Solved

Error trying to open Group policy Management Editor in Server 2008 R2

Posted on 2011-03-19
20
1,179 Views
Last Modified: 2012-08-14
When trying to open and make changes to an existing group policy in Server 2008 R2, I receive  the following error. "Group Policy Error, failed to open the group policy object, you may not have appropriate rights."

I was just making some final changes to this group policy object on this new server and was about to create a backup of the settings. So, unfortunately I can't restore the policy settings from backup. I think I remember a similar issue from Serve 2003 where I was able to use volume shadow copy to restore a registry.pol or something to that effect to get this back working again, but I'm not sure.

Is there a way to fix this issue? Thanks for your assistance.
0
Comment
Question by:skenny10
20 Comments
 
LVL 10

Expert Comment

by:Bawer
ID: 35172833
make sure you have enough permissions on SYSVOL folder.
0
 
LVL 8

Expert Comment

by:ActiveDirectoryman
ID: 35172867

You must have read or write access to the gplink and gpoptions propeties on the gpo.

What account are you using to try to edit the gpo?

By default, domain admins have this right.

make sure you have read and write access to the gpo you are trying to modify.

delegating group policy
http://technet.microsoft.com/en-us/library/cc776858(WS.10).aspx
0
 

Author Comment

by:skenny10
ID: 35172889

The permissions are fine. I have been in and out of this policy many times as I have been creating it. I am logged onto the server as an administrator. I just received this error all of a sudden.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 35173270
Run dcdiag post results
0
 

Author Comment

by:skenny10
ID: 35173420
Directory Server Diagnosis Performing initial setup:    Trying to find home server...    Home Server = ANNE    * Identified AD Forest.
   Done gathering initial info. Doing initial required tests    Testing server: Default-First-Site-Name\ANNE       Starting test: Connectivity          ......................... ANNE passed test Connectivity Doing primary tests    Testing server: Default-First-Site-Name\ANNE       Starting test: Advertising          ......................... ANNE passed test Advertising       Starting test: FrsEvent          ......................... ANNE passed test FrsEvent       Starting test: DFSREvent         ......................... ANNE passed test DFSREvent       Starting test: SysVolCheck          ......................... ANNE passed test SysVolCheck       Starting test: KccEvent          ......................... ANNE passed test KccEvent       Starting test: KnowsOfRoleHolders          ......................... ANNE passed test KnowsOfRoleHolders       Starting test: MachineAccount          ......................... ANNE passed test MachineAccount       Starting test: NCSecDesc          Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have              Replicating Directory Changes In Filtered Set
        access rights for the naming context:          DC=ForestDnsZones,DC=cec,DC=local
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have              Replicating Directory Changes In Filtered Set
         access rights for the naming context:          DC=DomainDnsZones,DC=cec,DC=local
         ......................... ANNE failed test NCSecDesc
      Starting test: NetLogons          ......................... ANNE passed test NetLogons       Starting test: ObjectsReplicated          ......................... ANNE passed test ObjectsReplicated       Starting test: Replications          ......................... ANNE passed test Replications       Starting test: RidManager          ......................... ANNE passed test RidManager       Starting test: Services          ......................... ANNE passed test Services       Starting test: SystemLog          An error event occurred.  EventID: 0x00000457             Time Generated: 03/19/2011   16:46:30             Event String:             Driver Lexmark Optra S 1625 (MS) required for printer Lexmark Tech area is unknown. Contact the administrator to install the driver before you log in again.          An error event occurred.  EventID: 0x00000457            Time Generated: 03/19/2011   16:46:31             Event String:             Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.          An error event occurred.  EventID: 0x00000457             Time Generated: 03/19/2011   16:46:32             Event String:             Driver Microsoft Office Live Meeting 2007 Document Writer Driver required for printer Microsoft Office Live Meeting 2007 Document Writer is unknown. Contact the administrator to install the driver before you log in again.          An error event occurred.  EventID: 0x00000457             Time Generated: 03/19/2011   16:46:34             Event String:             Driver PrimoPDF required for printer PrimoPDF is unknown. Contact the administrator to install the driver before you log in again.          An error event occurred.  EventID: 0x00000457             Time Generated: 03/19/2011   16:46:34             Event String:             Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.          An error event occurred.  EventID: 0x00000457
            Time Generated: 03/19/2011   16:46:35             Event String:             Driver Lexmark Optra S 1625 (MS) required for printer WebEx Document Loader is unknown. Contact the administrator to install the driver before you log in again.          An error event occurred.  EventID: 0x00000457             Time Generated: 03/19/2011   16:46:39             Event String:             Driver Lexmark C532 required for printer !!server1!Lexmark C532 is unknown. Contact the administrator to install the driver before you log in again.          ......................... ANNE failed test SystemLog       Starting test: VerifyReferences          ......................... ANNE passed test VerifyReferences    Running partition tests on : ForestDnsZones       Starting test: CheckSDRefDom          ......................... ForestDnsZones passed test CheckSDRefDom       Starting test: CrossRefValidation          ......................... ForestDnsZones passed test          CrossRefValidation   Running partition tests on : DomainDnsZones       Starting test: CheckSDRefDom          ......................... DomainDnsZones passed test CheckSDRefDom       Starting test: CrossRefValidation          ......................... DomainDnsZones passed test          CrossRefValidation    Running partition tests on : Schema       Starting test: CheckSDRefDom          ......................... Schema passed test CheckSDRefDom       Starting test: CrossRefValidation          ......................... Schema passed test CrossRefValidation    Running partition tests on : Configuration       Starting test: CheckSDRefDom          ......................... Configuration passed test CheckSDRefDom       Starting test: CrossRefValidation          ......................... Configuration passed test CrossRefValidation    Running partition tests on : cec       Starting test: CheckSDRefDom          ......................... cec passed test CheckSDRefDom       Starting test: CrossRefValidation          ......................... cec passed test CrossRefValidation
   
   Running enterprise tests on : cec.local      Starting test: LocatorCheck          ......................... cec.local passed test LocatorCheck       Starting test: Intersite          ......................... cec.local passed test Intersite
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 35207227
dcdiag is very hard to read in that format
0
 

Author Comment

by:skenny10
ID: 35207772
Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = ANNE
   * Identified AD Forest.
   Done gathering initial info.
Doing initial required tests
  Testing server: Default-First-Site-Name\ANNE
      Starting test: Connectivity
         ......................... ANNE passed test Connectivity

Doing primary tests
 
   Testing server: Default-First-Site-Name\ANNE
      Starting test: Advertising
         ......................... ANNE passed test Advertising
      Starting test: FrsEvent
         ......................... ANNE passed test FrsEvent
      Starting test: DFSREvent
         ......................... ANNE passed test DFSREvent
      Starting test: SysVolCheck
         ......................... ANNE passed test SysVolCheck
      Starting test: KccEvent
         ......................... ANNE passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... ANNE passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... ANNE passed test MachineAccount
      Starting test: NCSecDesc
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=cec,DC=local
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=DomainDnsZones,DC=cec,DC=local
         ......................... ANNE failed test NCSecDesc

      Starting test: NetLogons
        ......................... ANNE passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... ANNE passed test ObjectsReplicated
      Starting test: Replications
         ......................... ANNE passed test Replications
      Starting test: RidManager
         ......................... ANNE passed test RidManager
      Starting test: Services
         ......................... ANNE passed test Services
      Starting test: SystemLog
         An error event occurred.  EventID: 0x00000457
            Time Generated: 03/24/2011   09:16:20
            Event String:
            Driver Lexmark Optra S 1625 (MS) required for printer Lexmark Tech area is unknown. Contact the administrator to install the driver before you log in again.
         An error event occurred.  EventID: 0x00000457
           Time Generated: 03/24/2011   09:16:23
            Event String:
            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 03/24/2011   09:16:25
            Event String:
            Driver PrimoPDF required for printer PrimoPDF is unknown. Contact the administrator to install the driver before you log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 03/24/2011   09:16:25
           Event String:
            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 03/24/2011   09:16:26
            Event String:
            Driver Microsoft Office Live Meeting 2007 Document Writer Driver required for printer Microsoft Office Live Meeting 2007 Document Writer is unknown. Contact the administrator to install the driver before you log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 03/24/2011   09:16:28
            Event String:
            Driver Lexmark C532 required for printer !!server1!Lexmark C532 is unknown. Contact the administrator to install the driver before you log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 03/24/2011   09:16:29
            Event String:
            Driver Lexmark Optra S 1625 (MS) required for printer WebEx Document Loader is unknown. Contact the administrator to install the driver before you log in again.
        ......................... ANNE failed test SystemLog
      Starting test: VerifyReferences
         ......................... ANNE passed test VerifyReferences
 
   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation
 
   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation
   
   Running partition tests on : Schema
      Starting test: CheckSDRefDom
        ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
 
   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
 
   Running partition tests on : cec
      Starting test: CheckSDRefDom
         ......................... cec passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... cec passed test CrossRefValidation
 
   Running enterprise tests on : cec.local
      Starting test: LocatorCheck
         ......................... cec.local passed test LocatorCheck
      Starting test: Intersite
         ......................... cec.local passed test Intersite

0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 35207843
Everything looks good.

Right-click then click Run As
0
 

Author Comment

by:skenny10
ID: 35207910
Not sure what you mean. I get this error trying to open the policy.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 35207976
Is it for this policy only?
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:skenny10
ID: 35208012
Yes
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 35208232
Is this a new domain controller? Was this GPO created on this DC?
0
 

Author Comment

by:skenny10
ID: 35208538
It is a new domain controller, a secondary server in an existing domain. The GPO was created on this domain controller by myself. I was in and out of this policy dozens of times making changes before this error occurred.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 35208642
Policy is still in SYSVOl folder?
0
 

Author Comment

by:skenny10
ID: 35208654
yes
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 35208722
Have you tried opening from another station?
0
 

Author Comment

by:skenny10
ID: 35208757
Yes, no luck. I am assuming the policy is just corrupt at this point and that I will have to replace.
0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 500 total points
ID: 35208797
Could be corrupt if you can't open from another workstation or DC
0
 

Author Comment

by:skenny10
ID: 35208835
Yes, that is what I am assuming. Thanks for your assistance along the way.
0
 

Author Closing Comment

by:skenny10
ID: 35208838
thanks
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now