Solved

Can't edit Group Policy Object

Posted on 2014-01-07
3
5,591 Views
Last Modified: 2014-01-08
I have come to edit a GPO that was created quite a while ago but the "edit" bit of the menu is greyed out and I can't edit it.
Using Server 2012 standard.

What could the problem be?
0
Comment
Question by:paulmac110
3 Comments
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 39762295
It sounds like the user you are using lacks the edit permission to the GPO. Select the delegation tab on the GPO and ensure you have edit settings,delete,modify security.
0
 
LVL 12

Accepted Solution

by:
Sandeep earned 500 total points
ID: 39762358
Check what permissions are there on the GPO.

http://technet.microsoft.com/en-us/library/cc781991(v=ws.10).aspx

Default rights are as below :-
Edit settings, delete, modify security for

Domain Administrators
Enterprise Administrators
Creator Owner
SYSTEM

To Delegate Controls

To delegate Group Policy administrative tasks on a container
To delegate Group Policy-related permission on a site, domain, or OU, click the appropriate container in the GPMC console.

In the right pane for the site, domain, or OU, click the Delegation tab.

In the drop-down list box, select the desired permission you want to manage: Link GPOs, Perform Group Policy Modeling analyses, or Read Group Policy Results data. Note that GP Modeling and GP Results are not available for sites.

To add new groups, use the Add button.

To modify the Applies To setting for an existing permission, right-click the user or group in the list and then select either This container only or This container and all child containers.

To remove an existing group or user from having the specified permission, select the user or group from the list and click the Remove button. Only domain administrators have permission to do this.

To add or remove custom permissions, click Advanced at the bottom-right of the details pane and select the object whose permissions you want to change. Note that setting custom permissions is not recommended.
0
 
LVL 11

Expert Comment

by:Manjunath Sullad
ID: 39762498
Cross verify user ID is part of Group Policy Creator Owners group.

If you are facing this issue on particular DC / Server, try deleting the profile from computer properties, advanced systems settings, user profiles,

After deleting profile your profile will load freshly and try.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolve DNS query failed errors for Exchange
David Varnum recently wrote up his impressions of PRTG, based on a presentation by my colleague Christian at Tech Field Day at VMworld in Barcelona. Thanks David, for your detailed and honest evaluation!
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now