no more access to active directory users and computers

M

Mikael

hello,

After creating a group policy on a w2k PDC, i've no more
acces to the "active directory users and computers"
administrative tool. the window doesn't load. and when I
want to acces to the "Domain controller Security Policy"
i've the following message error "unable to open the group
policies object, you may haven't the a
appropriate rights" whereas i'm the scheme administrator.

thx.

Mikaël
 
J

Jimmy Harper [MSFT]

Hi Mikael. You might have changed the settings for the "Access this
computer from the network" user right in the Default Domain Controller
policy.

Try using the following steps from
http://support.microsoft.com/default.aspx?scid=KB;EN-US;257346 (slightly
modified from the article):

To resolve this issue, edit the Gpttmpl.inf file to grant
the "Access this computer from the network" user right for the
appropriate users on the domain controller:


1. Find and open the Gpttmpl.inf file in the Default Domain Controller
policy. It is located in the following folder:

\Winnt\Sysvol\Sysvol\<Domainname>\Policies\{6AC1786C-016F-11D2-945F-00C04fB9
84F9}\MACHINE\Microsoft\Wi
ndows NT\Secedit

2. Copy everything after SeInteractiveLogonRight=.

3. Paste the text you copied to the following location:
SeNetworkLogonRight=. Note Check the SeDenyNetworkLogonRight= entry.
You may have to remove any entries after the SeDenyNetworkLogonRight=
entry.

4. Save the changes and close the file.

5. Find and open the Gpt.ini file located in the following
folder:


\Winnt\Sysvol\Sysvol\<Domainname>\Policies\{6AC1786C-016F-11D2-945F-00C04fB9
84F9}

6. Increase the version number to a greater value.

7. Save and close the file.

8. Refresh group policy by running the following from a cmd prompt:

secedit /refreshpolicy machine_policy /enforce

9. After Group Policy has been reapplied, use Group Policy Editor to
set the user rights appropriately. The default groups for the "Access
this computer from the network" user right include Administrators,
Enterprise Domain Controllers, and Everyone.


--
Jimmy Harper [MSFT]
Directory Services
This posting is provided "AS IS" with no warranties, and confers no rights



hello,

After creating a group policy on a w2k PDC, i've no more
acces to the "active directory users and computers"
administrative tool. the window doesn't load. and when I
want to acces to the "Domain controller Security Policy"
i've the following message error "unable to open the group
policies object, you may haven't the a
appropriate rights" whereas i'm the scheme administrator.

thx.

Mikaël
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top