Nozza Posted December 15, 2008 Posted December 15, 2008 Hi I'm set up as a sys admin and domain admin on RM CC3 but I don't quite have the 100% control I need on certain workstations. E.g. on my own laptop I can't access all the Administrative Tools (like Services). I've checked my group memberships and I appear to be exactly the same as the other admins who do get full access. Any ideas folks? Thanks N
FN-GM Posted December 15, 2008 Posted December 15, 2008 Could it be something like a group policy blocking it?
sparkeh Posted December 15, 2008 Posted December 15, 2008 Just to check, you haven't also given yourself a user type have you? Make sure user type is set to "No User Type Applied"
Nozza Posted December 15, 2008 Author Posted December 15, 2008 No user type is applied. Re: group policy - are you talking about on the Windows server? What would I need to check specifically? I've gone into it but I'm not experienced in that and have been limited to comparing my settings with other admins who do have full rights. I cannot see any differences at all.
sparkeh Posted December 15, 2008 Posted December 15, 2008 Hmm I wonder if a profile reset might help in this case?
sparkeh Posted December 15, 2008 Posted December 15, 2008 Ohh have you added yourself to the 'policy managers' group? When looking at your group membership, you need to tick the 'show all groups box' and add 'policy managers' - this is hidden by default.
Nozza Posted December 15, 2008 Author Posted December 15, 2008 I'm not a member of Policy Managers no. I can't add myself as an error occurs "Error adding user to group(s)". However, none of the other admins is a member either and they don't have the same problems?
sparkeh Posted December 15, 2008 Posted December 15, 2008 I'm not a member of Policy Managers no. I can't add myself as an error occurs "Error adding user to group(s)". However, none of the other admins is a member either and they don't have the same problems? I am surprised that none of the other users have this problem as you need to be a member of policy manager to see things like services, disk management and event viewer. The only difference between a manually created admin account and the default SystemAdmin account is the membership of policy managers group. On reflection you may need to log in as SystemAdmin to add your user account to this group.
Nozza Posted December 15, 2008 Author Posted December 15, 2008 Thanks. I tried logging in as sys admin to make the change but got the same error.
sparkeh Posted December 15, 2008 Posted December 15, 2008 Hmmm....interesting. Ok perhaps check that group in AD - located in Domain -> users. Does it exist? Can you add yourself there?
Nozza Posted December 15, 2008 Author Posted December 15, 2008 I managed to add the policy group by logging onto the server and using RMMC from there. But it made no difference. Heh. When I try to acess Services in the admin tools I get this error still "The user policies prevent MMC from creating the Snap-in"
sparkeh Posted December 15, 2008 Posted December 15, 2008 Just to check, after changing policy group, you did log out and back in to apply policy?
Nozza Posted December 15, 2008 Author Posted December 15, 2008 Yeah a couple of times, just to make sure
sparkeh Posted December 15, 2008 Posted December 15, 2008 Do you have an RM support contract? I would raise a call about this.
Nozza Posted December 16, 2008 Author Posted December 16, 2008 Yes I raised a call a whilst ago. They don't have an answer as such other than to create a new account. Which is probably the best thing. I can work around it by making w registry changes which I've put in a reg file for quick use but whilst handy that's not the point. I'm still interested to know what is actually going on!
sparkeh Posted December 16, 2008 Posted December 16, 2008 Yes I raised a call a whilst ago. They don't have an answer as such other than to create a new account. Which is probably the best thing. I can work around it by making w registry changes which I've put in a reg file for quick use but whilst handy that's not the point. I'm still interested to know what is actually going on! Hmm, does a new account work for you? I too am interested in why this is happening, it would be concerned it is indicative of other problems, such as gpos not being correctly applied or something. Out of interest, when you login, can you run gpresult from the commandline? It lists all the policies that are being applied.
Nozza Posted December 16, 2008 Author Posted December 16, 2008 Are you talking about he local machine or the server? On the local machine it says INFO: The policy object does not exist. I have done the registry fix on it though - if that makes any difference.
sparkeh Posted December 16, 2008 Posted December 16, 2008 Are you talking about he local machine or the server? local machine. On the local machine it says INFO: The policy object does not exist.. Bah! I am seeing this a fair bit now as well, not got round to working out why, or if its a problem. Some machines are returning the policy list, some aren't. Nevermind just an idea.
Nozza Posted December 16, 2008 Author Posted December 16, 2008 OK update: the new account made no difference. What access I do get differs on different machines it would appear. BTW. using CC3 - is it usual for the workstations' Firewall settings to be greyed out for admins? Because most are except some machines where it isn't?!
TechMonkey Posted December 16, 2008 Posted December 16, 2008 I found recently that unless a machine was set to Personal the firewall settings seemed to be locked. I haven't investigated further on this though as it wasn't that big a deal for the problem I was solving. Check the different machines though?
bossman Posted December 16, 2008 Posted December 16, 2008 Do you have Microsoft group policy management tool installed on your workstation? If so then you can check all of your GPOs as i remember ours corrupted on a few so were not getting applied had to go in and manually change them, works fine now. :) 1
Nozza Posted December 17, 2008 Author Posted December 17, 2008 I've been told that windows firewall should be greyed out for workstations if a group policy has been applied to the domain - it's deliberately like that to allow only global control. However this clearly presents problems should any individual workstation uses a piece of software needing access to the internet via various ports etc. I'm not aware of having MS group policy management tool on the PC but how would I check to be sure? I tried another new account and this one seems to have worked. I'm not happy with it though since I still don't understand what exactly is going on.
bossman Posted December 17, 2008 Posted December 17, 2008 @Nozza: Yes it is greyed out as the GPO is set to disable the firewall. Download the Microsoft group policy management tool and install it to your workstation under systemadmin account it will then allow you to view and change your GPOs if they have been corrupted in any way. Webman and myself had a problem with the MMC being greyed out in places so I installed above to see what the problems were as I had determined group policies were not being applied. It told me that it couldn't open certain policies because they were corrupted, had to manually change them. :)
Nozza Posted December 17, 2008 Author Posted December 17, 2008 I think the group policy is to allow the firewall to be on but it restricts it's use. Probably a stupid Q but will the GP management tool only affect GPOs on that specific workstation?
bossman Posted December 17, 2008 Posted December 17, 2008 @nozza: No you will be able to view all of the global GPOs which are on your DC and allocated to the domain. These affect all your workstations. Do you use client security by any chance (the little padlock icon in system management tools)?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now