Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Unable to edit existing GPOs, but can create and edit new GPOs

Posted on 2013-06-04
10
Medium Priority
?
382 Views
Last Modified: 2013-06-06
Windows 2012 Server AD DS  2 Servers
Replicating DFSR   using /SYSVOL_DFSR
I followed the Sept 2009 Migration SYSVOL to DFS Replication. It has been working well and passes all diags.
I needed to update a pointer for 300 clients so I figured out how to use preferences for registry settings by editing the direct policy for one client (same as the field) as a test I keep in my cubicle. After verifying the settings I then tried to using Group Policy Update from the GPMC, but it didn't work. I then removed all of the registry preferences. It was soon after that I was not able to edit the main policy that oversees all of the clients. I have looked around using Google and tried to follow ADSIEdit, but I couldn't locate the internal references the web page stated. I have run every separate test on dcdiag and all pass.
Based on what I read from the web I then  tried nltest:
nltest /dclist:<domain> states the FSMO is the PDC, but nltest /dcname:<domain> fails.
Also my environment requires external DNS using one way outbound trust (non transitive)
What other info do you need?
0
Comment
Question by:hatcherb1234
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 5
10 Comments
 
LVL 25

Expert Comment

by:Lionel MM
ID: 39221805
"I was not able to edit the main policy that oversees all of the clients"
What happens when you try to edit? Have you verified permissions on the folder.
C:\Windows\SYSVOL\sysvol\YourDomainName\Policies

Also this article may help you to know where and how your policies are stored (3 parts)
http://www.windowsnetworking.com/articles-tutorials/common/Group-Policy-Settings-Part1.html
0
 
LVL 1

Author Comment

by:hatcherb1234
ID: 39222470
Thanks for responding. I think you narrowed it down rather quickly. I have no SYSVOL folder under C:\Windows.

The error that pops when trying to edit states: "Failed to open the Group Policy Object. You might not have the appropiate rights."

Details:"The system cannot find the path specified"
0
 
LVL 25

Expert Comment

by:Lionel MM
ID: 39223168
Found this that may help you unless you have backups of your group policy--this answer was given to a similar question about missing sysvol and netlogon folders here on EE.
http://serverfault.com/questions/355357/new-win2008r2-dc-missing-sysvol-and-netlogon-folders
0
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 1

Author Comment

by:hatcherb1234
ID: 39223336
As I stated in the initial question I am running DFSR not ntfrs. I think all my sysvol and netlogon are on my Drive G. See  below:

C:\Windows\system32>net share

Share name   Resource                        Remark

----------------------------------------------------------------
ADMIN$       C:\Windows                      Remote Admin
C$           C:\                             Default share
E$           E:\                             Default share
F$           F:\                             Default share
G$           G:\                             Default share
K$           K:\                             Default share
H$           H:\                             Default share
IPC$                                         Remote IPC
S$           S:\                             Default share
J$           J:\                             Default share
H            H:\
J            J:\
K            K:\
NETLOGON     G:\SYSVOL_DFSR\sysvol\MPIW.ENG.USPS.GOV\SCRIPTS
                                             Logon server share
SYSVOL       G:\SYSVOL_DFSR\sysvol           Logon server share
The command completed successfully.

This is normal for DFSR. I was able to edit after this. It was after I worked on a single client's policy that I lost the ability to edit from the common policy for all clients.
0
 
LVL 25

Expert Comment

by:Lionel MM
ID: 39223896
Did you check the permissions on those folders?
0
 
LVL 1

Author Comment

by:hatcherb1234
ID: 39223933
I don't remember. I think so. Please see the attachment. I'm not sure what the permissions shouild be for this.
permissions.jpg
0
 
LVL 25

Expert Comment

by:Lionel MM
ID: 39224145
How many sub folders do you have under SYSVOL share and what are the permissions on those? The user you are editing with is a member of which groups?
0
 
LVL 1

Author Comment

by:hatcherb1234
ID: 39225233
Please see attachments for both questions. In the meanwhile I made a brand new policy in parallel to the un-editable, but readable one and switched over to the new one and I am back in business. I'd still like to know what happened.
sysvol-folders.jpg
admin-member-of-groups.jpg
0
 
LVL 25

Accepted Solution

by:
Lionel MM earned 1500 total points
ID: 39225311
Well glad to know that you are back in business--as to what happened it could have been so many things but the most likely was the migration process. It is not uncommon for this to happen and has been happening in most versions of windows server. As to specifically why I could not be sure to pinpoint one or two specific reasons--sorry.
0
 
LVL 1

Author Closing Comment

by:hatcherb1234
ID: 39225318
Well we didn't find the reason, but you taught me a few things I should have checked in the first place. Enjoy your points.
0

Featured Post

Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
Know what services you can and cannot, should and should not combine on your server.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question