ADM file compatibility

Hello, we have a client who would like to use USB storage restriction the way it can be set up on a Windows Server 2008 domain, except they have a Windows Server 2003 domain at this time.  Windows Server 2003 and Windows XP only use registry based USB storage restriction.  Is it possible to use Windows Server 2008 ADMX files on a Windows Server 2003 domain controller if the files are renamed to ADM from ADMX?  Thanks for any help and suggestions, Mike
miket71Asked:
Who is Participating?
 
Krzysztof PytkoConnect With a Mentor Active Directory EngineerCommented:
Nope, you cannot simply rename ADMX/ADML to ADM because of different structure. ADM is some kind of "script" syntax while ADMX uses XML structure. Of course you can convert ADM into ADMX using ADMX Migrator from Microsoft
http://www.microsoft.com/downloads/en/details.aspx?FamilyId=0F1EEC3D-10C4-4B5F-9625-97C2F731090C&displaylang=en

but, few things :)

1) When you have 2008 in that domain, you can simply use GPP (Group Policy Preference) to modify registry on those clients. First, you need to install on them CSE (Client Side Extension) manually and it will work

XP CSE -> http://www.microsoft.com/downloads/en/details.aspx?FamilyID=e60b5c8f-d7dc-4b27-a261-247ce3f6c4f8&displaylang=en

2003 CSE -> http://www.microsoft.com/downloads/en/details.aspx?FamilyID=bfe775f9-5c34-44d0-8a94-44e47db35add&
displaylang=en

or use WSUS to issue this update.

2) Create custom ADM file for that and import to 2003/2008 GPO (2008 is compatible with classic administrative templates)
Good one is here
http://www.petri.co.il/disable_writing_to_usb_disks_in_xp_sp2_with_gpo.htm

3) You can create appropriate registry files and import them as startup scripts

1 and 2 are better but 3 could be treated as workaround for those 2 if won't work

Regards,
Krzysztof
0
 
miket71Author Commented:
We just downloaded ADML (ADMX) files from the Windows Server 2008 Administrative Templates by Microsoft, but they look much different than the ADM files for Windows Server 2003.  We are wondering if the code or syntax in an ADML file would have to be converted in order for a 2003 domain controller to understand it.
0
 
miket71Author Commented:
If we convert all of the 2003 ADM files to ADMX with the migration tool, will we then be able to import an ADML file provided by 2008 to use with the converted 2003 ADMs?  We would like to ultimately use the following 2008 ADML file on the 2003 domain:

removablestorage.adml

We don't know when they will purchase a 2008 server to use in the future.  We only have XP/2003 for now.

What is the difference between ADML and ADMX?

Thanks, Mike
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
Krzysztof PytkoActive Directory EngineerCommented:
Yes, because you have 2008 Server which "understands" ADMX/ADML structure. Then create GPO on 2008 DC in GPMC and link it to appropriate Ou(s)

Krzysztof
0
 
miket71Author Commented:
Yes, but the problem is that we do not have Server 2008 right now, and we will not for the forseeable future, so with  that being said, is it possible to do what was explained in our previous post?
0
 
Krzysztof PytkoActive Directory EngineerCommented:
Nope :)

This situation allows you only to use ADM (classic) files :(

Krzysztof
0
 
Donald StewartNetwork AdministratorCommented:
Server 2008 group policy doesnt disable USB any differently than 2003, it's the drivers that get disabled from starting up


http://support.microsoft.com/kb/555324


The ADM template in this article allows an Administrator to disable the respective drivers of these devices, ensuring that they cannot be used.
0
 
miket71Author Commented:
Okay thanks.  They are looking to only allow a specific brand name USB drive to read/write while denying all others.  I found a doc where that can be done once the device ID, hardware ID, and/or instance ID can be used to set it up in group policy, but that only applied to Vista/7/2008 as well.
0
 
Krzysztof PytkoActive Directory EngineerCommented:
Yes, because it is new GPO setting in 2008/7 It's not available in previous systems like 2003/XP

Krzysztof
0
 
Donald StewartNetwork AdministratorCommented:
And any new GPO setting in 2008 you can still apply to 2003/XP with Client Side Extensions
0
 
Donald StewartConnect With a Mentor Network AdministratorCommented:
0
All Courses

From novice to tech pro — start learning today.