Win2003 server Local Policy security items are disabled

G

Guest

Guest
Archived from groups: microsoft.public.win2000.group_policy (More info?)

Hi,

There seems to be a big different how windows 2003 and 2000 server handle
local policy items. In 2000 the Local Policy items are still configurable
even if the item configured in Default Domain Policy or Default DC Policy.
Locally there is two column appears in the Local Policy editor. One is for
the Local Policy; the other one is for the Effective Policy referring to the
settings of policies that apply from AD.

In 2003 server the AD configured items are simply disabled, making it
impossible to add local accounts to the Local Policy.

Is there any way around this? My 2003 server is part of the domain, but it
is not a DC. I do want to add local accounts to certain security items on the
server locally, and I cannot add those users in Active Directory because they
are local computer accounts.

Thanks
Steve
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.group_policy (More info?)

hi,
we have just installed GPMC in our windows 2003 server and we
have few 2000 servers which are totally isolated forests and we would
like to manage group policies on those 2000 servers ,
Our servers have SP4 on 2000 and we even tried KB325465,LDAP
signing.
Please do suggest us a way to manage gp's in 2000 servers from 2003
servers using GPMC tool.
Reply to,
Ambar Arasan Moorthy
Tata Consultancy Services Limited
Air-India Building 11th Floor,
Nariman Point ,
Mumbai - 400 021,Maharashtra
India
Mailto: ambar.moorthy@tcs.com
Website: http://www.tcs.com



"HUNPIRATE" wrote:

> Hi,
>
> There seems to be a big different how windows 2003 and 2000 server handle
> local policy items. In 2000 the Local Policy items are still configurable
> even if the item configured in Default Domain Policy or Default DC Policy.
> Locally there is two column appears in the Local Policy editor. One is for
> the Local Policy; the other one is for the Effective Policy referring to the
> settings of policies that apply from AD.
>
> In 2003 server the AD configured items are simply disabled, making it
> impossible to add local accounts to the Local Policy.
>
> Is there any way around this? My 2003 server is part of the domain, but it
> is not a DC. I do want to add local accounts to certain security items on the
> server locally, and I cannot add those users in Active Directory because they
> are local computer accounts.
>
> Thanks
> Steve
>