Solved

Default Domain Policy Settings Removed but Still being Applied?

Posted on 2009-07-07
10
485 Views
Last Modified: 2012-05-07
Hi!
My Default Domain Policy had some legacy IE Settings put into it at some point before I started over 4 years ago. And I stripped them out. Unfortunately it looks like the DDP is still pushing them out even though I removed them. I know this because I did a deny to the DDP policy only on one PC and it picked up the correct proxy settings from another GPO. So is there a way to change the Default domain policy, by deleting it and creating a new one? I heard of Dcgpofix, but I only want to do that policy and not the domain controller one?

So is that possible or should I be looking to do that some other way?

Cheers
0
Comment
Question by:Colchester_Institute
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
10 Comments
 
LVL 70

Expert Comment

by:KCTS
ID: 24793404
When you say you "stripped out" the settings I assume you just set them to NOT CONFIGURED. Try setting the policies to ENABLED (or DISABLED as appropriate) rather than just leaving them unconfigured.
0
 
LVL 1

Author Comment

by:Colchester_Institute
ID: 24793573
Sorry if I confused with the strip out bit, what I meant was in the DDP there was the proxy address specified for IE, I removed these settings out of the policy so that there was no proxy specified anymore, so the setting enable proxy is unticked as it would be setting up a new GPO.

But Still.....................some how with that setting gone it is still setting it. I have checked all other GPO's and that proxy isnt specified in any of them.

hence trying to replace the DDP

Cheers
0
 
LVL 26

Expert Comment

by:Pber
ID: 24794227
Do a RSOP.MSC or use Group Policy Results from the GPMC and navigate to the proxy settings and it will tell you what policy if any is setting that setting.
0
MS Dynamics Made Instantly Simpler

Make Your Microsoft Dynamics Investment Count  & Drastically Decrease Training Time by Providing Intuitive Step-By-Step WalkThru Tutorials.

 
LVL 1

Expert Comment

by:_Fred
ID: 24794324
Maybe the setting is coming from another gpo. to make sure ru the "group polici results wizard" by right cliking "group plicy results" at the group policy management console. After it runs, select the report that was produced and select the tab settings. Click the proxy setting and see what is the wining policy. This is the policy you have to change.
0
 
LVL 1

Author Comment

by:Colchester_Institute
ID: 24794599
I did a RSOP.msc & a wizard to see if I could find anything that was going on.

In the Rsop I went to the proxy settings and the enable proxy settings was disabled, but the proxy address was still in there. in the Precedence tab it showed the Default Domain Policy in there and nothing else :-(

The wizard showed me the other gpo which was a user admin policy and that had no proxy information in it either?

Is that pointing to the DDP?

Cheers for your help so far
0
 
LVL 1

Expert Comment

by:_Fred
ID: 24794741
Now i got confused...
What you need to see is the settings tab of the group policy results at the group policy management console after you run the group policy results wizard .
There you will see what is the wining gpo for the proxy setting. If the proxy setting doesn't appear at the group policy results, then it is disabled.
0
 
LVL 1

Author Comment

by:Colchester_Institute
ID: 24794861
Got ya,

Ok under the proxy side nothing there appeared which shows like you said that nothing is being applied. Check the screenshot attached. That was the setting in the default domain policy that I took out, but it is still there and also it takes over clients sometimes with that setting instead of the correct proxy. Weird I know! And I definately know that its not being applied via any other GPO as I have gone through all of them.
proxy.JPG
0
 
LVL 1

Author Comment

by:Colchester_Institute
ID: 24840744
this setting was in the default domain policy because it was specified even though it is not ticked to be enabled. Which meant that it was being pushed out to the clients like in the screen shot, removed the setting from the gpo and it got rid of the proxy specified. But the Auto Configuration tickbox is still ticked even though it is set to disabled.
0
 

Accepted Solution

by:
ee_auto earned 0 total points
ID: 25053257
Question PAQ'd, 500 points refunded, and stored in the solution database.
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question