problem with deleting and editing group policy from the group policy managment after ugrade domain controller

gogi100 46 Reputation points
2022-10-31T14:07:07.103+00:00

i upgraded domain controller from windows server 2008 to 2012. i have two domain controllers. the first dri-ad fsmo holder and the secondary dri--dcro. the domain functional level is windows server 2012. i have problem with editing and deleting group policies from the group policy management. every time i recevied message access denied. in tab status i have unaccessable server like picture

255680-unaccessable.jpg

i used next commands

icacls "{BE4C985C-5027-41DE-B775-8371CFC1E206}" /remove:g "dri\Domain Admins"
icacls "{BE4C985C-5027-41DE-B775-8371CFC1E206}" /grant "dri\Domain Admins":(OI)(CI)(F)

repadmin /syncall
repadmin /syncall /APed

on specific policy, but nothing
in AD users and computers in system>policies i checked permissions and domain admins has next permissions
255703-permissions.jpg

enterprise domain admins has full permissions. my account is member of those groups. Also i noticed next permissions for everyone account
255694-permissions1.jpg

when remove on everyone deny permission i can delete policy from the group policy managment. how resolve ths problem.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
9,436 questions
Windows Group Policy
Windows Group Policy
A feature of Windows that enables policy-based administration using Active Directory.
2,128 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
4,300 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. gogi100 46 Reputation points
    2022-11-01T13:51:39.507+00:00

    i deleted the everyone group from old group policy objects and when i click on status tab on domain in the group policy management. i receive:

    256076-gpmc3.jpg

    0 comments No comments

  2. gogi100 46 Reputation points
    2022-11-01T18:03:47.003+00:00

    i tryed restore permissions on group policy object but everytime the permission are resetting

    0 comments No comments

  3. Gary Reynolds 8,931 Reputation points
    2022-11-02T00:22:01.94+00:00

    Hi @gogi100 ,

    Have a look at this post on how to troubleshoot GPO permissions issues - https://nettools.net/gpo-explorer-gpo-test-details/

    Gary.


  4. gogi100 46 Reputation points
    2022-11-03T13:50:00.917+00:00

    i tested default domain policy in the nettools and the error exists on default domain policy, but the other policies are ok.

    DC: dri-ad.dri.local

    GPO Name: Default Domain Policy
    Created: 1/21/2011 1:57:42 PM
    Changed: 11/1/2022 11:38:38 AM
    DS Version: 1(user) \ 115(machine)
    Sysvol Version: 1(user) \ 115(machine)
    GP Status: 0
    GPE Version: 2
    User Extensions: [{3060E8D0-7020-11D2-842D-00C04FA372D4}{3060E8CE-7020-11D2-842D-00C04FA372D4}]
    Machine Extensions: [{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{53D6AB1B-2488-11D1-A28C-00C04FB94F17}][{827D319E-6EAC-11D2-A4EA-00C04F79F83A}{803E14A0-B4FB-11D0-A0D0-00A0C90F574B}][{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}{53D6AB1B-2488-11D1-A28C-00C04FB94F17}{53D6AB1D-2488-11D1-A28C-00C04FB94F17}]
    Sysvol Path: \dri.local\sysvol\dri.local\Policies{31B2F340-016D-11D2-945F-00C04FB984F9}
    DS User Object Count: 1
    DS Machine Object Count: 1
    SV User File Count: 10
    SV User File Size: 10400
    SV Machine File Count: 0
    SV Machine File Size: 0
    Applies to: S-1-5-11
    S-1-5-21-3433641461-923192373-1833595427-515


    DC: DRI-DCRO.dri.local
    GPO Name: Default Domain Policy
    Created: 1/21/2011 1:57:42 PM
    Changed: 11/1/2022 11:38:53 AM
    DS Version: 1(user) \ 115(machine)
    Sysvol Version: 1(user) \ 115(machine)
    GP Status: 0
    GPE Version: 2
    User Extensions: [{3060E8D0-7020-11D2-842D-00C04FA372D4}{3060E8CE-7020-11D2-842D-00C04FA372D4}]
    Machine Extensions: [{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{53D6AB1B-2488-11D1-A28C-00C04FB94F17}][{827D319E-6EAC-11D2-A4EA-00C04F79F83A}{803E14A0-B4FB-11D0-A0D0-00A0C90F574B}][{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}{53D6AB1B-2488-11D1-A28C-00C04FB94F17}{53D6AB1D-2488-11D1-A28C-00C04FB94F17}]
    Sysvol Path: \dri.local\sysvol\dri.local\Policies{31B2F340-016D-11D2-945F-00C04FB984F9}
    DS User Object Count: 1
    DS Machine Object Count: 1
    SV User File Count: 9
    SV User File Size: 3330
    SV Machine File Count: 0
    SV Machine File Size: 0
    Applies to: S-1-5-11
    S-1-5-21-3433641461-923192373-1833595427-515