phreak Posted August 8, 2012 Posted August 8, 2012 I have taken over administration of a Windows 2008 R2 domain and something I have noticed is that in group policies there are 3 policies that say Inaccessible and have a no entry sign over the icons for them. It says This GPO is inaccessible because you do not have read-level permission on it. However I am logged onto the domain controller as the domain Admin and still getting that error. I have tried logging onto the server as every other user that has access to log onto the server but still getting that same message. Also tried accessing it from a user computer logged on as a admin. Is there any way I can see which user would have access to these GPO's? Or is there a way I can take ownership of them?
ZeroHour Posted August 8, 2012 Posted August 8, 2012 I have had to fix permissions before on a GP which caused the problem you have but it was ages ago. To find the odd permissions (if I recall) try out AccessEnum on the policies directory {DRIVE}\Sysvol\{Domain}\Policies\, and post your findings here ideally before changing anything
phreak Posted August 8, 2012 Author Posted August 8, 2012 (edited) Thanks ZH, I tried that and got 4 Access is denied errors when I scanned. The rest showed the group policies I can see and who was allowed Read, Write and Deny access. When I right click and try go to properties or explore it says windows cannot find C:\windows\sysvol\etc.. etc.. Edited August 8, 2012 by phreak
ZeroHour Posted August 8, 2012 Posted August 8, 2012 (edited) Thanks ZH, I tried that and got 4 Access is denied errors when I scanned. The rest showed the group policies I can see and who was allowed Read, Write and Deny access Are they GUID based folder names? Are the other policy folders inheriting their permissions? If so you could reset the policies folders permissions to match (inherit) but dont blame me if the server blows up, I just think thats what I did before but it was ages ago If you get rights I would modify the now working policies with a change just to force propagation. Edited August 8, 2012 by ZeroHour
phreak Posted August 8, 2012 Author Posted August 8, 2012 Yes, they are GUID. Non of the others are inheriting the permissions. But what I tried was to force access to my account onto it, when I try change the security however I get Access denied. Although for one of the rules it did actually push the setting through and I can see it in GPMC now. I also tried giving myself permissions through ADSIedit however that didn't seem to make any difference. Unfortunately the 1 that seems to be stubbornly not accepting changes is the one I need to get to.
glennda Posted August 8, 2012 Posted August 8, 2012 I think you will need to change the ownership of the folders and then set the permissions.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now