Solved

Server 2008 audit/registry problems

Posted on 2013-02-04
8
506 Views
Last Modified: 2013-02-11
Recently I mistakenly put a server 2008 DC into an OU with a linked GPO that had a bunch of server 2003 registry and file permission settings, some of which don't even exist by default in the server 2008 OS. After they applied I started having problems with auditing, "auditpol.exe /get /category:*" was not showing the advanced auditing settings that were supposed to be applied and everything was shown as "not configured". I have since moved it out of the OU and I am trying to get the server back to the way it was before all of the registry settings and file permissions were applied, is there a way to clear these settings back to default?
0
Comment
Question by:mdubay
  • 5
  • 3
8 Comments
 
LVL 35

Expert Comment

by:Nick Sui
Comment Utility
I hope you have rebooted the server.

Did you force the Group Policy Settings on this server?

Sys.
0
 

Author Comment

by:mdubay
Comment Utility
The machine has been rebooted since the issue has happened but I don't think that will affect the outcome much. The settings we are looking to change back are the registry entries pertaining to the security options area of the GPO, since they are registry values they have been tattooed on to the machine.

I did not force the policies onto the server they got the policies by being in the specific OU.
0
 
LVL 35

Expert Comment

by:Nick Sui
Comment Utility
Okay.

I am currently working on a tool which keeps/maintains the configuration of Operating Systems/Servers and then allow you to revert back the configuration as and when needed. It is called Configuration Maintainer. You can see more at www.Dynamic-SpotAction.com

What registry policies and settings are you talking about here? Did you apply any registry settings manually on the server?

Sys.
0
 

Author Comment

by:mdubay
Comment Utility
Yea there was a ton of registry settings changed, about 30 registry keys in all. They were changed through the GPO that was meant for 2003 but accidentally applied to a 2008 box. A lot of the registry entries changed or created do not even exist on server 2008 by default.
0
Shouldn't all users have the same email signature?

You wouldn't let your users design their own business cards, would you? So, why do you let them design their own email signatures? Think of the damage they could be doing to your brand reputation! Choose the easy way to manage set up and add email signatures for all users.

 
LVL 35

Accepted Solution

by:
Nick Sui earned 500 total points
Comment Utility
Do you have a list of registry entries handy with you or it was applied via GPO? If GPO, was it applied from multiple GPOs?

Let me see if I can find a easiest way..

Sys
0
 

Author Comment

by:mdubay
Comment Utility
Not sure if I will be able to do that or not, I will have to check our company policy. Also it seems that the audit policies have miraculously come back and are working, I will be looking into this today and will repost if i can figure out what changed. Thanks.
0
 

Author Comment

by:mdubay
Comment Utility
As expected it seems that the problem has fixed its self. We have had this problem in the past but the problem remained and we had to rebuild the DC, we got lucky on this one it seems. Thanks for the help!
0
 

Author Closing Comment

by:mdubay
Comment Utility
Was not actually a solution but he was very helpful in the troubleshooting process.
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now