Solved

Group Policy on 2003 DC vs. 2008 DC

Posted on 2013-12-09
4
399 Views
Last Modified: 2013-12-13
I have a domain with a Server 2003 DC and a Server 2008 DC.  The domain and forest functional levels are Server 2003.  I tried to setup group policy for screen saver timeout by editing group policy on the 2008 DC but was unable to do so.  Normally on 2003, I would take the following steps:

Active Directory Users and Computers -> Right click on domain -> Click on Properties -> select Group Policy tab -> select Default Domain Policy and click the edit button.  From there I can see the Screen Saver policies.

On the 2008 DC, the process is different.  Following the same steps fails on the Properties screen.  There is no Group Policy tab.  

How do I accomplish group policy edits on the 2008 DC?  I would like to retire the Server 2003 at some point.
0
Comment
Question by:crickard62
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 100 total points
ID: 39706749
You have to use the Group Policy Management Console (GPMC) to view/edit/ work with group policies.

More on that here   http://technet.microsoft.com/en-us/library/cc753298.aspx

You can add GPMC via a feature or powershell   http://technet.microsoft.com/en-us/library/cc725932.aspx

Thanks

Mike
0
 
LVL 2

Accepted Solution

by:
Krokodili earned 400 total points
ID: 39706999
Please have a look at:
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_28309192.html

there you can see my solution and try to apply it to your domain.
0
 

Author Comment

by:crickard62
ID: 39707080
Knowing about GPMC helps definitely helped - thank you.  But that only solved part of the problem.  I still don't see the GPO settings correctly.  

Under Server 2003, the display GPO settings are in the User Configuration section of the GPO under Administrative Templates/Control Panel/Display.  On Server 2008, the settings are in the User Configuration section of the GPO under Administrative Templates/Control Panel/Personalization.  That said, the Enable screen saver and Screen saver timeout settings on 2008 are not configured even though I set the corresponding properties on 2003.  

Is there a way to get the 2003 GPO settings to automatically propagate over to the corresponding 2008 GPO settings?  Maybe a more general way to ask the question is how can I find all my 2003 GPO settings and find the corresponding 2008 GPO settings and make sure they are set correctly on both DCs?
0
 
LVL 2

Expert Comment

by:Krokodili
ID: 39707092
That's what you should do. You should create a PolicyDefinitions folder under Sysvol, and make it your Central Store.

First you must create a folder on the domain controller,
name the folder PolicyDefinitions, and store the folder at:
C:\Windows\SYSVOL\sysvol\{Domain Name}\Policies\
This folder will now be your Central Store.
You must then copy all the contents of the Windows Server 2008 under
C:\Windows\PolicyDefinitions folder to the Central Store.
The ADML files in this folder are also in a language-specific folder (such as en-US).
0

Featured Post

Salesforce Has Never Been Easier

Improve and reinforce salesforce training & adoption using WalkMe's digital adoption platform. Start saving on costly employee training by creating fast intuitive Walk-Thrus for Salesforce. Claim your Free Account Now

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This article runs through the process of deploying a single EXE application selectively to a group of user.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question