Solved

How do I reset all domain group policy to defaults.

Posted on 2010-11-15
12
1,061 Views
Last Modified: 2012-05-10
Hello everyone.  

I have a small problem in group policy.  I had a 2003 R2 DC.  Then I added a 2008 Std & then a 2008 R2 Ent. DC.  Then I removed the 2003 R2 from the domain.  Raised the domain and forest functional level to 2008.

I'm having problems with Offline files on some windows 7 and XP computers.  I have my group policy off.  (default)  With GP off, a couple workstations are still trying to sync offline files to the 2003 R2 DC, which is not in the domain anymore.  I removed the Offline GP before I removed the 2003 R2 DC.  I also checked that its not applied anymore.  Right now, gpresult gives me nothing that will help.

 I also have System Center Essentials Installed, and that's the only GP that is applied.

In the GP "SCE Managed Computers Group Policy (MAIN_MG)" I'm getting an error- telling me I have to update my ADM files.  How do I update them, and which ones?

Please help.  
(I'm from Russia, and a couple of my servers are in Russian, so posting logs.. or something... I think will not help, unless you know Russian ))).  Please ask, I will try to translate my logs and errors as close as possible to the original English Server OS)

Thanx
0
Comment
Question by:Alex-Dryagin
  • 5
  • 3
  • 2
  • +2
12 Comments
 
LVL 21

Expert Comment

by:RK
ID: 34135947
After removing  old DC from the domain via ntdsutil or dcpromo, you have to manually remove the dns entry for the old server from your dns console & Active directory sites and service, If not, the client will always look for the old server which is not in the domain.

"Good Luck"
0
 
LVL 1

Author Comment

by:Alex-Dryagin
ID: 34136229
Did that just right after I ran dcpromo...
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 34136912
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 24

Accepted Solution

by:
Awinish earned 500 total points
ID: 34136943
You need to reapply the policy with modified the setting the changes can be applied & make it not configured & apply on those affected pc.

Sometime, removing the system from the domain should quit all the GPO settings but if its not, you need to manually delete the entry from registry or repair the system.

Try below KB, which might help you & its applied for windows 7 too.
http://support.microsoft.com/kb/313222

http://blogs.technet.com/b/askds/archive/2009/03/12/how-to-properly-disable-offline-files-in-windows-vista.aspx

http://forums.cnet.com/7723-6142_102-125598.html


0
 
LVL 20

Expert Comment

by:Iain MacMillan
ID: 34136956
normally i would suggest putting the 2003 DC back online, but you have raised the domain level up, which is a one way process as far as i know.  The offline sync issue with XP systems might be due to the change in GP not propagating through your LAN before you shut the old DC down, but as long as you disable use of it on your current domain policy, then it should stop some if the issues until you get everything else fixed.  if you demoted the old DC correctly and waited for propagation and sync, then you shouldn't need to make changes in Sites and Services.  Check your DNS and DHCP scope properties as well, and make sure only your current DC's are listed.  You might want to check any systems which do not list on the DHCP, as they likely have static addresses which will reference the old DC (such as other servers, printers and test systems).

that said i know how to reset the domain if you have 2003 DC's, not sure if the same process will work for 2008 - let me know if you wish me to post the details.

I have both types of DC for many reasons, XP does not use the ADMX templates that Win 7 and 2008 do, and I still have 2003 Exchange server, so i use a 2003 DC Server to help with policies and using Exchange System Manager (I now run Win 7 64bit, which cannot run ESM 2003).
0
 
LVL 1

Author Comment

by:Alex-Dryagin
ID: 34140084
dariusg, Thak you for the link.

This is what I forgot to do... big mistake.
Important All users who are affected by your GPO modification must log off and back on to any computers where they have logged on before the changes are applied. You must apply these changes to the user's computer before you go to the next step.

Is there a way to undo or clear the GP that is probably still being applied?

What can I do?  Removing the computer from the domain and then back doesn't help... any ideas?
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 34140148
You need to make sure that the GPO is gone or readd the GPO back then properly stop the redirection. Or you can go into the registry to remove the key that holds this information
0
 
LVL 1

Author Comment

by:Alex-Dryagin
ID: 34147281
The thing is, I can't re-add the GPO back because someone deleted it when I was on a vacation...  but, before I removed the GPO, I properly stopped folder redirection.  The thing is I forgot that users who are affected by your GPO modification must log off and back on....  So I have the GPO someplace in the registry that is still being applied to some computers that I don't see.

Where can I find the GPO in the registry?

Many thanx in advance!
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34147472
Did you check the link i posted?
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 34147637
0
 
LVL 1

Author Closing Comment

by:Alex-Dryagin
ID: 34154491
Simple and clear
0
 
LVL 1

Author Comment

by:Alex-Dryagin
ID: 34154498
Thanx everyone for the help!!  Topic closed.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question