Solved

Cant remove registry changes made with ADM

Posted on 2009-07-01
4
339 Views
Last Modified: 2012-05-07
I was directed to create a new registry key via group policy.  I made the adm file and added that to a new GPO.  Then I was told the path to it was wrong and it should be placed in another existing path.

The problem arises when I change the ADM file and try to replace the changes I made previously.  I go into the GPO remove the template, then add the revised template.

Running gpupdate on the test machine reveals my new setting takes effect, but the old path that is bad is there too.  I delete the key and do a gpupdate and it comes back.  I checked the SYSVOL folder for that GPO and find the ADM template in it; its only the corrected version.  The only way I found to correct the problem is to delete the whole GPO and recreate it.

Where does it get the information to keep making the bad registy key?  How do I get it to purge that setting?
0
Comment
Question by:cavalierlan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 84

Accepted Solution

by:
oBdA earned 500 total points
ID: 24755197
Add the "bad" key back to your adm template in a separate policy (you can leave the "good" key in), import the template again, set the policy with the "bad" key back to "Not configured".
For the future: *before* you change an adm template, set ALL policies you're about to change back to "Not configured".
Do NOT remove an adm template for good if there are still policies configured in it! The template just tells the GP editor what to display; removing a template from a GPO does NOT remove any settings configured in the GPO with the help of this template!
0
 

Author Comment

by:cavalierlan
ID: 24755440
will I have to leave it in the GPO not configured, or can I remove it once it is not configured?
 
0
 

Author Comment

by:cavalierlan
ID: 24755547
Also, do you guys get paid for your points? How does that work?
0
 
LVL 84

Expert Comment

by:oBdA
ID: 24755557
Once the setting is back at "Not configured", you can remove the "bad" key again.
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article runs through the process of deploying a single EXE application selectively to a group of user.
A hard and fast method for reducing Active Directory Administrators members.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question