Groupe Policy remote update ?

G

Guest

Guest
Archived from groups: microsoft.public.win2000.group_policy (More info?)

Dear all,

I have setup up a standard deployement procedure of our Windows 2000 professional system, by using the sysprep utility.
Based on that I have define on this image installation Local policy wich have been defined restricted to all users except the Administrator according to Microsoft procedure for doing so.

Which means that after deployement, our system local security is :

- Remove of Add/Remove hardware and software from control panel
- Do not allowed windows update
- Disable edition of registry database
- ....and more

Only Adminstrator user has no restriction.

Now it happen that one of my customer would like to be able to hand windows update itself. For this it is needed to edition just one parameter in Local froup policy.

The problem is that if the system is already at customer site m which could be far away, is there an easy solution to just enable the Windows update from initial policy settings.?

It would mean, can I send to the customer by mail the modified file ..\system32\GroupPolicy\Machine\Registry.pol
That will have that windows update enable.

Thanks for your advise and help

regards
Calderara Serge
Maillefer S.A
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.group_policy (More info?)

The answer is a qualified "yes". You can just create an updated registry.pol
file and have them copy it over their existing local one. However, you
should also send them the updated gpt.ini file that is found in the local
GPO directory as well, because if you send just the .pol file, and don't
update the local GPO version number, the machine will not know that the
local GPO has changed and will not re-process it with the new setting.

Hope that helps.

Darren
"Serge calderara" <anonymous@discussions.microsoft.com> wrote in message
news:0B2CFF99-15FB-41B9-8F67-18C94336AD18@microsoft.com...
> Dear all,
>
> I have setup up a standard deployement procedure of our Windows 2000
professional system, by using the sysprep utility.
> Based on that I have define on this image installation Local policy wich
have been defined restricted to all users except the Administrator according
to Microsoft procedure for doing so.
>
> Which means that after deployement, our system local security is :
>
> - Remove of Add/Remove hardware and software from control panel
> - Do not allowed windows update
> - Disable edition of registry database
> - ....and more
>
> Only Adminstrator user has no restriction.
>
> Now it happen that one of my customer would like to be able to hand
windows update itself. For this it is needed to edition just one parameter
in Local froup policy.
>
> The problem is that if the system is already at customer site m which
could be far away, is there an easy solution to just enable the Windows
update from initial policy settings.?
>
> It would mean, can I send to the customer by mail the modified file
...\system32\GroupPolicy\Machine\Registry.pol
> That will have that windows update enable.
>
> Thanks for your advise and help
>
> regards
> Calderara Serge
> Maillefer S.A
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.group_policy (More info?)

Thnaks a lot with your answer,

By the way, wen this new .pol file and gpo.ini file is copied over the existing system policy, do I need to log on and off with all user account in order to take in account that new policy, or is it simply the ini file which does that?

regards
serge