Solved

Reset the Default Domain Policy GPO

Posted on 2010-11-09
4
2,668 Views
Last Modified: 2012-05-10
Dear All,

I would like to Reset the default settings of “Default Domain Policy” GPO in windows 2008 R2 domain controllers. This is due a lot of settings which we change in this Policy.

Thanks
0
Comment
Question by:Arabsoft_Security
4 Comments
 
LVL 8

Accepted Solution

by:
ShareefHuddle earned 125 total points
ID: 34099343
Use dcgpofix.exe it comes with Windows 2008. If you get a schema error follow this KB: http://support.microsoft.com/kb/947053
0
 
LVL 24

Assisted Solution

by:Awinish
Awinish earned 125 total points
ID: 34099446
DCgpofix is used in disaster recovery situation, as running dcgpofix doesn't restore the proper security permission. I haven't tried with windows 2008 R2.

http://support.microsoft.com/kb/833783

I would suggest restore the default GPO from backup or from another DC.

You can use gpotool.exe to check the GPO's are healthy.

http://blogs.technet.com/b/grouppolicy/archive/2008/10/16/restoring-default-domain-policies-to-their-defaults.aspx

Note: MS never recommends to do any settings in default domain & default domain controller policy.


0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 125 total points
ID: 34099534
Just a note about that, if you are running exchange in your environment take a look at these links (you will have to run domainprep again)

http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/31224/view/topic/Default.aspx
Thread on activedir last year

http://www.frickelsoft.net/blog/?p=25
Good entry by Florian about it.

Thanks
Mike
0
 
LVL 5

Assisted Solution

by:balmasri
balmasri earned 125 total points
ID: 34100075
in your lab, prepare a domain and backup the "Default Domain Policy GPO " and restore it to your domain .

run DcGPOFix [/ignoreschema] [/Target: Domain | DC | Both].  will keep the same settings.
0

Join & Write a Comment

Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now