Solved

Server 2008 audit/registry problems

Posted on 2013-02-04
8
511 Views
Last Modified: 2013-02-11
Recently I mistakenly put a server 2008 DC into an OU with a linked GPO that had a bunch of server 2003 registry and file permission settings, some of which don't even exist by default in the server 2008 OS. After they applied I started having problems with auditing, "auditpol.exe /get /category:*" was not showing the advanced auditing settings that were supposed to be applied and everything was shown as "not configured". I have since moved it out of the OU and I am trying to get the server back to the way it was before all of the registry settings and file permissions were applied, is there a way to clear these settings back to default?
0
Comment
Question by:mdubay
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
8 Comments
 
LVL 35

Expert Comment

by:Nirmal Sharma
ID: 38851530
I hope you have rebooted the server.

Did you force the Group Policy Settings on this server?

Sys.
0
 

Author Comment

by:mdubay
ID: 38851823
The machine has been rebooted since the issue has happened but I don't think that will affect the outcome much. The settings we are looking to change back are the registry entries pertaining to the security options area of the GPO, since they are registry values they have been tattooed on to the machine.

I did not force the policies onto the server they got the policies by being in the specific OU.
0
 
LVL 35

Expert Comment

by:Nirmal Sharma
ID: 38854122
Okay.

I am currently working on a tool which keeps/maintains the configuration of Operating Systems/Servers and then allow you to revert back the configuration as and when needed. It is called Configuration Maintainer. You can see more at www.Dynamic-SpotAction.com

What registry policies and settings are you talking about here? Did you apply any registry settings manually on the server?

Sys.
0
Free eBook: Backup on AWS

Everything you need to know about backup and disaster recovery with AWS, for FREE!

 

Author Comment

by:mdubay
ID: 38855620
Yea there was a ton of registry settings changed, about 30 registry keys in all. They were changed through the GPO that was meant for 2003 but accidentally applied to a 2008 box. A lot of the registry entries changed or created do not even exist on server 2008 by default.
0
 
LVL 35

Accepted Solution

by:
Nirmal Sharma earned 500 total points
ID: 38857954
Do you have a list of registry entries handy with you or it was applied via GPO? If GPO, was it applied from multiple GPOs?

Let me see if I can find a easiest way..

Sys
0
 

Author Comment

by:mdubay
ID: 38875959
Not sure if I will be able to do that or not, I will have to check our company policy. Also it seems that the audit policies have miraculously come back and are working, I will be looking into this today and will repost if i can figure out what changed. Thanks.
0
 

Author Comment

by:mdubay
ID: 38877337
As expected it seems that the problem has fixed its self. We have had this problem in the past but the problem remained and we had to rebuild the DC, we got lucky on this one it seems. Thanks for the help!
0
 

Author Closing Comment

by:mdubay
ID: 38877344
Was not actually a solution but he was very helpful in the troubleshooting process.
0

Featured Post

Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
server Downtime & up time for last45days for multiple servers 6 52
Separate DNS forwarding 2 47
Time sync on Domain 5 42
IE Shortcut - How to open in MAXIMIZED size 11 70
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
It’s been over a month into 2017, and there is already a sophisticated Gmail phishing email making it rounds. New techniques and tactics, have given hackers a way to authentically impersonate your contacts.How it Works The attack works by targeti…
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question