Solved

GPO disabled password options MS14-025

Posted on 2014-11-26
5
380 Views
Last Modified: 2015-01-27
I have setup a GPO for  all my clients. It enables the local administrator account and assigns it a password. I just discovered that Microsoft disabled this feature.

http://support.microsoft.com/kb/2962486

I do not see the patches mentioned on the domain controller - 2919355, 2928120, 2961899 so I am not sure what patch disabled this feature.

I am wondering if there is anyway to get this back. I would uninstall those patches if I found them and see if that fixes it.
0
Comment
Question by:ajdratch
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 82

Expert Comment

by:David Johnson, CD, MVP
ID: 40467467
Microsoft removed a vulnerability to your system and you want to add that vulnerability back?

It is easy by scripting to add that functionality back just not by group policy that ALL users have access to and can read the plain text password.
0
 

Author Comment

by:ajdratch
ID: 40467577
How can all users have access to the GPO if they are not domain administrators and can not log onto the servers.

What happens when something goes wrong with the computer and you need to log in with a local administrator account. Wouldn't it be great to know the password?

I saw the script in the link for that patch but I'd prefer not deal with all that code.

Here I am thinking I have all this covered only to find out MS disabled this.
0
 
LVL 82

Expert Comment

by:David Johnson, CD, MVP
ID: 40467635
all gpo's reside in the sysvol directory which the users have read access to. Otherwise group policy would not work.
0
 

Accepted Solution

by:
ajdratch earned 0 total points
ID: 40494531
I am now able to do this through my RMM - Level Platforms
0
 

Author Closing Comment

by:ajdratch
ID: 40572377
Work around is to use RMM
0

Featured Post

Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Suggested Courses

635 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question