Jump to content

Recommended Posts

Posted

I have taken over administration of a Windows 2008 R2 domain and something I have noticed is that in group policies there are 3 policies that say Inaccessible and have a no entry sign over the icons for them. It says This GPO is inaccessible because you do not have read-level permission on it.

 

However I am logged onto the domain controller as the domain Admin and still getting that error. I have tried logging onto the server as every other user that has access to log onto the server but still getting that same message. Also tried accessing it from a user computer logged on as a admin.

 

Is there any way I can see which user would have access to these GPO's? Or is there a way I can take ownership of them?

Posted

I have had to fix permissions before on a GP which caused the problem you have but it was ages ago.

To find the odd permissions (if I recall) try out AccessEnum on the policies directory {DRIVE}\Sysvol\{Domain}\Policies\, and post your findings here ideally before changing anything ;)

Posted (edited)

Thanks ZH,

 

I tried that and got 4 Access is denied errors when I scanned. The rest showed the group policies I can see and who was allowed Read, Write and Deny access.

 

When I right click and try go to properties or explore it says windows cannot find C:\windows\sysvol\etc.. etc..

Edited by phreak
Posted (edited)
Thanks ZH,

 

I tried that and got 4 Access is denied errors when I scanned. The rest showed the group policies I can see and who was allowed Read, Write and Deny access

 

Are they GUID based folder names?

Are the other policy folders inheriting their permissions?

If so you could reset the policies folders permissions to match (inherit) but dont blame me if the server blows up, I just think thats what I did before but it was ages ago ;)

If you get rights I would modify the now working policies with a change just to force propagation.

Edited by ZeroHour
Posted

Yes, they are GUID.

Non of the others are inheriting the permissions. But what I tried was to force access to my account onto it, when I try change the security however I get Access denied. Although for one of the rules it did actually push the setting through and I can see it in GPMC now.

I also tried giving myself permissions through ADSIedit however that didn't seem to make any difference.

 

Unfortunately the 1 that seems to be stubbornly not accepting changes is the one I need to get to.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...