ganesh.blogs Posted June 23, 2009 Posted June 23, 2009 Access Denied. Fail to Save. permalink Dear All, I am using Windows 2008 Server Sp2 When I am tried to edit the default domain policy, It gives the following error message. Access Denied. Failed to save \\pacrdc1.com\sysvol\pacrdc1.com\Policies\{31B2F34 0-016D-11D2-945F-00C04FB984F9}\MACHINE\Microsoft\Windows NT\SecEdit\GptTmpl.inf. Make sure that you have the right permission to this object. To overcome this, I create new policy and try to edit the computer policy settings, same error replicates and already existing policies are also not allowed to edit computer policies such as Audit policy settings. Due to this problem, I formated the Server and reinstalled all the services and its roles. It works fine for 20 more days. But after 20 days, the same error replicates. When I use gpresult/R command in command prompt, i gives the following msg. The Default Domain Policy are filtered out because it is empty. The content of gpresult is given below. C:\Users\SystemAdmin>gpresult /r Microsoft ® Windows ® Operating System Group Policy Result tool v2.0 Copyright © Microsoft Corp. 1981-2001 Created On 23-06-2009 at 11:11:41 RSOP data for PACRDC1\SystemAdmin on ADMINCABIN-01 : Logging Mode ------------------------------------------------------------------ OS Configuration: Member Workstation OS Version: 6.1.7100 Site Name: PACRPoly Roaming Profile: N/A Local Profile: C:\Users\SystemAdmin Connected over a slow link?: No COMPUTER SETTINGS ------------------ CN=AdminCabin-01,CN=Computers,DC=pacrdc1,DC=com Last time Group Policy was applied: 23-06-2009 at 10:32:30 Group Policy was applied from: PACR-DC2-2K9.pacrdc1.com Group Policy slow link threshold: 500 kbps Domain Name: PACRDC1 Domain Type: Windows 2000 Applied Group Policy Objects ----------------------------- Default Domain Policy The following GPOs were not applied because they were filtered out ------------------------------------------------------------------- Local Group Policy Filtering: Not Applied (Empty) The computer is a part of the following security groups ------------------------------------------------------- BUILTIN\Administrators Everyone BUILTIN\Users NT AUTHORITY\NETWORK NT AUTHORITY\Authenticated Users This Organization ADMINCABIN-01$ Domain Computers System Mandatory Level USER SETTINGS -------------- CN=System Administrator\, P.A.C. Ramasamy Raja Polytechnic College,CN=Users, DC=pacrdc1,DC=com Last time Group Policy was applied: 23-06-2009 at 10:08:43 Group Policy was applied from: PACR-DC2-2K9.pacrdc1.com Group Policy slow link threshold: 500 kbps Domain Name: PACRDC1 Domain Type: Windows 2000 Applied Group Policy Objects ----------------------------- N/A The following GPOs were not applied because they were filtered out ------------------------------------------------------------------- Default Domain Policy Filtering: Not Applied (Empty) Local Group Policy Filtering: Not Applied (Empty) The user is a part of the following security groups --------------------------------------------------- Domain Users Everyone BUILTIN\Users BUILTIN\Administrators NT AUTHORITY\INTERACTIVE CONSOLE LOGON NT AUTHORITY\Authenticated Users This Organization LOCAL Group Policy Creator Owners Domain Admins Enterprise Admins Schema Admins ePO User Group Denied RODC Password Replication Group High Mandatory Level C:\Users\SystemAdmin> I checked the event viewer, the Group Policy error 1058 eveint id is replicated in the server. I didn't understand what is route cause of this problem and where it is started. I have a doubt, this error occours after the installization DFS in the file server. The server details are listed below. Main Server : PACR-DC1-2K9 (dedicated SunFire x2100 Server - Entry Model) Back Server : PACR-DC2-2K9 (dedicated IBM x226 Server - Entry Model) File Server : PACR-MEM1-2K9 (desktop system configured as server ) All are Windows Server 2008 Enterprise OS execpt File Server (Windows Server 2008 Standard) :( Hope this problem is rectified soon. :confused: Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.