[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 746
  • Last Modified:

Locked out of GPM

I have locked myself out of the GPO manager and I need to get back in. Silly thing to do but I wasn't thinking, I guess.

Environment
Windows 2008 R2 server that is the DC and a RDS (terminal server) for about ten users. There is a 2003 server that is part of the domain but does not have AD loaded though I certainly could do that if necessary.

Problem
So...... I created a GPO to lock down the RDS (formerly terminal service) sessions of the users. I locked down the ability for snap-ins to run as well as the ability of the user to  use the command prompt.  Unfortunately, the Administrator was a part of the group so now the Administrator has no ability to modify GPOs or manage the server -- snap-ins will not work from either a RDS session or from the console.

I sort of did the age old mistake of deleting the administrator account without first making another account with administrative rights and permissions.

Question:
Is there anyway anyone can think of that will get the administrator the rights to modify GPOs so as to allow me control of the 2008 machine?

Seems to me that I need to either modify or delete the current GPO. Can I use PSEXEC or the 2003 server in anyway?

Al
0
albevier
Asked:
albevier
  • 2
1 Solution
 
Mike KlineCommented:
Do you have any admin accounts to use on the domain or do you not have any accounts to use.

If you have an account you can install GPMC on the 2003 box and login with the account and modify the policy

http://www.microsoft.com/en-us/download/details.aspx?id=21895

Thanks

Mike
0
 
albevierAuthor Commented:
Bwahahahah! I like it! Let me give it a go!  HA! ur a geeen-eeee-US, Mike! I'm back in with no disruption to anyone in the office!

Thanks!

Al
0
 
Mike KlineCommented:
No problem, best part was no disruption to anyone :)

I was in a looooonnnnggg time ago (93-97).   I'll be 38 in a few months...old Hooah! :)
0

Featured Post

Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now