Group Policy Permissions Issue

Archived from groups: microsoft.public.win2000.security (More info?)

After a crash do to a group policy being edited, I want to make my group
policies read only.

I made it so everyone only had read rights to the security of two group
policies, in my domain.

I assumed that as the owner - the Domain or Enterprise Admin would be able
to edit the permissions, like it is with the file system.

Opps

Seems like I can not alter the permissions, or delete the Group Policies
from my list of Group Policies. Even as the owner of the Policy.

Any way to reset the permissions of a Group Policy so the Domain/Enterprise
admin could edit the file again?
3 answers Last reply
More about group policy permissions issue
  1. Archived from groups: microsoft.public.win2000.security (More info?)

    You always can use the dsacls command but it may be easier to first try
    using AD Users and Computers. First make sure advanced features are selected
    in view. The go to system - policies to find all your Group Policies. Then
    right click them and select properties where you can use the security tab to
    hopefully change permissions back to what you need. You will only see the
    GUID for each Group Policy. You can use the support tool gpotool /v to find
    the friendly names of each policy if you need such.. --- Steve


    "James Roper, MCSE" <JamesRoperMCSE@discussions.microsoft.com> wrote in
    message news:8FA62424-3BFE-4023-B65B-D60B37C7A393@microsoft.com...
    > After a crash do to a group policy being edited, I want to make my group
    > policies read only.
    >
    > I made it so everyone only had read rights to the security of two group
    > policies, in my domain.
    >
    > I assumed that as the owner - the Domain or Enterprise Admin would be able
    > to edit the permissions, like it is with the file system.
    >
    > Opps
    >
    > Seems like I can not alter the permissions, or delete the Group Policies
    > from my list of Group Policies. Even as the owner of the Policy.
    >
    > Any way to reset the permissions of a Group Policy so the
    > Domain/Enterprise
    > admin could edit the file again?
    >
  2. Archived from groups: microsoft.public.win2000.security (More info?)

    Using Active Directory Users and Computers/System/Policies was the trick.

    Thanks
  3. Archived from groups: microsoft.public.win2000.security (More info?)

    Glad to here that and I want to add that unless users/computers have "apply"
    permission for the Group Policy that the policy will not apply to them.
    System State backups of a domain controller will backup all the Group
    Policies along with other AD info and then you could always do an
    authoritative restore if you have problems in the future due to a corrupted
    or otherwise mangled policy. --- Steve


    "James Roper, MCSE" <JamesRoperMCSE@discussions.microsoft.com> wrote in
    message news:622B20B9-91E5-4625-9E81-DBA46F81D851@microsoft.com...
    > Using Active Directory Users and Computers/System/Policies was the trick.
    >
    > Thanks
    >
Ask a new question

Read More

Policy Permissions Windows