Solved

Server 2008 GPO Help

Posted on 2010-11-26
7
1,127 Views
Last Modified: 2012-05-10
I had help from some members here to setup GPO to user accounts on Server 2008 back in February of this year. We setup a restriction so one account no matter what PC it logged into could only run certain exe files. In my GPO Management console when I edit the GPO assigned to that login I cannot find where we did this and in software restrictions it says nothing has been defined. I know its enforced since its been used and the PC's tell me its enforced. Where do I look to add a few exe files ?
0
Comment
Question by:sraley
  • 5
7 Comments
 
LVL 23

Expert Comment

by:Stelian Stan
ID: 34219489
To find out the settings run Group Policy Management tool > Select the GPO you assigned and on the right side click on "Settings". It should show you all the settings for that GPO.
0
 
LVL 5

Expert Comment

by:Seth_McCauley
ID: 34219544
Perhaps this restriction was added to a different policy. You could try running the Group Policy Modeling wizard to find out which policy the software restriction was added to. From the GP management console, right-click on the OU your test user resides in, then select "Group Policy Modeling". You can pretty much hit "next" all the way through the wizard. Once it's finished, click the "Settings" tab and you should see all the settings that apply to that user, plus the policy they were applied in. You might also need to do this for the OU the computer resides in.
0
 

Author Comment

by:sraley
ID: 34220197
yes I used GPMC and clicked settings and get

Security Settingshide
An error has occurred while collecting data for Software Restriction Policies.

This error impacts the following settings:
Software Restriction Policies
Software Restriction Policies/Security Levels
Software Restriction Policies/Additional Rules  
The following errors apply to all of the above settings:
An unknown error occurred while data was gathered for this extension. Details: Unable to cast object of type 'System.String[]' to type 'Microsoft.GroupPolicy.Reporting.Extensions.Registry.UnknownType'.
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 

Author Comment

by:sraley
ID: 34220201
running the model wizard, the results say because of security filtering my 3 GPO's are all showing up in the denied applied GPO's.
0
 

Author Comment

by:sraley
ID: 34222793
the wizard still gives me the security filtering errors but I found the hotfix that I can see the settings tab correctly so I know that the GPO is in effect that all exe files are blocked but I can not find the location of where I have a list of what is allowed, like msword.exe and excel.exe. Where do i get to this list?
0
 

Accepted Solution

by:
sraley earned 0 total points
ID: 34222808
nevermind foudn the list under user->administrative templates-> system
0
 

Author Closing Comment

by:sraley
ID: 34255740
Figured it out.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you migrate a Terminal Server licenses server inside the 2008 server family, you can takte advantage of the build-in migration tool. If you like to migrate an older 2003 Server (and the installed client CALs) to a 2008 R2 server for example, you …
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question