Solved

Reset the Default Domain Policy GPO

Posted on 2010-11-09
4
2,716 Views
Last Modified: 2012-05-10
Dear All,

I would like to Reset the default settings of “Default Domain Policy” GPO in windows 2008 R2 domain controllers. This is due a lot of settings which we change in this Policy.

Thanks
0
Comment
Question by:Arabsoft_Security
4 Comments
 
LVL 8

Accepted Solution

by:
ShareefHuddle earned 125 total points
ID: 34099343
Use dcgpofix.exe it comes with Windows 2008. If you get a schema error follow this KB: http://support.microsoft.com/kb/947053
0
 
LVL 24

Assisted Solution

by:Awinish
Awinish earned 125 total points
ID: 34099446
DCgpofix is used in disaster recovery situation, as running dcgpofix doesn't restore the proper security permission. I haven't tried with windows 2008 R2.

http://support.microsoft.com/kb/833783

I would suggest restore the default GPO from backup or from another DC.

You can use gpotool.exe to check the GPO's are healthy.

http://blogs.technet.com/b/grouppolicy/archive/2008/10/16/restoring-default-domain-policies-to-their-defaults.aspx

Note: MS never recommends to do any settings in default domain & default domain controller policy.


0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 125 total points
ID: 34099534
Just a note about that, if you are running exchange in your environment take a look at these links (you will have to run domainprep again)

http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/31224/view/topic/Default.aspx
Thread on activedir last year

http://www.frickelsoft.net/blog/?p=25
Good entry by Florian about it.

Thanks
Mike
0
 
LVL 5

Assisted Solution

by:balmasri
balmasri earned 125 total points
ID: 34100075
in your lab, prepare a domain and backup the "Default Domain Policy GPO " and restore it to your domain .

run DcGPOFix [/ignoreschema] [/Target: Domain | DC | Both].  will keep the same settings.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question