Solved

GPO Help - Need Help Locating and Changing A Custom Setting.

Posted on 2007-12-06
8
743 Views
Last Modified: 2008-05-31
Hey everyone,

I've got a GPO that was made with Server 2000 and possibly created on XP SP1.  Now I've been given the task of changing it some what, but I can't tweak one of the settings.

We are looking to remove only the "C" drive from the user's "My Computer" on the network's workstations.

Inside of GPMC, I open the GPO and hit the Settings Tab...at the bottom of that tab I see:

Extra Registry Settings
 
     Display names for some settings cannot be found. You might be able to resolve this issue by updating the .ADM files used by Group Policy Management.

Setting                                                                                                              State
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives         31

I think this is what I need to alter to allow all drive except the "C" drive.

Does anyone know how I might revert that back or view it so its NOT and "Extra Registry Setting?"

thanks,
inverted
     
0
Comment
Question by:inverted_2000
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 26

Expert Comment

by:farhankazi
ID: 20421301
Have a look at following link:
http://support.microsoft.com/kb/231289

Hope this helps!
Farhan
0
 
LVL 2

Author Comment

by:inverted_2000
ID: 20422009
Kind of helps...but there are 70 folders under
\\server\SYSVOL\clt.domain.com\Policies\

I see the system.adm file, but which one should I access the system.adm from?
0
 
LVL 16

Expert Comment

by:2PiFL
ID: 20422422
Can you use the GPOE and follow these steps:

1. Start the Microsoft Management Console. On the Console menu, click Add/Remove Snap-in.
2. Add the Group Policy Object Editor snap-in for the default domain policy. To do this, click Browse when you are prompted to select a Group Policy Object (GPO). The default GPO is Local Computer. You can also add GPOs for other domain partitions (specifically, Organizational Units).
3. Open the following sections: User Configuration, Administrative Templates, Windows Components, and Windows Explorer.
4. Click Hide these specified drives in My Computer.
5. Click to select the Hide these specified drives in My Computer check box.
6. Click the appropriate option in the drop-down box.

This will edit the proper .adm file
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 
LVL 2

Author Comment

by:inverted_2000
ID: 20422723
I got that much...I'm going to try to set them all back as Disabled and see if I can get them back to the default.
0
 
LVL 2

Author Comment

by:inverted_2000
ID: 20422772
Yup...I just changed the settings around...from:

Enabled
  to
Disabled
  to
Not Configured

That seemed to re-write whatever had that option 31 in place.

Thanks anyway folks (o:
0
 
LVL 84

Accepted Solution

by:
oBdA earned 500 total points
ID: 20422841
The guy who did this probably did what Microsoft recommends *not* to do: he edited the %Systemroot%\inf\system.adm file on his machine, created the GPO, and the customized adm got updated by a service pack.
Make a backup of the GPO using the GPMC before you start with the following.
Use the GPMC to find the GPO's GUID; in the policies folder, check the subfolder named with this GUID for the subfolder "Adm". In the adm folder, open system.adm in Notepad, and search for "!!ABOnly" (can appear several times); check if you see the "31" (which hides A through E) as VALUE NUMERIC in this policy block.
If so, copy that system.adm to your workstation, rename it to system-temp.adm or whatever. Start the GP editor, unload system.adm (right-click "User Configuration\Administrative Templates"), load your system-temp.adm instead. You should now be able to set the "Hide Drives" policy back to "Not configured" (don't change anything else). Close the GP editor, open it again. Remove the system-temp.adm file, add the original system.adm, and you should now be able to set the "Hide Drives" value to your likings.
0
 
LVL 1

Expert Comment

by:modus_operandi
ID: 20479078
Force accepted.
modus_operandi
EE Moderator
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question