Solved

How to remove all group policies

Posted on 2014-01-08
4
351 Views
Last Modified: 2014-01-12
I have a system which has VPn and have some issues so i suspect some GPO's are not affected properly or corrupted.

How can i reset all GPO's on this system
Remove them all and reapply them
Can i have the steps please

Windows 7 OS and windows 2003 AD
0
Comment
Question by:mtthompsons
  • 2
4 Comments
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
Comment Utility
You can use rsop.msc to view what policies are being applied correctly. When rsop.msc opens right click on computer configuration and user configuration and check General Tab for the policies that are/should be applied. You can then check the error Tab for any policies that are not working or failing when policy processing is happening. You can also reference the event viewer as well to see if policies are failing.

If you are in fact having issues with group policies you can do the following...
- Move your user and computer account to an OU where policies are not being applied
- from the client run gpupdate /force
- then reboot the machine
- run rsop.msc again to check the polciies that should now be removed
- move your user account and computer account back into the respective OU's
- run gpupdate /force again and reboot

Will.
0
 

Author Comment

by:mtthompsons
Comment Utility
Thanks
Does the GPO's affect local administrator?
I mean any local accounts on the system do they get the GPO's?
0
 
LVL 53

Expert Comment

by:Will Szymkowski
Comment Utility
No, local accounts are not affected. There are however certain policies (can't think of any off the top of my head) that when they are applied to the machine they are also applied to the local account as well. These policies cannot be removed until a fresh install of the OS has been done.

Most likely in your situation this is not the case. I just re-call that there were some policies a few years back that also affected the local machine and users while logging in locally.

Will.
0
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
There are some settings that even if you remove them still apply.  You will hear this referred t as "group policy tattooing" GP MVP Darren has a good blog on that

http://gpoguy.com/whitepapers/understanding-policy-tattooing/

You can also check your event logs for GP errors.

Thanks

Mike
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Companies that have implemented Microsoft’s Active Directory need to ensure that the Active Directory is configured and operating properly. If there are issues found and not resolved, it eventually leads the components to fail or stop working and fi…
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now