Avatar of wiglack
wiglackFlag for United States of America

asked on 

Default Domain Policy deleted

I have a 2012 test server.  I was messing around with a central store for gpo's.  While I was creating the centralized store, I renamed the wrong folder.  This caused group policy management to display an error that I couldn't find or read the GPO for the default domain policy.  Before I figured out that I renamed the wrong directory, I deleted the default domain policy, so that I could recreate it.  I later found that I had renamed the wrong directory in sysvol.  But the damage was done and now I can't create a default policy.
I can't quite figure out how to recreate it.  Can anyone help?

BTW I could easily just wipe the domain and start over, but I want to learn how to recover from an error like this incase I encounter a client who did something as stupid as me, but in production.
Windows Server 2012Active Directory

Avatar of undefined
Last Comment
wiglack
Avatar of Rob Stone
Rob Stone
Flag of United Kingdom of Great Britain and Northern Ireland image

Avatar of Nick Rhode
Nick Rhode
Flag of United States of America image

You can probably use the command: dcgpofix

http://technet.microsoft.com/en-us/library/hh875588.aspx
Avatar of wiglack
wiglack
Flag of United States of America image

ASKER

I already tried dcgpofix.  That didn't work.  I hadn't tried with the /ignorschema switch, but that didn't work either.

@Stoner79: I tried the first kb article you posted, but there is on GPO tab in ADUC.  Any suggestions?
Avatar of Mike Kline
Mike Kline
Flag of United States of America image

Did you get any errors when you ran the command?  So the default domain policy was deleted?  I'm asking because I may spin up a VM and test this on 2012 (never tried on 2012)

Thanks

Mike
Avatar of wiglack
wiglack
Flag of United States of America image

ASKER

No errors running  dcgpofix /ignoreschema /target:Domain  I also tried dcgpofix /target:both.

It appears the policy is in the sysvol folder, but it doesn't appear in group policy management.  When I try to create a new policy called Default Domain Policy, I get an error that GPO with this name already exists.
Avatar of Sandesh Dubey
Sandesh Dubey
Flag of India image

It seems that the policy is still present in AD database.Open ADSiedit and check for the orphan gpo guid.

Path=CN=Policies,CN=System,DC=DomainName,DC=com by using ADSIEDIT.msc

I will also recommend before you proceed with deletition.Download resource kit tool and run gpotool.You will het the policy quid details and policy name and then proceed with deletion.http://www.microsoft.com/en-in/download/details.aspx?id=17657

Do you have sysvol backup.If yes then you can restore the policies and script folder on DC and perfrom authorative and non authorative restore of sysvol.

If no backup and default domain contoller and default domain policy is missing then you need to run dcgpofix.

To reset the Domain GPO, type dcgpofix /target:Domain
To reset the Default DC GPO, type dcgpofix /target:DC
To reset both the Domain and Default DC GPOs, type dcgpofix /target:both

Note:
Domain GPO GUID -{31B2F340-016D-11D2-945F-00C04FB984F9}
DC GPO GUID - {6AC1786C-016F-11D2-945F-00C04FB984F9}
http://support.microsoft.com/kb/556025

Hope this helps
Avatar of wiglack
wiglack
Flag of United States of America image

ASKER

I don't have a sysvol backup, shadow copies weren't turned on, and there is no hyperv snapshot.

I can't delete it with ADSI edit either.

User generated image
Both of those GUID's are in the sysvol folder.
Avatar of Sandesh Dubey
Sandesh Dubey
Flag of India image

Both the quids are in sysvol then why are you deleting.It seeem to be permission issue.Before you proceed with deletion can you post the gpotool output.
Avatar of wiglack
wiglack
Flag of United States of America image

ASKER

C:\Program Files (x86)\Windows Resource Kits\Tools>gpotool
Validating DCs...
Available DCs:
DC1.home.wiglack.com
Searching for policies...
Found 2 policies
============================================================
Policy {31B2F340-016D-11D2-945F-00C04FB984F9}
Friendly name: Default Domain Policy
Policy OK
============================================================
Policy {6AC1786C-016F-11D2-945F-00C04FB984F9}
Friendly name: Default Domain Controllers Policy
Policy OK
============================================================

Policies OK

C:\Program Files (x86)\Windows Resource Kits\Tools>
SOLUTION
Avatar of Sandesh Dubey
Sandesh Dubey
Flag of India image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of wiglack
wiglack
Flag of United States of America image

ASKER

Yes they match sysvol\policies
Avatar of compdigit44
compdigit44

From you post it appears your default domain and domain controllers policy are present but you mentioned that they are not showing up in GPMC, is this correct?

If so, try to clear you MMC cache in your profile.

Which can be found in the following location: C:\Users\%username%\AppData\Roaming\Microsoft\MMC
Avatar of wiglack
wiglack
Flag of United States of America image

ASKER

@compdigit44: I did that, no change.  I rebooted after deleting the files.  No dice.  I logged in as a new user and there still is no Default Domain Policy.
Avatar of compdigit44
compdigit44

Ok so when you run the gpotool it is showing the default domain / domain controllers policies named correctly, but not via GPMC is this correct.

If so, can you please upload a screen shot of what you are seeing in GPMC.
Avatar of wiglack
wiglack
Flag of United States of America image

ASKER

User generated image
ASKER CERTIFIED SOLUTION
Avatar of compdigit44
compdigit44

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
Avatar of wiglack
wiglack
Flag of United States of America image

ASKER

How would I do that?
Active Directory
Active Directory

Active Directory (AD) is a Microsoft brand for identity-related capabilities. In the on-premises world, Windows Server AD provides a set of identity capabilities and services, and is hugely popular (88% of Fortune 1000 and 95% of enterprises use AD). This topic includes all things Active Directory including DNS, Group Policy, DFS, troubleshooting, ADFS, and all other topics under the Microsoft AD and identity umbrella.

86K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo