Solved

Unable to edit existing GPOs, but can create and edit new GPOs

Posted on 2013-06-04
10
378 Views
Last Modified: 2013-06-06
Windows 2012 Server AD DS  2 Servers
Replicating DFSR   using /SYSVOL_DFSR
I followed the Sept 2009 Migration SYSVOL to DFS Replication. It has been working well and passes all diags.
I needed to update a pointer for 300 clients so I figured out how to use preferences for registry settings by editing the direct policy for one client (same as the field) as a test I keep in my cubicle. After verifying the settings I then tried to using Group Policy Update from the GPMC, but it didn't work. I then removed all of the registry preferences. It was soon after that I was not able to edit the main policy that oversees all of the clients. I have looked around using Google and tried to follow ADSIEdit, but I couldn't locate the internal references the web page stated. I have run every separate test on dcdiag and all pass.
Based on what I read from the web I then  tried nltest:
nltest /dclist:<domain> states the FSMO is the PDC, but nltest /dcname:<domain> fails.
Also my environment requires external DNS using one way outbound trust (non transitive)
What other info do you need?
0
Comment
Question by:hatcherb1234
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 5
10 Comments
 
LVL 25

Expert Comment

by:Lionel MM
ID: 39221805
"I was not able to edit the main policy that oversees all of the clients"
What happens when you try to edit? Have you verified permissions on the folder.
C:\Windows\SYSVOL\sysvol\YourDomainName\Policies

Also this article may help you to know where and how your policies are stored (3 parts)
http://www.windowsnetworking.com/articles-tutorials/common/Group-Policy-Settings-Part1.html
0
 
LVL 1

Author Comment

by:hatcherb1234
ID: 39222470
Thanks for responding. I think you narrowed it down rather quickly. I have no SYSVOL folder under C:\Windows.

The error that pops when trying to edit states: "Failed to open the Group Policy Object. You might not have the appropiate rights."

Details:"The system cannot find the path specified"
0
 
LVL 25

Expert Comment

by:Lionel MM
ID: 39223168
Found this that may help you unless you have backups of your group policy--this answer was given to a similar question about missing sysvol and netlogon folders here on EE.
http://serverfault.com/questions/355357/new-win2008r2-dc-missing-sysvol-and-netlogon-folders
0
Office 365 Training for IT Pros

Learn how to provision Office 365 tenants, synchronize your on-premise Active Directory, and implement Single Sign-On.

 
LVL 1

Author Comment

by:hatcherb1234
ID: 39223336
As I stated in the initial question I am running DFSR not ntfrs. I think all my sysvol and netlogon are on my Drive G. See  below:

C:\Windows\system32>net share

Share name   Resource                        Remark

----------------------------------------------------------------
ADMIN$       C:\Windows                      Remote Admin
C$           C:\                             Default share
E$           E:\                             Default share
F$           F:\                             Default share
G$           G:\                             Default share
K$           K:\                             Default share
H$           H:\                             Default share
IPC$                                         Remote IPC
S$           S:\                             Default share
J$           J:\                             Default share
H            H:\
J            J:\
K            K:\
NETLOGON     G:\SYSVOL_DFSR\sysvol\MPIW.ENG.USPS.GOV\SCRIPTS
                                             Logon server share
SYSVOL       G:\SYSVOL_DFSR\sysvol           Logon server share
The command completed successfully.

This is normal for DFSR. I was able to edit after this. It was after I worked on a single client's policy that I lost the ability to edit from the common policy for all clients.
0
 
LVL 25

Expert Comment

by:Lionel MM
ID: 39223896
Did you check the permissions on those folders?
0
 
LVL 1

Author Comment

by:hatcherb1234
ID: 39223933
I don't remember. I think so. Please see the attachment. I'm not sure what the permissions shouild be for this.
permissions.jpg
0
 
LVL 25

Expert Comment

by:Lionel MM
ID: 39224145
How many sub folders do you have under SYSVOL share and what are the permissions on those? The user you are editing with is a member of which groups?
0
 
LVL 1

Author Comment

by:hatcherb1234
ID: 39225233
Please see attachments for both questions. In the meanwhile I made a brand new policy in parallel to the un-editable, but readable one and switched over to the new one and I am back in business. I'd still like to know what happened.
sysvol-folders.jpg
admin-member-of-groups.jpg
0
 
LVL 25

Accepted Solution

by:
Lionel MM earned 500 total points
ID: 39225311
Well glad to know that you are back in business--as to what happened it could have been so many things but the most likely was the migration process. It is not uncommon for this to happen and has been happening in most versions of windows server. As to specifically why I could not be sure to pinpoint one or two specific reasons--sorry.
0
 
LVL 1

Author Closing Comment

by:hatcherb1234
ID: 39225318
Well we didn't find the reason, but you taught me a few things I should have checked in the first place. Enjoy your points.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Ever notice how you can't use a new drive in Windows without having Windows assigning a Disk Signature?  Ever have a signature collision problem (especially with Virtual Machines?)  This article is intended to help you understand what's going on and…
When you upgrade from Windows 8 to 8.1 or to Windows 10 or if you are like me you are on the Insider Program you may find yourself with many 450MB recovery partitions.  With a traditional disk that may not be a problem but with relatively smaller SS…
In this Micro Tutorial viewers will learn how they can get their files copied out from their unbootable system without need to use recovery services. As an example non-bootable Windows 2012R2 installation is used which has boot problems.
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question