Solved

Can't edit Group Policy Object

Posted on 2014-01-07
3
7,066 Views
Last Modified: 2014-01-08
I have come to edit a GPO that was created quite a while ago but the "edit" bit of the menu is greyed out and I can't edit it.
Using Server 2012 standard.

What could the problem be?
0
Comment
Question by:paulmac110
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 39762295
It sounds like the user you are using lacks the edit permission to the GPO. Select the delegation tab on the GPO and ensure you have edit settings,delete,modify security.
0
 
LVL 12

Accepted Solution

by:
Sandeep earned 500 total points
ID: 39762358
Check what permissions are there on the GPO.

http://technet.microsoft.com/en-us/library/cc781991(v=ws.10).aspx

Default rights are as below :-
Edit settings, delete, modify security for

Domain Administrators
Enterprise Administrators
Creator Owner
SYSTEM

To Delegate Controls

To delegate Group Policy administrative tasks on a container
To delegate Group Policy-related permission on a site, domain, or OU, click the appropriate container in the GPMC console.

In the right pane for the site, domain, or OU, click the Delegation tab.

In the drop-down list box, select the desired permission you want to manage: Link GPOs, Perform Group Policy Modeling analyses, or Read Group Policy Results data. Note that GP Modeling and GP Results are not available for sites.

To add new groups, use the Add button.

To modify the Applies To setting for an existing permission, right-click the user or group in the list and then select either This container only or This container and all child containers.

To remove an existing group or user from having the specified permission, select the user or group from the list and click the Remove button. Only domain administrators have permission to do this.

To add or remove custom permissions, click Advanced at the bottom-right of the details pane and select the object whose permissions you want to change. Note that setting custom permissions is not recommended.
0
 
LVL 11

Expert Comment

by:Manjunath Sullad
ID: 39762498
Cross verify user ID is part of Group Policy Creator Owners group.

If you are facing this issue on particular DC / Server, try deleting the profile from computer properties, advanced systems settings, user profiles,

After deleting profile your profile will load freshly and try.
0

Featured Post

Webinar June 1st - Attacking Ransomware  

The global cyberattack that corrupted hundreds of thousands of computer systems on May 12th had a face, name, & price tag that we’ve seen all too often in recent years: Ransomware. With the stakes – and costs – of a ransomware attack higher than ever, is your business prepared ?

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Resolve DNS query failed errors for Exchange
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question