Tom's Hardware > Forum > Windows 2000/NT > Windows 2000/NT General Discussion > Manual Update Group Policy on Windows 2000 Server

Manual Update Group Policy on Windows 2000 Server

Forum Windows 2000/NT : Windows 2000/NT General Discussion - Manual Update Group Policy on Windows 2000 Server

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Archived from groups: microsoft.public.win2000.group_policy (More info?)

 

I recently created a group policy that is applicable to machines via
secuirty group membership in Active Directory. So, for example I have
a Group Policy named GP1 associated with a container in Active
Directory. Additionally, I created group that servers have to be a
member of in order to receive the Group Policy settings.

I've added several servers to the group which makes the group policy
applicable to them. However, the GPO settings are applied to the
servers after a reboot. Is there a way to manually push the new group
policy to the servers without rebooting them? The servers are Windows
2000 boxes and I've tried running secedit /refreshpolicy
MACHINE_POLICY /enforce to no avail.

Thanks.
-n

Sponsored Links
Register or log in to remove.

Archived from groups: microsoft.public.win2000.group_policy (More info?)

 

Not that I know of. The machines don't have the group membership in their
session token and this is necessary to access thte GPO.

--
--
Brian Desmond
Windows Server MVP
desmondb@payton.cps.k12.il.us

Http://www.briandesmond.com


"nasteric" <nasteric@yahoo.com> wrote in message
news:e651d8ae.0410231548.361eca51@posting.google.com...
> I recently created a group policy that is applicable to machines via
> secuirty group membership in Active Directory. So, for example I have
> a Group Policy named GP1 associated with a container in Active
> Directory. Additionally, I created group that servers have to be a
> member of in order to receive the Group Policy settings.
>
> I've added several servers to the group which makes the group policy
> applicable to them. However, the GPO settings are applied to the
> servers after a reboot. Is there a way to manually push the new group
> policy to the servers without rebooting them? The servers are Windows
> 2000 boxes and I've tried running secedit /refreshpolicy
> MACHINE_POLICY /enforce to no avail.
>
> Thanks.
> -n

Reply to Anonymous

Archived from groups: microsoft.public.win2000.group_policy (More info?)

 

Brian is right. The server does not have its new group SID in its token.
However, you can delete all machine account kerberos tickets, then force the
update.
But this requires getting kerbtray or klist (resource kit tools) on the
server, then setup a script to run in the system context to delete the
tickets.
Much easier to reboot IMHO


"Brian Desmond [MVP]" <desmondb@payton.cps.k12.il.us> wrote in message
news:eHiTFrXuEHA.2804@TK2MSFTNGP14.phx.gbl...
> Not that I know of. The machines don't have the group membership in their
> session token and this is necessary to access thte GPO.
>
> --
> --
> Brian Desmond
> Windows Server MVP
> desmondb@payton.cps.k12.il.us
>
> Http://www.briandesmond.com
>
>
> "nasteric" <nasteric@yahoo.com> wrote in message
> news:e651d8ae.0410231548.361eca51@posting.google.com...
>> I recently created a group policy that is applicable to machines via
>> secuirty group membership in Active Directory. So, for example I have
>> a Group Policy named GP1 associated with a container in Active
>> Directory. Additionally, I created group that servers have to be a
>> member of in order to receive the Group Policy settings.
>>
>> I've added several servers to the group which makes the group policy
>> applicable to them. However, the GPO settings are applied to the
>> servers after a reboot. Is there a way to manually push the new group
>> policy to the servers without rebooting them? The servers are Windows
>> 2000 boxes and I've tried running secedit /refreshpolicy
>> MACHINE_POLICY /enforce to no avail.
>>
>> Thanks.
>> -n
>
>

Reply to Anonymous

Archived from groups: microsoft.public.win2000.group_policy (More info?)

 

Thanks all for your help. That sounds right!


"Brian Desmond [MVP]" <desmondb@payton.cps.k12.il.us> wrote in message news:<eHiTFrXuEHA.2804@TK2MSFTNGP14.phx.gbl>...
> Not that I know of. The machines don't have the group membership in their
> session token and this is necessary to access thte GPO.
>
> --
> --
> Brian Desmond
> Windows Server MVP
> desmondb@payton.cps.k12.il.us
>
> Http://www.briandesmond.com
>
>
> "nasteric" <nasteric@yahoo.com> wrote in message
> news:e651d8ae.0410231548.361eca51@posting.google.com...
> > I recently created a group policy that is applicable to machines via
> > secuirty group membership in Active Directory. So, for example I have
> > a Group Policy named GP1 associated with a container in Active
> > Directory. Additionally, I created group that servers have to be a
> > member of in order to receive the Group Policy settings.
> >
> > I've added several servers to the group which makes the group policy
> > applicable to them. However, the GPO settings are applied to the
> > servers after a reboot. Is there a way to manually push the new group
> > policy to the servers without rebooting them? The servers are Windows
> > 2000 boxes and I've tried running secedit /refreshpolicy
> > MACHINE_POLICY /enforce to no avail.
> >
> > Thanks.
> > -n

Reply to Anonymous
Tom's Hardware > Forum > Windows 2000/NT > Windows 2000/NT General Discussion > Manual Update Group Policy on Windows 2000 Server
Go to:

There are 1116 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them