none
Group Policy User Rights

    Question

  • I am trying to change User Rights from ‘Access this computer from the network’ on a server 2008.  I have the server 2008 four areas I need to lock down, two of the settings allow me to change, two do not, what would cause this.

    Start, Run, gpedit.msc
    Computer Configuration, Windows Settings, Security Settings, Local Policies, User Rights Assignment
    ‘Access This Computer From The Network” is locked and I cannot change

    All Programs, Administrative Tools, Local Security Policy
    Security Settings, Local Policies, User Rights Assignment
    ‘Access This Computer From The Network” is locked and I cannot change


    All Programs, Administrative Tools, Group Policy Management, Proposal.com, Default Domain Policy
    Edit, Computer Configuration, Policies, Windows Settings, Security Settings, Local Policies, User Rights Assignment
    ‘Access This Computer From The Network” is NOT locked and I can change all settings


    All Programs, Administrative Tools, Group Policy Management, Proposal.com, Domain Controllers, Default Domain Controllers Policy
    Edit, Computer Configuration, Policies, Windows Settings, Security Settings, Local Policies, User Rights Assignment
    ‘Access This Computer From The Network” is NOT locked and I can change all settings

    What would cause the first two to be locked?

    Thanks
    b.

     

    Friday, February 20, 2015 3:49 PM

Answers

  • > Start, Run, gpedit.msc
     
    GPedit.msc edits the local (!) security policy. This cannot (!) be
    changed if a domain policy already deploys the same setting.
     
    > Computer Configuration, Windows Settings, Security Settings, Local
    > Policies, User Rights Assignment
    > ‘Access This Computer From The Network” is locked and I cannot change
     
    Already set in the default domain controller policy, so cannot be
    changed in gpedit.msc, but only in another policy linked to your DC OU.
    Like you already mentioned later :)
     
    > All Programs, Administrative Tools, Local Security Policy
    > Security Settings, Local Policies, User Rights Assignment
    > ‘Access This Computer From The Network” is locked and I cannot change
     
    Already set in the default domain controller policy, so cannot be
    changed in gpedit.msc, but only in another policy linked to your DC OU.
     
     

    Martin

    Mal ein GUTES Buch über GPOs lesen?

    NO THEY ARE NOT EVIL, if you know what you are doing: Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))
    Monday, February 23, 2015 4:22 PM

All replies

  • Hi B,

    >>I am trying to change User Rights from ‘Access this computer from the network’ on a server 2008. 

    Is the server damain controller or member server? Based on the description, the setting should have been controlled on domain level.  If we want to edit the setting, we can edit it in the domain GPO which has defined the setting.

    Best regards,
    Frank Shen


    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, February 23, 2015 2:53 AM
    Moderator
  • It is a Domain Controller
    Monday, February 23, 2015 12:14 PM
  • > Start, Run, gpedit.msc
     
    GPedit.msc edits the local (!) security policy. This cannot (!) be
    changed if a domain policy already deploys the same setting.
     
    > Computer Configuration, Windows Settings, Security Settings, Local
    > Policies, User Rights Assignment
    > ‘Access This Computer From The Network” is locked and I cannot change
     
    Already set in the default domain controller policy, so cannot be
    changed in gpedit.msc, but only in another policy linked to your DC OU.
    Like you already mentioned later :)
     
    > All Programs, Administrative Tools, Local Security Policy
    > Security Settings, Local Policies, User Rights Assignment
    > ‘Access This Computer From The Network” is locked and I cannot change
     
    Already set in the default domain controller policy, so cannot be
    changed in gpedit.msc, but only in another policy linked to your DC OU.
     
     

    Martin

    Mal ein GUTES Buch über GPOs lesen?

    NO THEY ARE NOT EVIL, if you know what you are doing: Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))
    Monday, February 23, 2015 4:22 PM