?
Solved

Registry change using Gpo

Posted on 2011-09-06
10
Medium Priority
?
1,051 Views
Last Modified: 2012-05-12
Hi,

We are using Windows Server 2003 domain contollers. Our clinet machines are running in Windows XP. I need to modify the following registy key on all our clinet machines using group policy.

Currently the registy setting is having the value 1 and I need to change it to 0 using gpo.


"Hkey_Local_Machine\System\CurrentConrolSet\Control\Filesystem\NtfsDisable8dot3NameCreation"

The above reg value should be 0.

Can you please provide me any .adm template or the corresponding settings in the GPMC console for this.

Thanks in advance.
0
Comment
Question by:gaddam01
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
10 Comments
 
LVL 10

Expert Comment

by:cjrmail2k
ID: 36487638
...configure this Policy (WS2008 R2 here): Computer Configuration\Policies\Administrative Templates\System\Filesystem\NTFS\Short Name Creation Options

I know this is for 2008 but it may exist in 2003
0
 

Author Comment

by:gaddam01
ID: 36487678
The above the options is not available in Windows Server 2003.
0
 
LVL 39

Accepted Solution

by:
Krzysztof Pytko earned 2000 total points
ID: 36487682
Hi try with that

CLASS MACHINE

CATEGORY "NTFS Management"

KEYNAME "System\CurrentConrolSet\Control\Filesystem"

      POLICY "8dot3 Name Creation"

      EXPLAIN "Disables 8dot3 Name Creation"
      SUPPORTED "Windows 2000+"
      VALUENAME "NtfsDisable8dot3NameCreation"
      VALUEON NUMERIC 0
      VALUEOFF NUMERIC 1

      END POLICY

END CATEGORY

if you have at least one 2008 DC, you can use for that GPP (Group Policy Preferences) but first of all you have to install CSE (cClient Side Extension) on that server 2003

Regards,
Krzysztof
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:gaddam01
ID: 36487917
Hello,

Hi try with that

CLASS MACHINE

CATEGORY "NTFS Management"

KEYNAME "System\CurrentConrolSet\Control\Filesystem"

      POLICY "8dot3 Name Creation"

      EXPLAIN "Disables 8dot3 Name Creation"
      SUPPORTED "Windows 2000+"
      VALUENAME "NtfsDisable8dot3NameCreation"
      VALUEON NUMERIC 0
      VALUEOFF NUMERIC 1

      END POLICY

END CATEGORY


If the above code I had save it as .adm template then where is the location in GPMC I can configure this??
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36487986
You need to download GPMC as separate installation fole (it's not included within 2003) from
http://www.microsoft.com/download/en/details.aspx?id=21895

Krzysztof
0
 

Author Comment

by:gaddam01
ID: 36488059
Hello,

I had already installed GPMC. Can you please specify the path for the registy settings where I need to configure in the Group policy Editor?
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36488153
OK, you need to run GPMC and create new GPO or select the existing one. Now, edit it, and select "Computer Configuration -> Administrative Templates". Click on it right mouse button and choose "Add/Remove Templates" point to the location where ADM file is saved. Now, go to menu "View -> Filtering" and unselect both checkboxes at the bottom.
Now, you should be able to see new node "NTFS Management". Configure there "8dot3 Name Creation" and choose "Enabled"
Link GPO to appropriate OU with computers and reboot it to take it effect

Krzysztof
0
 

Author Comment

by:gaddam01
ID: 36572019
I've requested that this question be closed as follows:

Accepted answer: 0 points for gaddam01's comment http:/Q_27292704.html#36487917

for the following reason:

solution worked for me.
0
 

Author Comment

by:gaddam01
ID: 36572020
I need to raise one more question. So please close this question now.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question