Solved

Using Group Policy Results Wizard for different domain

Posted on 2009-05-12
3
298 Views
Last Modified: 2012-05-06
Hi AD Experts :)

My setup is a bit strange and as below:

Forest root: domain.com
Domains: Toronto.domain.com, Washington.domain.com, LosAngeles.domain.com

I am a domain admin for Toronto.domain.com only.

There is a server in the Washington domain named Server1.washington.domain.com, and a user in our domain Toronto\User1.

User1 wants to carry out some work on Server1, but wants to ensure that he has full permissions. He is a local Admin on Server1, but is worried that there maybe GPO's that would prevent him doing any work (such as shutting down etc).

I tried to run GP Results Wizard on Server1, but I receive an error saying that I do not have enough permissions. What can I do here to get a GP result type thing to show what GPO's, if any, will be blocking what actions?

Our Forest level is Windows 2003, and Server1 is Windows 2003 Server too.
0
Comment
Question by:Joe_Budden
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 5

Accepted Solution

by:
BryanMI earned 500 total points
ID: 24366684
He should be able to run the resultant set of policy under his account for his username on that server.  You probably won't be able to do it as you don't have permission on that server.

Get him to login and walk him through running this to see what's going on.
0
 
LVL 1

Author Comment

by:Joe_Budden
ID: 24366773
Hi Bryan,

So I need to install GPMC on Server1? How would I run resultant set of policy on the server?

Thanks!
0
 
LVL 5

Expert Comment

by:BryanMI
ID: 24366800
If your user has the GPMC on his desktop, or you have it on your desktop and can get him to do a runas or logon to your desktop, you can do it from there.  You can put in the server name instead of using the local computer in the RSOP wizard, to get results for another machine.  In this case, you could enter your server name and get the policy results.

The big thing here is that it has to run under the account of the user who does have that admin access to server1.  Technically, it can run from anywhere as long as he is the one to run it.
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question