<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

	<channel>
		<title>GPTalk Mailing List</title>
		<link>http://www.gpoguy.com/MailList/tabid/58/forumid/1/view/topics/Default.aspx</link>
		<description>The Group Policy Mailing list from GPOGUY</description>
		<language>en-US</language>
		<generator>ActiveForums  3.6</generator>
		<copyright>Copyright 2009 by GPOGUY.COM</copyright>
		<webMaster>darren@gpoguy.com</webMaster>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/GptalkMailingList" type="application/rss+xml" /><feedburner:browserFriendly></feedburner:browserFriendly><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
			<title>[gptalk] GPO Backgroun Images (UNCLASSIFIED)</title>
			<description>Classification:  UNCLASSIFIED  &lt;br&gt; Caveats: NONE &lt;br&gt;  &lt;br&gt; Hi to all, &lt;br&gt;  &lt;br&gt; How can I force a standard background image I created through GPO? &lt;br&gt;  &lt;br&gt; Thanks to all and I hope everyone has a great Weekend! &lt;br&gt;  &lt;br&gt; Gregory T Maxwell &lt;br&gt; System Administrator &lt;br&gt; Network Enterprise Centert (NEC) &lt;br&gt; Fort Huachuca, AZ  &lt;br&gt; (520)533-2393 &lt;br&gt;  &lt;br&gt; https://ice.disa.mil/index.cfm?fa=service_provider_list&amp;site_id=277&amp;serv &lt;br&gt; ice_category_id=34 &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Classification:  UNCLASSIFIED  &lt;br&gt; Caveats: NONE &lt;br&gt;  &lt;br&gt; </description>
			<link>http://www.gpoguy.com/MailList/tabid/58/forumid/1/postid/1245/view/topic/Default.aspx</link>
			<author>gtmaxwell</author>
			<pubDate>Fri, 02 Oct 2009 21:27:03 GMT</pubDate>
		</item>
		<item>
			<title>[gptalk] IE GPO - remove toobar</title>
			<description>How can I remove this tool bar and all the icons... &lt;br&gt;  &lt;br&gt; [cid:image001.png@01CA4353.2F117420] &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ============================================================================== &lt;br&gt; CONFIDENTIALITY NOTICE: This email contains information from the sender that may be CONFIDENTIAL, LEGALLY PRIVILEGED, PROPRIETARY or otherwise protected from disclosure. This email is intended for use only by the person or entity to whom it is addressed. If you are not the intended recipient, any use, disclosure, copying, distribution, printing, or any action taken in reliance on the contents of this email, is strictly prohibited. If you received this email in error, please contact the sending party by reply email, delete the email from your computer system and shred any paper copies. &lt;br&gt;   &lt;br&gt; Note to Patients: There are a number of risks you should consider before using e-mail to communicate with us. See our Privacy Policy and Henry Ford My Health at www.henryford.com for more detailed information. If you do not believe that our policy gives you the privacy and security protection you need, do not send e-mail or Internet communications to us. &lt;br&gt;  &lt;br&gt; ============================================================================== &lt;br&gt;  &lt;br&gt; </description>
			<link>http://www.gpoguy.com/MailList/tabid/58/forumid/1/postid/1231/view/topic/Default.aspx</link>
			<author>mdzikowski</author>
			<pubDate>Fri, 02 Oct 2009 16:29:13 GMT</pubDate>
		</item>
		<item>
			<title>[gptalk] Group Policy for PST Size Limit</title>
			<description>Hi, &lt;br&gt;  &lt;br&gt; I want to deploy a policy to restrict Outlook PST size to 2 GB after that a new PST should be created automatically &amp; the delivery should be set to that PST. Because in some cases I have seen PST may corrupt after 3-4 GB. Kindly tell me how can I do this. &lt;br&gt;  &lt;br&gt; Regards, &lt;br&gt;  &lt;br&gt; Dhiraj &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt; This email is confidential and intended only for the use of the individual or entity named above and may contain information that is privileged. If you are not the intended recipient, you are notified that any dissemination, distribution or copying of this email is strictly prohibited. If you have received this email in error, please notify us immediately by return email or telephone and destroy the original message. - This mail is sent via Sony Asia Pacific Mail Gateway.. &lt;br&gt;  &lt;br&gt; </description>
			<link>http://www.gpoguy.com/MailList/tabid/58/forumid/1/postid/1222/view/topic/Default.aspx</link>
			<author>DhirajHaritwal</author>
			<pubDate>Fri, 02 Oct 2009 11:42:54 GMT</pubDate>
		</item>
		<item>
			<title>Re: [gptalk] Domain Admins unable to manage workstations - group / 
 local policy strangeness</title>
			<description>I've attached a copy of the report. &lt;br&gt;  &lt;br&gt; 2009/10/2 Darren Mar-Elia &amp;lt;darren@sdmsoftware.com&amp;gt; &lt;br&gt;  &lt;br&gt; &amp;gt;  OK. Then something is definitely screwed up. Can you post the RSOP report &lt;br&gt; &amp;gt; for one of these machines with the domain admin user logging in? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Darren &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* gptalk-owner@lists.gpoguy.com [mailto: &lt;br&gt; &amp;gt; gptalk-owner@lists.gpoguy.com] *On Behalf Of *Peter Gough &lt;br&gt; &amp;gt; *Sent:* Thursday, October 01, 2009 5:25 PM &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; *Subject:* Re: [gptalk] Domain Admins unable to manage workstations - &lt;br&gt; &amp;gt; group / local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; These are brand new machines. We're building them using the same install &lt;br&gt; &amp;gt; media we've used previously and then joining them to our domain. Nothing in &lt;br&gt; &amp;gt; this part of our process has changed. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/2 Darren Mar-Elia &amp;lt;darren@sdmsoftware.com&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; It depends upon how the loopback policy is setup (i.e. where its linked and &lt;br&gt; &amp;gt; whether its security-group filtered) but if you don’t see it, that’s not the &lt;br&gt; &amp;gt; issue. Let me ask this. You said earlier in the thread that this is only &lt;br&gt; &amp;gt; affecting new machines that you join to the domain? Where did these machines &lt;br&gt; &amp;gt; come from? Were they in another AD domain? If so, what you may be seeing is &lt;br&gt; &amp;gt; some lingering policies that were implemented in that original domain. I’ve &lt;br&gt; &amp;gt; seen this problem before and its ugly. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Darren &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* gptalk-owner@lists.gpoguy.com [mailto: &lt;br&gt; &amp;gt; gptalk-owner@lists.gpoguy.com] *On Behalf Of *Peter Gough &lt;br&gt; &amp;gt; *Sent:* Thursday, October 01, 2009 4:16 PM &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; *Subject:* Re: [gptalk] Domain Admins unable to manage workstations - &lt;br&gt; &amp;gt; group / local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I've checked and there's definitely no loopback enabled on any of my &lt;br&gt; &amp;gt; policies. If there was wouldn't this affect all machines anyway? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/2 Darren Mar-Elia &amp;lt;darren@sdmsoftware.com&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Another thing to look into Peter—make sure you don’t have loopback enabled &lt;br&gt; &amp;gt; on these computers at some point. This could be causing the effect you’re &lt;br&gt; &amp;gt; seeing. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Darren &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; **** &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Darren Mar-Elia &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; CTO &amp; Founder &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; SDM Software, Inc. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; "*The Group Policy Experts"* &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; www.sdmsoftware.com &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Founder— www.gpoguy.com – The Group Policy Resource Site &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Blog: www.sdmsoftware.com/blog &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Twitter: www.twitter.com/grouppolicyguy &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* gptalk-owner@lists.gpoguy.com [mailto: &lt;br&gt; &amp;gt; gptalk-owner@lists.gpoguy.com] *On Behalf Of *Peter Gough &lt;br&gt; &amp;gt; *Sent:* Thursday, October 01, 2009 7:07 AM &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Subject:* Re: [gptalk] Domain Admins unable to manage workstations - &lt;br&gt; &amp;gt; group / local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Thanks guys. I'm off to bed now (00:06 in Brisbane having just watched last &lt;br&gt; &amp;gt; week's MotD &amp;lt;http://en.wikipedia.org/wiki/MOTD&amp;gt; (I'm a Pom&amp;lt;http://en.wikipedia.org/wiki/Alternative_words_for_British#Pommy&amp;gt;!)). &lt;br&gt; &amp;gt; I'll try out your suggestions tomorrow and let you know how I get on. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/1 Tim Bolton &amp;lt;jsclmedave@gmail.com&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; This link may help &lt;br&gt; &amp;gt; http://www.windowsnetworking.com/articles_tutorials/Resultant-Set-Policy-Queries-GPRESULT.html &lt;br&gt; &amp;gt; Have not looked at any differences - if any - in 2008 as of yet. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Tim Bolton &lt;br&gt; &amp;gt; 148 2nd Street North &lt;br&gt; &amp;gt; Central City Iowa, 52214 &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Microsoft Certified IT Professional &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; On Thu, Oct 1, 2009 at 8:12 AM, Peter Gough &amp;lt;pmgough@gmail.com&amp;gt; wrote: &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Wow! Hadn't realised GP Preferences weren't displayed when I ran RSoP on &lt;br&gt; &amp;gt; the box itself, although I wish I'd noticed! &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I'm at home at the moment (it's 23:10 in Brisbane!) but are you suggesting &lt;br&gt; &amp;gt; running something like: &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; gpresult /s \\myproblemcomputer /v ... from my Server 2008? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I'll give it a go tomorrow morning. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Thanks, &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/1 Andrew McHale &amp;lt;Andrew.McHale@synergix.co.uk&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Hi Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; If you’re applying GP Preferences to an XP machine you won’t see the &lt;br&gt; &amp;gt; results of that in an RSoP report ran on that machine as it can’t display &lt;br&gt; &amp;gt; GPP settings. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Try running GPResult for the problematic machine, but from a 2008 machine &lt;br&gt; &amp;gt; to get a true picture of all the settings being applied. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Andrew &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* Peter Gough [mailto:pmgough@gmail.com] &lt;br&gt; &amp;gt; *Sent:* 01 October 2009 13:39 &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Subject:* Re: [gptalk] Domain Admins unable to manage workstations - &lt;br&gt; &amp;gt; group / local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The only other thing I can think of that's changed recently is that we've &lt;br&gt; &amp;gt; started managing policies from a Windows Server 2008 box to take advantage &lt;br&gt; &amp;gt; of the Group Policy Preference stuff. Would that have any impact? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/1 Peter Gough &amp;lt;pmgough@gmail.com&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I don't believe that's the case. The image we're currently using is fairly &lt;br&gt; &amp;gt; new but we've installed an old image on a couple of workstations to see if &lt;br&gt; &amp;gt; this is the issue and the same problem occurs. We've also setup a total &lt;br&gt; &amp;gt; vanilla-build workstation from our original XP SP2 disks and again we're &lt;br&gt; &amp;gt; seeing the same issue. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; This seems to be an active directory / group policy thing rather than a &lt;br&gt; &amp;gt; workstation specific problem. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The thing that's got me baffled is that the results we're getting from &lt;br&gt; &amp;gt; running RSoP against the machine don't reflect what we're experiencing on &lt;br&gt; &amp;gt; the ground. RSoP says everything is normal but domain admins are still &lt;br&gt; &amp;gt; unable to login to a machine and run services.msc (for example). &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/1 Martin Hugo &amp;lt;Martin_Hugo@hboe.org&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Is it in the local policies of your image? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Martin T. Hugo &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Network Administrator &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Hilliard City Schools &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 614-921-7102 (Ph) &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 614-771-7243 (Fax) &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Error! Filename not specified.*Think before you print &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* gptalk-owner@lists.gpoguy.com [mailto: &lt;br&gt; &amp;gt; gptalk-owner@lists.gpoguy.com] *On Behalf Of *Peter Gough &lt;br&gt; &amp;gt; *Sent:* Thursday, October 01, 2009 2:36 AM &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; *Subject:* [gptalk] Domain Admins unable to manage workstations - group / &lt;br&gt; &amp;gt; local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I've got a bit of a strange problem which I've been totally unable to &lt;br&gt; &amp;gt; resolve. Essentially what's happening is that when I join a workstation to &lt;br&gt; &amp;gt; our Windows Server 2003 domain the domain admins are affected by our &lt;br&gt; &amp;gt; restrictive group policies and we are unable to manage the machines. For &lt;br&gt; &amp;gt; example a domain admin is unable to launch regedit, manage services etc. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; We restrict this sort of stuff for our regular users but currently on any &lt;br&gt; &amp;gt; new workstations we join to the domain *all* domain user accounts are being &lt;br&gt; &amp;gt; affected. Interestingly group policy settings appear to be applied correctly &lt;br&gt; &amp;gt; on existing workstations. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The only 'fix' I've found is to login as a local admin, launch group policy &lt;br&gt; &amp;gt; for the local machine and navigate to [User Config / Admin Templates / &lt;br&gt; &amp;gt; System / Prevent access to registry editing tools]. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I then change this setting from its default 'Not Configured' state to &lt;br&gt; &amp;gt; 'Disabled', hit apply, then change it back again to 'Not Configured' and hit &lt;br&gt; &amp;gt; apply and suddenly domain admins can run regedit and standard domain users &lt;br&gt; &amp;gt; can't. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; In order to get access to some of the other restricted stuff I have to &lt;br&gt; &amp;gt; login as a local admin, navigate to [User Config / Admin Templates / Windows &lt;br&gt; &amp;gt; Components / Microsoft Management Console / Restrict users to the explicitly &lt;br&gt; &amp;gt; permitted list of snap-ins] and again toggle the settings. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The change happens even before I move the computer object into any of our &lt;br&gt; &amp;gt; sub OUs so none of our restrictive policies should be applied at this point. &lt;br&gt; &amp;gt; When I run an RSoP against the machine it tells me that only the Default &lt;br&gt; &amp;gt; Domain Policy is applied (which doesn't contain any of our restrictive &lt;br&gt; &amp;gt; policies) and that the Local Policy isn't applied because it is empty. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Any thoughts on why this might be happening or what I can do next to &lt;br&gt; &amp;gt; troubleshoot? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Thanks, &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt;  &lt;br&gt; </description>
			<link>http://www.gpoguy.com/MailList/tabid/58/forumid/1/postid/1219/view/topic/Default.aspx</link>
			<author>pmgough</author>
			<pubDate>Fri, 02 Oct 2009 05:49:59 GMT</pubDate>
		</item>
		<item>
			<title>RE: [gptalk] Domain Admins unable to manage workstations - group /
 local policy strangeness</title>
			<description>OK. Then something is definitely screwed up. Can you post the RSOP report for one of these machines with the domain admin user logging in? &lt;br&gt;  &lt;br&gt; Darren &lt;br&gt;  &lt;br&gt; From: gptalk-owner@lists.gpoguy.com [mailto:gptalk-owner@lists.gpoguy.com] On Behalf Of Peter Gough &lt;br&gt; Sent: Thursday, October 01, 2009 5:25 PM &lt;br&gt; To: gptalk@lists.gpoguy.com &lt;br&gt; Subject: Re: [gptalk] Domain Admins unable to manage workstations - group / local policy strangeness &lt;br&gt;  &lt;br&gt; These are brand new machines. We're building them using the same install media we've used previously and then joining them to our domain. Nothing in this part of our process has changed. &lt;br&gt; 2009/10/2 Darren Mar-Elia &amp;lt;darren@sdmsoftware.com&amp;lt;mailto:darren@sdmsoftware.com&amp;gt;&amp;gt; &lt;br&gt;  &lt;br&gt; It depends upon how the loopback policy is setup (i.e. where its linked and whether its security-group filtered) but if you don't see it, that's not the issue. Let me ask this. You said earlier in the thread that this is only affecting new machines that you join to the domain? Where did these machines come from? Were they in another AD domain? If so, what you may be seeing is some lingering policies that were implemented in that original domain. I've seen this problem before and its ugly. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Darren &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: gptalk-owner@lists.gpoguy.com&amp;lt;mailto:gptalk-owner@lists.gpoguy.com&amp;gt; [mailto:gptalk-owner@lists.gpoguy.com&amp;lt;mailto:gptalk-owner@lists.gpoguy.com&amp;gt;] On Behalf Of Peter Gough &lt;br&gt; Sent: Thursday, October 01, 2009 4:16 PM &lt;br&gt;  &lt;br&gt; To: gptalk@lists.gpoguy.com&amp;lt;mailto:gptalk@lists.gpoguy.com&amp;gt; &lt;br&gt; Subject: Re: [gptalk] Domain Admins unable to manage workstations - group / local policy strangeness &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; I've checked and there's definitely no loopback enabled on any of my policies. If there was wouldn't this affect all machines anyway? &lt;br&gt;  &lt;br&gt; 2009/10/2 Darren Mar-Elia &amp;lt;darren@sdmsoftware.com&amp;lt;mailto:darren@sdmsoftware.com&amp;gt;&amp;gt; &lt;br&gt;  &lt;br&gt; Another thing to look into Peter-make sure you don't have loopback enabled on these computers at some point. This could be causing the effect you're seeing. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Darren &lt;br&gt;  &lt;br&gt; **** &lt;br&gt;  &lt;br&gt; Darren Mar-Elia &lt;br&gt;  &lt;br&gt; CTO &amp; Founder &lt;br&gt;  &lt;br&gt; SDM Software, Inc. &lt;br&gt;  &lt;br&gt; "The Group Policy Experts" &lt;br&gt;  &lt;br&gt; www.sdmsoftware.com&amp;lt;http://www.sdmsoftware.com/&amp;gt; &lt;br&gt;  &lt;br&gt; Founder- www.gpoguy.com&amp;lt;http://www.gpoguy.com&amp;gt; - The Group Policy Resource Site &lt;br&gt;  &lt;br&gt; Blog: www.sdmsoftware.com/blog&amp;lt;http://www.sdmsoftware.com/blog&amp;gt; &lt;br&gt;  &lt;br&gt; Twitter: www.twitter.com/grouppolicyguy&amp;lt;http://www.twitter.com/grouppolicyguy&amp;gt; &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: gptalk-owner@lists.gpoguy.com&amp;lt;mailto:gptalk-owner@lists.gpoguy.com&amp;gt; [mailto:gptalk-owner@lists.gpoguy.com&amp;lt;mailto:gptalk-owner@lists.gpoguy.com&amp;gt;] On Behalf Of Peter Gough &lt;br&gt; Sent: Thursday, October 01, 2009 7:07 AM &lt;br&gt;  &lt;br&gt; To: gptalk@lists.gpoguy.com&amp;lt;mailto:gptalk@lists.gpoguy.com&amp;gt; &lt;br&gt;  &lt;br&gt; Subject: Re: [gptalk] Domain Admins unable to manage workstations - group / local policy strangeness &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Thanks guys. I'm off to bed now (00:06 in Brisbane having just watched last week's MotD&amp;lt;http://en.wikipedia.org/wiki/MOTD&amp;gt; (I'm a Pom&amp;lt;http://en.wikipedia.org/wiki/Alternative_words_for_British#Pommy&amp;gt;!)). I'll try out your suggestions tomorrow and let you know how I get on. &lt;br&gt;  &lt;br&gt; Peter &lt;br&gt;  &lt;br&gt; 2009/10/1 Tim Bolton &amp;lt;jsclmedave@gmail.com&amp;lt;mailto:jsclmedave@gmail.com&amp;gt;&amp;gt; &lt;br&gt;  &lt;br&gt; Peter &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; This link may help http://www.windowsnetworking.com/articles_tutorials/Resultant-Set-Policy-Queries-GPRESULT.html   Have not looked at any differences - if any - in 2008 as of yet. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Tim Bolton &lt;br&gt; 148 2nd Street North &lt;br&gt; Central City Iowa, 52214 &lt;br&gt;  &lt;br&gt; Microsoft Certified IT Professional &lt;br&gt;  &lt;br&gt; On Thu, Oct 1, 2009 at 8:12 AM, Peter Gough &amp;lt;pmgough@gmail.com&amp;lt;mailto:pmgough@gmail.com&amp;gt;&amp;gt; wrote: &lt;br&gt;  &lt;br&gt; Wow! Hadn't realised GP Preferences weren't displayed when I ran RSoP on the box itself, although I wish I'd noticed! &lt;br&gt;  &lt;br&gt; I'm at home at the moment (it's 23:10 in Brisbane!) but are you suggesting running something like: &lt;br&gt;  &lt;br&gt; gpresult /s \\myproblemcomputer /v ... from my Server 2008? &lt;br&gt;  &lt;br&gt; I'll give it a go tomorrow morning. &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt;  &lt;br&gt; Peter &lt;br&gt;  &lt;br&gt; 2009/10/1 Andrew McHale &amp;lt;Andrew.McHale@synergix.co.uk&amp;lt;mailto:Andrew.McHale@synergix.co.uk&amp;gt;&amp;gt; &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Hi Peter &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; If you're applying GP Preferences to an XP machine you won't see the results of that in an RSoP report ran on that machine as it can't display GPP settings. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Try running GPResult for the problematic machine, but from a 2008 machine to get a true picture of all the settings being applied. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Andrew &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: Peter Gough [mailto:pmgough@gmail.com&amp;lt;mailto:pmgough@gmail.com&amp;gt;] &lt;br&gt; Sent: 01 October 2009 13:39 &lt;br&gt;  &lt;br&gt; To: gptalk@lists.gpoguy.com&amp;lt;mailto:gptalk@lists.gpoguy.com&amp;gt; &lt;br&gt;  &lt;br&gt; Subject: Re: [gptalk] Domain Admins unable to manage workstations - group / local policy strangeness &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; The only other thing I can think of that's changed recently is that we've started managing policies from a Windows Server 2008 box to take advantage of the Group Policy Preference stuff. Would that have any impact? &lt;br&gt;  &lt;br&gt; 2009/10/1 Peter Gough &amp;lt;pmgough@gmail.com&amp;lt;mailto:pmgough@gmail.com&amp;gt;&amp;gt; &lt;br&gt;  &lt;br&gt; I don't believe that's the case. The image we're currently using is fairly new but we've installed an old image on a couple of workstations to see if this is the issue and the same problem occurs. We've also setup a total vanilla-build workstation from our original XP SP2 disks and again we're seeing the same issue. &lt;br&gt;  &lt;br&gt; This seems to be an active directory / group policy thing rather than a workstation specific problem. &lt;br&gt;  &lt;br&gt; The thing that's got me baffled is that the results we're getting from running RSoP against the machine don't reflect what we're experiencing on the ground. RSoP says everything is normal but domain admins are still unable to login to a machine and run services.msc (for example). &lt;br&gt;  &lt;br&gt; 2009/10/1 Martin Hugo &amp;lt;Martin_Hugo@hboe.org&amp;lt;mailto:Martin_Hugo@hboe.org&amp;gt;&amp;gt; &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Is it in the local policies of your image? &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Martin T. Hugo &lt;br&gt;  &lt;br&gt; Network Administrator &lt;br&gt;  &lt;br&gt; Hilliard City Schools &lt;br&gt;  &lt;br&gt; 614-921-7102 (Ph) &lt;br&gt;  &lt;br&gt; 614-771-7243 (Fax) &lt;br&gt;  &lt;br&gt; Error! Filename not specified.Think before you print &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: gptalk-owner@lists.gpoguy.com&amp;lt;mailto:gptalk-owner@lists.gpoguy.com&amp;gt; [mailto:gptalk-owner@lists.gpoguy.com&amp;lt;mailto:gptalk-owner@lists.gpoguy.com&amp;gt;] On Behalf Of Peter Gough &lt;br&gt; Sent: Thursday, October 01, 2009 2:36 AM &lt;br&gt; To: gptalk@lists.gpoguy.com&amp;lt;mailto:gptalk@lists.gpoguy.com&amp;gt; &lt;br&gt; Subject: [gptalk] Domain Admins unable to manage workstations - group / local policy strangeness &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; I've got a bit of a strange problem which I've been totally unable to resolve. Essentially what's happening is that when I join a workstation to our Windows Server 2003 domain the domain admins are affected by our restrictive group policies and we are unable to manage the machines. For example a domain admin is unable to launch regedit, manage services etc. &lt;br&gt;  &lt;br&gt; We restrict this sort of stuff for our regular users but currently on any new workstations we join to the domain *all* domain user accounts are being affected. Interestingly group policy settings appear to be applied correctly on existing workstations. &lt;br&gt;  &lt;br&gt; The only 'fix' I've found is to login as a local admin, launch group policy for the local machine and navigate to [User Config / Admin Templates / System / Prevent access to registry editing tools]. &lt;br&gt;  &lt;br&gt; I then change this setting from its default 'Not Configured' state to 'Disabled', hit apply, then change it back again to 'Not Configured' and hit apply and suddenly domain admins can run regedit and standard domain users can't. &lt;br&gt;  &lt;br&gt; In order to get access to some of the other restricted stuff I have to login as a local admin, navigate to [User Config / Admin Templates / Windows Components / Microsoft Management Console / Restrict users to the explicitly permitted list of snap-ins] and again toggle the settings. &lt;br&gt;  &lt;br&gt; The change happens even before I move the computer object into any of our sub OUs so none of our restrictive policies should be applied at this point. When I run an RSoP against the machine it tells me that only the Default Domain Policy is applied (which doesn't contain any of our restrictive policies) and that the Local Policy isn't applied because it is empty. &lt;br&gt;  &lt;br&gt; Any thoughts on why this might be happening or what I can do next to troubleshoot? &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt;  &lt;br&gt; Peter &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; </description>
			<link>http://www.gpoguy.com/MailList/tabid/58/forumid/1/postid/1218/view/topic/Default.aspx</link>
			<author>dmarelia</author>
			<pubDate>Fri, 02 Oct 2009 05:25:57 GMT</pubDate>
		</item>
		<item>
			<title>Re: [gptalk] Domain Admins unable to manage workstations - group / 
 local policy strangeness</title>
			<description>These are brand new machines. We're building them using the same install &lt;br&gt; media we've used previously and then joining them to our domain. Nothing in &lt;br&gt; this part of our process has changed. &lt;br&gt;  &lt;br&gt; 2009/10/2 Darren Mar-Elia &amp;lt;darren@sdmsoftware.com&amp;gt; &lt;br&gt;  &lt;br&gt; &amp;gt;  It depends upon how the loopback policy is setup (i.e. where its linked &lt;br&gt; &amp;gt; and whether its security-group filtered) but if you don’t see it, that’s not &lt;br&gt; &amp;gt; the issue. Let me ask this. You said earlier in the thread that this is only &lt;br&gt; &amp;gt; affecting new machines that you join to the domain? Where did these machines &lt;br&gt; &amp;gt; come from? Were they in another AD domain? If so, what you may be seeing is &lt;br&gt; &amp;gt; some lingering policies that were implemented in that original domain. I’ve &lt;br&gt; &amp;gt; seen this problem before and its ugly. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Darren &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* gptalk-owner@lists.gpoguy.com [mailto: &lt;br&gt; &amp;gt; gptalk-owner@lists.gpoguy.com] *On Behalf Of *Peter Gough &lt;br&gt; &amp;gt; *Sent:* Thursday, October 01, 2009 4:16 PM &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; *Subject:* Re: [gptalk] Domain Admins unable to manage workstations - &lt;br&gt; &amp;gt; group / local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I've checked and there's definitely no loopback enabled on any of my &lt;br&gt; &amp;gt; policies. If there was wouldn't this affect all machines anyway? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/2 Darren Mar-Elia &amp;lt;darren@sdmsoftware.com&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Another thing to look into Peter—make sure you don’t have loopback enabled &lt;br&gt; &amp;gt; on these computers at some point. This could be causing the effect you’re &lt;br&gt; &amp;gt; seeing. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Darren &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; **** &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Darren Mar-Elia &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; CTO &amp; Founder &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; SDM Software, Inc. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; "*The Group Policy Experts"* &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; www.sdmsoftware.com &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Founder— www.gpoguy.com – The Group Policy Resource Site &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Blog: www.sdmsoftware.com/blog &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Twitter: www.twitter.com/grouppolicyguy &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* gptalk-owner@lists.gpoguy.com [mailto: &lt;br&gt; &amp;gt; gptalk-owner@lists.gpoguy.com] *On Behalf Of *Peter Gough &lt;br&gt; &amp;gt; *Sent:* Thursday, October 01, 2009 7:07 AM &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Subject:* Re: [gptalk] Domain Admins unable to manage workstations - &lt;br&gt; &amp;gt; group / local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Thanks guys. I'm off to bed now (00:06 in Brisbane having just watched last &lt;br&gt; &amp;gt; week's MotD &amp;lt;http://en.wikipedia.org/wiki/MOTD&amp;gt; (I'm a Pom&amp;lt;http://en.wikipedia.org/wiki/Alternative_words_for_British#Pommy&amp;gt;!)). &lt;br&gt; &amp;gt; I'll try out your suggestions tomorrow and let you know how I get on. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/1 Tim Bolton &amp;lt;jsclmedave@gmail.com&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; This link may help &lt;br&gt; &amp;gt; http://www.windowsnetworking.com/articles_tutorials/Resultant-Set-Policy-Queries-GPRESULT.html &lt;br&gt; &amp;gt; Have not looked at any differences - if any - in 2008 as of yet. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Tim Bolton &lt;br&gt; &amp;gt; 148 2nd Street North &lt;br&gt; &amp;gt; Central City Iowa, 52214 &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Microsoft Certified IT Professional &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; On Thu, Oct 1, 2009 at 8:12 AM, Peter Gough &amp;lt;pmgough@gmail.com&amp;gt; wrote: &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Wow! Hadn't realised GP Preferences weren't displayed when I ran RSoP on &lt;br&gt; &amp;gt; the box itself, although I wish I'd noticed! &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I'm at home at the moment (it's 23:10 in Brisbane!) but are you suggesting &lt;br&gt; &amp;gt; running something like: &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; gpresult /s \\myproblemcomputer /v ... from my Server 2008? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I'll give it a go tomorrow morning. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Thanks, &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/1 Andrew McHale &amp;lt;Andrew.McHale@synergix.co.uk&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Hi Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; If you’re applying GP Preferences to an XP machine you won’t see the &lt;br&gt; &amp;gt; results of that in an RSoP report ran on that machine as it can’t display &lt;br&gt; &amp;gt; GPP settings. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Try running GPResult for the problematic machine, but from a 2008 machine &lt;br&gt; &amp;gt; to get a true picture of all the settings being applied. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Andrew &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* Peter Gough [mailto:pmgough@gmail.com] &lt;br&gt; &amp;gt; *Sent:* 01 October 2009 13:39 &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Subject:* Re: [gptalk] Domain Admins unable to manage workstations - &lt;br&gt; &amp;gt; group / local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The only other thing I can think of that's changed recently is that we've &lt;br&gt; &amp;gt; started managing policies from a Windows Server 2008 box to take advantage &lt;br&gt; &amp;gt; of the Group Policy Preference stuff. Would that have any impact? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/1 Peter Gough &amp;lt;pmgough@gmail.com&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I don't believe that's the case. The image we're currently using is fairly &lt;br&gt; &amp;gt; new but we've installed an old image on a couple of workstations to see if &lt;br&gt; &amp;gt; this is the issue and the same problem occurs. We've also setup a total &lt;br&gt; &amp;gt; vanilla-build workstation from our original XP SP2 disks and again we're &lt;br&gt; &amp;gt; seeing the same issue. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; This seems to be an active directory / group policy thing rather than a &lt;br&gt; &amp;gt; workstation specific problem. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The thing that's got me baffled is that the results we're getting from &lt;br&gt; &amp;gt; running RSoP against the machine don't reflect what we're experiencing on &lt;br&gt; &amp;gt; the ground. RSoP says everything is normal but domain admins are still &lt;br&gt; &amp;gt; unable to login to a machine and run services.msc (for example). &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/1 Martin Hugo &amp;lt;Martin_Hugo@hboe.org&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Is it in the local policies of your image? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Martin T. Hugo &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Network Administrator &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Hilliard City Schools &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 614-921-7102 (Ph) &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 614-771-7243 (Fax) &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Error! Filename not specified.*Think before you print &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* gptalk-owner@lists.gpoguy.com [mailto: &lt;br&gt; &amp;gt; gptalk-owner@lists.gpoguy.com] *On Behalf Of *Peter Gough &lt;br&gt; &amp;gt; *Sent:* Thursday, October 01, 2009 2:36 AM &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; *Subject:* [gptalk] Domain Admins unable to manage workstations - group / &lt;br&gt; &amp;gt; local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I've got a bit of a strange problem which I've been totally unable to &lt;br&gt; &amp;gt; resolve. Essentially what's happening is that when I join a workstation to &lt;br&gt; &amp;gt; our Windows Server 2003 domain the domain admins are affected by our &lt;br&gt; &amp;gt; restrictive group policies and we are unable to manage the machines. For &lt;br&gt; &amp;gt; example a domain admin is unable to launch regedit, manage services etc. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; We restrict this sort of stuff for our regular users but currently on any &lt;br&gt; &amp;gt; new workstations we join to the domain *all* domain user accounts are being &lt;br&gt; &amp;gt; affected. Interestingly group policy settings appear to be applied correctly &lt;br&gt; &amp;gt; on existing workstations. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The only 'fix' I've found is to login as a local admin, launch group policy &lt;br&gt; &amp;gt; for the local machine and navigate to [User Config / Admin Templates / &lt;br&gt; &amp;gt; System / Prevent access to registry editing tools]. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I then change this setting from its default 'Not Configured' state to &lt;br&gt; &amp;gt; 'Disabled', hit apply, then change it back again to 'Not Configured' and hit &lt;br&gt; &amp;gt; apply and suddenly domain admins can run regedit and standard domain users &lt;br&gt; &amp;gt; can't. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; In order to get access to some of the other restricted stuff I have to &lt;br&gt; &amp;gt; login as a local admin, navigate to [User Config / Admin Templates / Windows &lt;br&gt; &amp;gt; Components / Microsoft Management Console / Restrict users to the explicitly &lt;br&gt; &amp;gt; permitted list of snap-ins] and again toggle the settings. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The change happens even before I move the computer object into any of our &lt;br&gt; &amp;gt; sub OUs so none of our restrictive policies should be applied at this point. &lt;br&gt; &amp;gt; When I run an RSoP against the machine it tells me that only the Default &lt;br&gt; &amp;gt; Domain Policy is applied (which doesn't contain any of our restrictive &lt;br&gt; &amp;gt; policies) and that the Local Policy isn't applied because it is empty. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Any thoughts on why this might be happening or what I can do next to &lt;br&gt; &amp;gt; troubleshoot? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Thanks, &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt;  &lt;br&gt; </description>
			<link>http://www.gpoguy.com/MailList/tabid/58/forumid/1/postid/1215/view/topic/Default.aspx</link>
			<author>pmgough</author>
			<pubDate>Fri, 02 Oct 2009 01:25:29 GMT</pubDate>
		</item>
		<item>
			<title>RE: [gptalk] Domain Admins unable to manage workstations - group /
 local policy strangeness</title>
			<description>It depends upon how the loopback policy is setup (i.e. where its linked and whether its security-group filtered) but if you don't see it, that's not the issue. Let me ask this. You said earlier in the thread that this is only affecting new machines that you join to the domain? Where did these machines come from? Were they in another AD domain? If so, what you may be seeing is some lingering policies that were implemented in that original domain. I've seen this problem before and its ugly. &lt;br&gt;  &lt;br&gt; Darren &lt;br&gt;  &lt;br&gt; From: gptalk-owner@lists.gpoguy.com [mailto:gptalk-owner@lists.gpoguy.com] On Behalf Of Peter Gough &lt;br&gt; Sent: Thursday, October 01, 2009 4:16 PM &lt;br&gt; To: gptalk@lists.gpoguy.com &lt;br&gt; Subject: Re: [gptalk] Domain Admins unable to manage workstations - group / local policy strangeness &lt;br&gt;  &lt;br&gt; I've checked and there's definitely no loopback enabled on any of my policies. If there was wouldn't this affect all machines anyway? &lt;br&gt; 2009/10/2 Darren Mar-Elia &amp;lt;darren@sdmsoftware.com&amp;lt;mailto:darren@sdmsoftware.com&amp;gt;&amp;gt; &lt;br&gt;  &lt;br&gt; Another thing to look into Peter-make sure you don't have loopback enabled on these computers at some point. This could be causing the effect you're seeing. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Darren &lt;br&gt;  &lt;br&gt; **** &lt;br&gt;  &lt;br&gt; Darren Mar-Elia &lt;br&gt;  &lt;br&gt; CTO &amp; Founder &lt;br&gt;  &lt;br&gt; SDM Software, Inc. &lt;br&gt;  &lt;br&gt; "The Group Policy Experts" &lt;br&gt;  &lt;br&gt; www.sdmsoftware.com&amp;lt;http://www.sdmsoftware.com/&amp;gt; &lt;br&gt;  &lt;br&gt; Founder- www.gpoguy.com&amp;lt;http://www.gpoguy.com&amp;gt; - The Group Policy Resource Site &lt;br&gt;  &lt;br&gt; Blog: www.sdmsoftware.com/blog&amp;lt;http://www.sdmsoftware.com/blog&amp;gt; &lt;br&gt;  &lt;br&gt; Twitter: www.twitter.com/grouppolicyguy&amp;lt;http://www.twitter.com/grouppolicyguy&amp;gt; &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: gptalk-owner@lists.gpoguy.com&amp;lt;mailto:gptalk-owner@lists.gpoguy.com&amp;gt; [mailto:gptalk-owner@lists.gpoguy.com&amp;lt;mailto:gptalk-owner@lists.gpoguy.com&amp;gt;] On Behalf Of Peter Gough &lt;br&gt; Sent: Thursday, October 01, 2009 7:07 AM &lt;br&gt;  &lt;br&gt; To: gptalk@lists.gpoguy.com&amp;lt;mailto:gptalk@lists.gpoguy.com&amp;gt; &lt;br&gt; Subject: Re: [gptalk] Domain Admins unable to manage workstations - group / local policy strangeness &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Thanks guys. I'm off to bed now (00:06 in Brisbane having just watched last week's MotD&amp;lt;http://en.wikipedia.org/wiki/MOTD&amp;gt; (I'm a Pom&amp;lt;http://en.wikipedia.org/wiki/Alternative_words_for_British#Pommy&amp;gt;!)). I'll try out your suggestions tomorrow and let you know how I get on. &lt;br&gt;  &lt;br&gt; Peter &lt;br&gt;  &lt;br&gt; 2009/10/1 Tim Bolton &amp;lt;jsclmedave@gmail.com&amp;lt;mailto:jsclmedave@gmail.com&amp;gt;&amp;gt; &lt;br&gt;  &lt;br&gt; Peter &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; This link may help http://www.windowsnetworking.com/articles_tutorials/Resultant-Set-Policy-Queries-GPRESULT.html   Have not looked at any differences - if any - in 2008 as of yet. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Tim Bolton &lt;br&gt; 148 2nd Street North &lt;br&gt; Central City Iowa, 52214 &lt;br&gt;  &lt;br&gt; Microsoft Certified IT Professional &lt;br&gt;  &lt;br&gt; On Thu, Oct 1, 2009 at 8:12 AM, Peter Gough &amp;lt;pmgough@gmail.com&amp;lt;mailto:pmgough@gmail.com&amp;gt;&amp;gt; wrote: &lt;br&gt;  &lt;br&gt; Wow! Hadn't realised GP Preferences weren't displayed when I ran RSoP on the box itself, although I wish I'd noticed! &lt;br&gt;  &lt;br&gt; I'm at home at the moment (it's 23:10 in Brisbane!) but are you suggesting running something like: &lt;br&gt;  &lt;br&gt; gpresult /s \\myproblemcomputer /v ... from my Server 2008? &lt;br&gt;  &lt;br&gt; I'll give it a go tomorrow morning. &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt;  &lt;br&gt; Peter &lt;br&gt;  &lt;br&gt; 2009/10/1 Andrew McHale &amp;lt;Andrew.McHale@synergix.co.uk&amp;lt;mailto:Andrew.McHale@synergix.co.uk&amp;gt;&amp;gt; &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Hi Peter &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; If you're applying GP Preferences to an XP machine you won't see the results of that in an RSoP report ran on that machine as it can't display GPP settings. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Try running GPResult for the problematic machine, but from a 2008 machine to get a true picture of all the settings being applied. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Andrew &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: Peter Gough [mailto:pmgough@gmail.com&amp;lt;mailto:pmgough@gmail.com&amp;gt;] &lt;br&gt; Sent: 01 October 2009 13:39 &lt;br&gt;  &lt;br&gt; To: gptalk@lists.gpoguy.com&amp;lt;mailto:gptalk@lists.gpoguy.com&amp;gt; &lt;br&gt;  &lt;br&gt; Subject: Re: [gptalk] Domain Admins unable to manage workstations - group / local policy strangeness &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; The only other thing I can think of that's changed recently is that we've started managing policies from a Windows Server 2008 box to take advantage of the Group Policy Preference stuff. Would that have any impact? &lt;br&gt;  &lt;br&gt; 2009/10/1 Peter Gough &amp;lt;pmgough@gmail.com&amp;lt;mailto:pmgough@gmail.com&amp;gt;&amp;gt; &lt;br&gt;  &lt;br&gt; I don't believe that's the case. The image we're currently using is fairly new but we've installed an old image on a couple of workstations to see if this is the issue and the same problem occurs. We've also setup a total vanilla-build workstation from our original XP SP2 disks and again we're seeing the same issue. &lt;br&gt;  &lt;br&gt; This seems to be an active directory / group policy thing rather than a workstation specific problem. &lt;br&gt;  &lt;br&gt; The thing that's got me baffled is that the results we're getting from running RSoP against the machine don't reflect what we're experiencing on the ground. RSoP says everything is normal but domain admins are still unable to login to a machine and run services.msc (for example). &lt;br&gt;  &lt;br&gt; 2009/10/1 Martin Hugo &amp;lt;Martin_Hugo@hboe.org&amp;lt;mailto:Martin_Hugo@hboe.org&amp;gt;&amp;gt; &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Is it in the local policies of your image? &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Martin T. Hugo &lt;br&gt;  &lt;br&gt; Network Administrator &lt;br&gt;  &lt;br&gt; Hilliard City Schools &lt;br&gt;  &lt;br&gt; 614-921-7102 (Ph) &lt;br&gt;  &lt;br&gt; 614-771-7243 (Fax) &lt;br&gt;  &lt;br&gt; Error! Filename not specified.Think before you print &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: gptalk-owner@lists.gpoguy.com&amp;lt;mailto:gptalk-owner@lists.gpoguy.com&amp;gt; [mailto:gptalk-owner@lists.gpoguy.com&amp;lt;mailto:gptalk-owner@lists.gpoguy.com&amp;gt;] On Behalf Of Peter Gough &lt;br&gt; Sent: Thursday, October 01, 2009 2:36 AM &lt;br&gt; To: gptalk@lists.gpoguy.com&amp;lt;mailto:gptalk@lists.gpoguy.com&amp;gt; &lt;br&gt; Subject: [gptalk] Domain Admins unable to manage workstations - group / local policy strangeness &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; I've got a bit of a strange problem which I've been totally unable to resolve. Essentially what's happening is that when I join a workstation to our Windows Server 2003 domain the domain admins are affected by our restrictive group policies and we are unable to manage the machines. For example a domain admin is unable to launch regedit, manage services etc. &lt;br&gt;  &lt;br&gt; We restrict this sort of stuff for our regular users but currently on any new workstations we join to the domain *all* domain user accounts are being affected. Interestingly group policy settings appear to be applied correctly on existing workstations. &lt;br&gt;  &lt;br&gt; The only 'fix' I've found is to login as a local admin, launch group policy for the local machine and navigate to [User Config / Admin Templates / System / Prevent access to registry editing tools]. &lt;br&gt;  &lt;br&gt; I then change this setting from its default 'Not Configured' state to 'Disabled', hit apply, then change it back again to 'Not Configured' and hit apply and suddenly domain admins can run regedit and standard domain users can't. &lt;br&gt;  &lt;br&gt; In order to get access to some of the other restricted stuff I have to login as a local admin, navigate to [User Config / Admin Templates / Windows Components / Microsoft Management Console / Restrict users to the explicitly permitted list of snap-ins] and again toggle the settings. &lt;br&gt;  &lt;br&gt; The change happens even before I move the computer object into any of our sub OUs so none of our restrictive policies should be applied at this point. When I run an RSoP against the machine it tells me that only the Default Domain Policy is applied (which doesn't contain any of our restrictive policies) and that the Local Policy isn't applied because it is empty. &lt;br&gt;  &lt;br&gt; Any thoughts on why this might be happening or what I can do next to troubleshoot? &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt;  &lt;br&gt; Peter &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; </description>
			<link>http://www.gpoguy.com/MailList/tabid/58/forumid/1/postid/1210/view/topic/Default.aspx</link>
			<author>dmarelia</author>
			<pubDate>Fri, 02 Oct 2009 00:32:12 GMT</pubDate>
		</item>
		<item>
			<title>Re: [gptalk] Domain Admins unable to manage workstations - group / 
 local policy strangeness</title>
			<description>Thanks. The only thing I've changed recently is that I've begun using Group &lt;br&gt; Policy Preferences and administering these from a Server 2008 box but I &lt;br&gt; don't see how this would cause the behaviour I'm seeing. &lt;br&gt;  &lt;br&gt; 2009/10/1 Tim Bolton &amp;lt;jsclmedave@gmail.com&amp;gt; &lt;br&gt;  &lt;br&gt; &amp;gt; Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; This link may help &lt;br&gt; &amp;gt; http://www.windowsnetworking.com/articles_tutorials/Resultant-Set-Policy-Queries-GPRESULT.html &lt;br&gt; &amp;gt; Have not looked at any differences - if any - in 2008 as of yet. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Tim Bolton &lt;br&gt; &amp;gt; 148 2nd Street North &lt;br&gt; &amp;gt; Central City Iowa, 52214 &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Microsoft Certified IT Professional &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; On Thu, Oct 1, 2009 at 8:12 AM, Peter Gough &amp;lt;pmgough@gmail.com&amp;gt; wrote: &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt;&amp;gt; Wow! Hadn't realised GP Preferences weren't displayed when I ran RSoP on &lt;br&gt; &amp;gt;&amp;gt; the box itself, although I wish I'd noticed! &lt;br&gt; &amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt; I'm at home at the moment (it's 23:10 in Brisbane!) but are you suggesting &lt;br&gt; &amp;gt;&amp;gt; running something like: &lt;br&gt; &amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt; gpresult /s \\myproblemcomputer /v ... from my Server 2008? &lt;br&gt; &amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt; I'll give it a go tomorrow morning. &lt;br&gt; &amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt; Thanks, &lt;br&gt; &amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt; Peter &lt;br&gt; &amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt; 2009/10/1 Andrew McHale &amp;lt;Andrew.McHale@synergix.co.uk&amp;gt; &lt;br&gt; &amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;   Hi Peter &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; If you’re applying GP Preferences to an XP machine you won’t see the &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; results of that in an RSoP report ran on that machine as it can’t display &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; GPP settings. &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; Try running GPResult for the problematic machine, but from a 2008 machine &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; to get a true picture of all the settings being applied. &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; Andrew &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; *From:* Peter Gough [mailto:pmgough@gmail.com] &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; *Sent:* 01 October 2009 13:39 &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; *Subject:* Re: [gptalk] Domain Admins unable to manage workstations - &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; group / local policy strangeness &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; The only other thing I can think of that's changed recently is that we've &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; started managing policies from a Windows Server 2008 box to take advantage &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; of the Group Policy Preference stuff. Would that have any impact? &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; 2009/10/1 Peter Gough &amp;lt;pmgough@gmail.com&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; I don't believe that's the case. The image we're currently using is &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; fairly new but we've installed an old image on a couple of workstations to &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; see if this is the issue and the same problem occurs. We've also setup a &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; total vanilla-build workstation from our original XP SP2 disks and again &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; we're seeing the same issue. &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; This seems to be an active directory / group policy thing rather than a &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; workstation specific problem. &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; The thing that's got me baffled is that the results we're getting from &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; running RSoP against the machine don't reflect what we're experiencing on &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; the ground. RSoP says everything is normal but domain admins are still &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; unable to login to a machine and run services.msc (for example). &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; 2009/10/1 Martin Hugo &amp;lt;Martin_Hugo@hboe.org&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; Is it in the local policies of your image? &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; Martin T. Hugo &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; Network Administrator &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; Hilliard City Schools &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; 614-921-7102 (Ph) &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; 614-771-7243 (Fax) &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; *Error! Filename not specified.*Think before you print &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; *From:* gptalk-owner@lists.gpoguy.com [mailto: &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; gptalk-owner@lists.gpoguy.com] *On Behalf Of *Peter Gough &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; *Sent:* Thursday, October 01, 2009 2:36 AM &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; *Subject:* [gptalk] Domain Admins unable to manage workstations - group &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; / local policy strangeness &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; I've got a bit of a strange problem which I've been totally unable to &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; resolve. Essentially what's happening is that when I join a workstation to &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; our Windows Server 2003 domain the domain admins are affected by our &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; restrictive group policies and we are unable to manage the machines. For &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; example a domain admin is unable to launch regedit, manage services etc. &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; We restrict this sort of stuff for our regular users but currently on any &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; new workstations we join to the domain *all* domain user accounts are being &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; affected. Interestingly group policy settings appear to be applied correctly &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; on existing workstations. &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; The only 'fix' I've found is to login as a local admin, launch group &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; policy for the local machine and navigate to [User Config / Admin Templates &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; / System / Prevent access to registry editing tools]. &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; I then change this setting from its default 'Not Configured' state to &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; 'Disabled', hit apply, then change it back again to 'Not Configured' and hit &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; apply and suddenly domain admins can run regedit and standard domain users &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; can't. &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; In order to get access to some of the other restricted stuff I have to &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; login as a local admin, navigate to [User Config / Admin Templates / Windows &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; Components / Microsoft Management Console / Restrict users to the explicitly &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; permitted list of snap-ins] and again toggle the settings. &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; The change happens even before I move the computer object into any of our &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; sub OUs so none of our restrictive policies should be applied at this point. &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; When I run an RSoP against the machine it tells me that only the Default &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; Domain Policy is applied (which doesn't contain any of our restrictive &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; policies) and that the Local Policy isn't applied because it is empty. &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; Any thoughts on why this might be happening or what I can do next to &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; troubleshoot? &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; Thanks, &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; Peter &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt; &lt;br&gt; &amp;gt;&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt;  &lt;br&gt; </description>
			<link>http://www.gpoguy.com/MailList/tabid/58/forumid/1/postid/1208/view/topic/Default.aspx</link>
			<author>pmgough</author>
			<pubDate>Fri, 02 Oct 2009 00:25:55 GMT</pubDate>
		</item>
		<item>
			<title>Re: [gptalk] Domain Admins unable to manage workstations - group / 
 local policy strangeness</title>
			<description>Thanks. When I run this I get the setup I expect, ie. the Default Domain &lt;br&gt; Policy is being applied and the Local Group Policy is denied because it is &lt;br&gt; empty. According to the results no other policies are being applied and &lt;br&gt; there is nothing in the DDP which would cause the results I'm seeing. &lt;br&gt;  &lt;br&gt; Any other thoughts? &lt;br&gt;  &lt;br&gt; It's strange because according to the RSoP info everything should be fine. &lt;br&gt; The components are all okay, i don't get any weird policy events to &lt;br&gt; investigate and the results look exactly the same on an affected computer as &lt;br&gt; they do on one of my unaffected machines. &lt;br&gt;  &lt;br&gt; Peter &lt;br&gt;  &lt;br&gt; 2009/10/1 Andrew McHale &amp;lt;Andrew.McHale@synergix.co.uk&amp;gt; &lt;br&gt;  &lt;br&gt; &amp;gt;  Yep, that’d do the job. I’d suggest adding the /H parameter (only &lt;br&gt; &amp;gt; available on Vista/7/2008 I believe) to nominate a file to output the &lt;br&gt; &amp;gt; results to. Makes it much easier reading. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; gpresult /S \\myproblemcomputer /V /H gpresult.htm &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The file is output into the root of the logged on users profile (c:\users\ &lt;br&gt; &amp;gt; user.name\). Make sure you open the file in IE as Firefox doesn’t display &lt;br&gt; &amp;gt; the active content correctly. And make sure the Windows Firewall is off on &lt;br&gt; &amp;gt; the remote machine if you are able to (which you probably can’t due to no &lt;br&gt; &amp;gt; admin rights!) &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Good luck and good night! &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Andrew &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* Peter Gough [mailto:pmgough@gmail.com] &lt;br&gt; &amp;gt; *Sent:* 01 October 2009 14:13 &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; *Subject:* Re: [gptalk] Domain Admins unable to manage workstations - &lt;br&gt; &amp;gt; group / local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Wow! Hadn't realised GP Preferences weren't displayed when I ran RSoP on &lt;br&gt; &amp;gt; the box itself, although I wish I'd noticed! &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I'm at home at the moment (it's 23:10 in Brisbane!) but are you suggesting &lt;br&gt; &amp;gt; running something like: &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; gpresult /s \\myproblemcomputer /v ... from my Server 2008? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I'll give it a go tomorrow morning. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Thanks, &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/1 Andrew McHale &amp;lt;Andrew.McHale@synergix.co.uk&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Hi Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; If you’re applying GP Preferences to an XP machine you won’t see the &lt;br&gt; &amp;gt; results of that in an RSoP report ran on that machine as it can’t display &lt;br&gt; &amp;gt; GPP settings. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Try running GPResult for the problematic machine, but from a 2008 machine &lt;br&gt; &amp;gt; to get a true picture of all the settings being applied. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Andrew &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* Peter Gough [mailto:pmgough@gmail.com] &lt;br&gt; &amp;gt; *Sent:* 01 October 2009 13:39 &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Subject:* Re: [gptalk] Domain Admins unable to manage workstations - &lt;br&gt; &amp;gt; group / local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The only other thing I can think of that's changed recently is that we've &lt;br&gt; &amp;gt; started managing policies from a Windows Server 2008 box to take advantage &lt;br&gt; &amp;gt; of the Group Policy Preference stuff. Would that have any impact? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/1 Peter Gough &amp;lt;pmgough@gmail.com&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I don't believe that's the case. The image we're currently using is fairly &lt;br&gt; &amp;gt; new but we've installed an old image on a couple of workstations to see if &lt;br&gt; &amp;gt; this is the issue and the same problem occurs. We've also setup a total &lt;br&gt; &amp;gt; vanilla-build workstation from our original XP SP2 disks and again we're &lt;br&gt; &amp;gt; seeing the same issue. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; This seems to be an active directory / group policy thing rather than a &lt;br&gt; &amp;gt; workstation specific problem. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The thing that's got me baffled is that the results we're getting from &lt;br&gt; &amp;gt; running RSoP against the machine don't reflect what we're experiencing on &lt;br&gt; &amp;gt; the ground. RSoP says everything is normal but domain admins are still &lt;br&gt; &amp;gt; unable to login to a machine and run services.msc (for example). &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 2009/10/1 Martin Hugo &amp;lt;Martin_Hugo@hboe.org&amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Is it in the local policies of your image? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Martin T. Hugo &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Network Administrator &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Hilliard City Schools &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 614-921-7102 (Ph) &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; 614-771-7243 (Fax) &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Error! Filename not specified.*Think before you print &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* gptalk-owner@lists.gpoguy.com [mailto: &lt;br&gt; &amp;gt; gptalk-owner@lists.gpoguy.com] *On Behalf Of *Peter Gough &lt;br&gt; &amp;gt; *Sent:* Thursday, October 01, 2009 2:36 AM &lt;br&gt; &amp;gt; *To:* gptalk@lists.gpoguy.com &lt;br&gt; &amp;gt; *Subject:* [gptalk] Domain Admins unable to manage workstations - group / &lt;br&gt; &amp;gt; local policy strangeness &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I've got a bit of a strange problem which I've been totally unable to &lt;br&gt; &amp;gt; resolve. Essentially what's happening is that when I join a workstation to &lt;br&gt; &amp;gt; our Windows Server 2003 domain the domain admins are affected by our &lt;br&gt; &amp;gt; restrictive group policies and we are unable to manage the machines. For &lt;br&gt; &amp;gt; example a domain admin is unable to launch regedit, manage services etc. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; We restrict this sort of stuff for our regular users but currently on any &lt;br&gt; &amp;gt; new workstations we join to the domain *all* domain user accounts are being &lt;br&gt; &amp;gt; affected. Interestingly group policy settings appear to be applied correctly &lt;br&gt; &amp;gt; on existing workstations. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The only 'fix' I've found is to login as a local admin, launch group policy &lt;br&gt; &amp;gt; for the local machine and navigate to [User Config / Admin Templates / &lt;br&gt; &amp;gt; System / Prevent access to registry editing tools]. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; I then change this setting from its default 'Not Configured' state to &lt;br&gt; &amp;gt; 'Disabled', hit apply, then change it back again to 'Not Configured' and hit &lt;br&gt; &amp;gt; apply and suddenly domain admins can run regedit and standard domain users &lt;br&gt; &amp;gt; can't. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; In order to get access to some of the other restricted stuff I have to &lt;br&gt; &amp;gt; login as a local admin, navigate to [User Config / Admin Templates / Windows &lt;br&gt; &amp;gt; Components / Microsoft Management Console / Restrict users to the explicitly &lt;br&gt; &amp;gt; permitted list of snap-ins] and again toggle the settings. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The change happens even before I move the computer object into any of our &lt;br&gt; &amp;gt; sub OUs so none of our restrictive policies should be applied at this point. &lt;br&gt; &amp;gt; When I run an RSoP against the machine it tells me that only the Default &lt;br&gt; &amp;gt; Domain Policy is applied (which doesn't contain any of our restrictive &lt;br&gt; &amp;gt; policies) and that the Local Policy isn't applied because it is empty. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Any thoughts on why this might be happening or what I can do next to &lt;br&gt; &amp;gt; troubleshoot? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Thanks, &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Peter &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt;  &lt;br&gt; </description>
			<link>http://www.gpoguy.com/MailList/tabid/58/forumid/1/postid/1207/view/topic/Default.aspx</link>
			<author>pmgough</author>
			<pubDate>Fri, 02 Oct 2009 00:15:45 GMT</pubDate>
		</item>
		<item>
			<title>[gptalk] WSUS gpo</title>
			<description> &lt;br&gt; Does any of you have experience dealing with WSUS? I deployed a new WSUS server in our 100% windows environment and I am having issues with computers not showing on WSUS. There are about 400 computers missing and when I  fix one by forcing the gpo refresh, running the windows fix it utility, or going to the extreme of deleting the computer domain account and rejoin the pc back on the domain then another computer that was showing on WSUS disappears. It is like if they were playing games with me! &lt;br&gt;  &lt;br&gt; My gpo seems to be good for almost 900 computers so I have no idea what is going on. And I have spent countless hours looking on the internet for solutions and trying things but nothing helps. &lt;br&gt;  &lt;br&gt; Another problem I am having is that on windows vista when the user wants to run the updates manually using "Windows updates" the computer goes to my WSUS server instead of going to the internet and update from there. For workstations that works ok but for laptops is not good since some users run their updates manually at home and they get errors saying that windows can't connect to windows updates because it is looking for my WSUS server. Is there anything different that I need to do on the gpo for these windows vista computers? Our DCs and AD are running on windows 2003 mode. &lt;br&gt;  &lt;br&gt; I really would appreciate any help. &lt;br&gt;  &lt;br&gt; Thanks &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Dagoberto Estrada &lt;br&gt; Utah transit Authority &lt;br&gt; 801-287-2310 &lt;br&gt; -------------------------- &lt;br&gt; Sent from my BlackBerry Wireless Handheld &lt;br&gt; </description>
			<link>http://www.gpoguy.com/MailList/tabid/58/forumid/1/postid/1206/view/topic/Default.aspx</link>
			<author>mrbusdriversir</author>
			<pubDate>Thu, 01 Oct 2009 23:13:48 GMT</pubDate>
		</item>
	</channel></rss>
