’t worry, you can easily undo it!
I have been using Windows 200x in production environments since 1998 and up until November 2003 never made the obvious mistake of going into the SECURITY TAB of a Group Policy, clicked ENTERPRISE ADMINS, FULL CONTROL, DENY… note very bright. I should have simply clicked DENY for APPLY GROUP POLICY. I knew I was stuck as soon as I clicked OK.
Most of the following detail was taken from an excellent MS Newsgroup Posting so I will not take credit for it.
Use the DSACLS tool included in the Support Tools for Windows 2000 and Windows Server 2003 (which can be found on the Windows CD), to remove the Deny Access permissions from the Domain Administrators group. You must know the distinguished name (also known as DN) of the GPO to use this tool. Use the ADSIEdit.msc tool that is included in the Support Tools for Windows 2000 and Windows Server 2003, to determine the distinguished name of the GPO in Active
Directory.
The examples below assume you want to reset the permissions for Domain Admins. In my case I needed to correct Enterprise Admins, so I substituted the phrase Enterprise Admins for Domain Admins. Obviously, you can adjust this to fit your situation… just enter the exact name of the group you screwed over:
To reset permissions:
<Domain_Namecontainer\CN=System\CN=Policies
cn={f5e14b83-0181-437e-878c-8d16cb945d68},cn=policies,cn=system,dc=mybigdomain,dc=com
NOTE: The restricted policy is displayed with a notepad icon; the other policies are displayed with folder icons.
dsacls <distinguished_name/R “<domain_name>\domain admins”
For example:
dsaclscn={f5e14b83-0181-437e-878c-8d16cb945d68},cn=policies,cn=system,dc=mybigdomain,dc=com /R “mybigdomain\Domain Admins”
dsacls <distinguished_name/G “<domain_name>\domain admins”:GA
Winnt\Sysvol\Sysvol\<Domain_name>\Policies
folder. The GUID for the restricted GPO is listed in this folder.
For more information, please refer to the following articles:
294257 “Failed to Open the Group Policy Object”
http://support.microsoft.com/?id=294257
314203 How to Install the Windows Support Tools from a Command Prompt
http://support.microsoft.com/?id=314203
This website uses cookies.