Well if you've still got ADUC open, can't you just go and unlink the policy?
Main Topics
Browse All TopicsHELP! I have created a very restrictive group policy on my Windows 2003 server and applied it at the domain level with the intention that it would only apply to terminal services users. I've got it wrong and it's applied itself to all accounts including the Administrator. The only rope I have is that I had the "Active Directory Users and Computers" application open before the policy got applied and I still have it open - I can't open a second instance of it due to the policy so I daren't close the one I have open. This is a production application server - I can't rebuild it and it would be a serious problem even to have to restore last night's backup. Is there any way I can revert the mess I've just made for myself? The console login and Remote Desktop as Administrator are both affected and I pretty much can't open anything - no access to the C: drive, no access to run anything but approved programs.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
@demazter: I downloaded and ran the group policy management console on my own laptop but when I start it, I get the message "To manage Group Policy, you must log on to the computer with a domain user account". We don't have a proper Active Directory infrastructure - this is a standalone installation of Active Directory on the server in question - my laptop isn't a member of an Active Directory at all - we only installed Active Directory this morning and it was for the exclusive purpose of managing permissions for Terminal Services on this one server. I tried using "Add Forest..." in the group policy management console and adding the name of the domain I've just set up, but it says the domain does not exist or could not be contacted.
@theras2000: When I right click on the domain and select "Properties", the tab for "Group Policy" isn't there - presumably because the permissions for it get tested as the form loads and my group policy is denying access to it. Is there another route by which to unlink the policy from the already opened instance of ADUC?
has the laptop got an ip address and the correct DNS server entry?
Can it ping the domain controller?
Can you connect to the \\servername\sysvol\domain
If so lookup the policy with the latest datestamp and right click on it and just remove all permissions from it (we can fix this later)
@demazter:
I found I could connect to the share name you described, and I have done as you said and removed all permissions from the policy with the latest data stamp. Although the Administrator account still has the policy applied, I found I was able to create a new user and put them in the administrators group using the ADUC instance I already had open, then when I logged in as that user I was able to get back into Group Policy Management Console, so I'm much, much closer to resolving the problem now - thanks a lot for getting me this far!
Now to get myself back up and running, I need to work out how to sort the policy out so that it apples to all users except administrators, and stop it applying to the Administrator account where it is already applied. Greatful for any help you can give on these last bits...
Business Accounts
Answer for Membership
by: demazterPosted on 2009-07-27 at 04:36:15ID: 24950448
Use a computer that is not connected to the domain and download the group policy management console then connect to your domain from here and either unlink the policy or under security add adminisrator in an remove the apply policy permission.