Administrator cannot change Local Security Policies

G

Guest

This is a long one, I'm trying to be explicit.

I am the administrator of a Active Directory Server and am logging on to the Domain from a local XP Pro pc. (This is happening on several of my pcs, and not on several others.)

The problem local machine explicitly has Domain Admins as well as specific Domain users in its' Local Administrators account. While logged on as any administrator, I cannot edit Local Policies (Start / Control Panel / Performance and Maintenance / Administrative Tools / Local Security Policy ) .. I can "push past" the errors and get in, but all editing (changes) is "greyed out".

I am asked which account I want to use, if I use any Domain User or the Domain Administrator which is not the Local PCs' Administrator (Administrator) I am told I "Do not have permission to perform this operation." If I log on as the Local Administrator (PCName\Administrator) I get "in" but again, I cannot make changes, ie. the "Add User or Group" and "Remove" buttons are greyed out, as is the list of users.

It should probably be noted that this entire network is comprised of pcs which have been upgraded from Windows 95 to 98 to XP, (as well as the servers going from NT4 to 2000) and some screwy stuff happened with Policies back between 98/NT and '98/2000. Some policies were removed and, at one point some config pols were lost or messed up between the local pcs and the Domain controller. I suspect the pcs that lost their policies are the ones I'm currently having trouble with.

Oh, and by the way also, I have attempted already upgrading one of the problem pcs from FAT32 to NTFS even though I didn't think it would help. It didn't. This problem is not "file" security, it is O/S policy.

Ideas, please. Thanks.
 
J

Juan

Greetings:

In Start\Run\MMC\File\add or remove complement\add\security templates\Edit
security....
also add\component services\........ expand and add your account in My
Computer\Properties\Default COM Security\add your account...
Save, rename console and save to... Try and edit security policies now.

1) In Start\Run\secpol.msc\Local Directives\User rights assignment\take
ownership of files or other objects\add administrator, or your user account
....
2) In Security Options\Accounts: State of the administrator account\enable.
These two directives I find are essential to take full control of the
nmachine.
Enable other policies as/if needed....

HOW TO: Reset Security Settings back to Default. (in case you need to
restore security settings to default)
http://support.microsoft.com/default.aspx?scid=kb;en-us;313222&Product=winxp
(313222) - This step-by-step article describes how to set the security
settings back to the default settings. Sample Command to Reset Security
Settings NOTE : After security settings are applied, you cannot undo the
changes without restoring from a backup.

---------------Original Message-------------
BrianSmall said:
This is a long one, I'm trying to be explicit.

I am the administrator of a Active Directory Server and am logging on to
the Domain from a local XP Pro pc. (This is happening on several of my pcs,
and not on several others.)
The problem local machine explicitly has Domain Admins as well as specific
Domain users in its' Local Administrators account. While logged on as any
administrator, I cannot edit Local Policies (Start / Control Panel /
Performance and Maintenance / Administrative Tools / Local Security Policy )
... I can "push past" the errors and get in, but all editing (changes) is
"greyed out".
I am asked which account I want to use, if I use any Domain User or the
Domain Administrator which is not the Local PCs' Administrator
(Administrator) I am told I "Do not have permission to perform this
operation." If I log on as the Local Administrator (PCName\Administrator) I
get "in" but again, I cannot make changes, ie. the "Add User or Group" and
"Remove" buttons are greyed out, as is the list of users.
It should probably be noted that this entire network is comprised of pcs
which have been upgraded from Windows 95 to 98 to XP, (as well as the
servers going from NT4 to 2000) and some screwy stuff happened with Policies
back between 98/NT and '98/2000. Some policies were removed and, at one
point some config pols were lost or messed up between the local pcs and the
Domain controller. I suspect the pcs that lost their policies are the ones
I'm currently having trouble with.
Oh, and by the way also, I have attempted already upgrading one of the
problem pcs from FAT32 to NTFS even though I didn't think it would help. It
didn't. This problem is not "file" security, it is O/S policy.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top