none
RSOP: the policy engine did not attempt to configure the setting

    Question

  • Hello,

    I have problems a few days ago with the audit policies, I get the following error when I run rsop.msc: the policy engine did not attempt to configure the setting

    i have this policy Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings.

    Does anybody have an idea?

    Monday, March 13, 2017 4:36 PM

All replies

  • Hi,

    Please check if the below similar threads helps:

    Error at RSOP while trying to set Audit settings via GPO

    https://social.technet.microsoft.com/Forums/windowsserver/en-US/1a85c8c4-0b7b-42d0-81ea-70a76574948f/error-at-rsop-while-trying-to-set-audit-settings-via-gpo?forum=winserversecurity

    RSOP: the policy engine did not attempt to configure the setting

    https://social.technet.microsoft.com/Forums/windowsserver/en-US/fde42cfc-bb74-4e11-8b60-c1a3cb5d80ed/rsop-the-policy-engine-did-not-attempt-to-configure-the-setting?forum=winserverGP

    Best Regards,

    Alvin Wang


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Tuesday, March 14, 2017 8:56 AM
    Moderator
  • Hello,

    thanks for your reply.

    Thanks for your answer, make the changes in the policy and registry but the same error still comes out

    Tuesday, March 14, 2017 3:35 PM
  • Hi,

    Have you checked event log (%windir%\security\logs\winlogon.log) on the target machine?

    Best Regards,

    Alvin Wang


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.


    Thursday, March 16, 2017 8:26 AM
    Moderator
  • Hi,

    Just want to confirm the current situations.

    Please feel free to let us know if you need further assistance.

    Best Regards,

    Alvin Wang


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Friday, March 24, 2017 8:54 AM
    Moderator
  • Hello, Still did not solve the problem

    viernes, 24 de marzo de 2017 12:45:28 a.m.
    Copiar valores de recuperación a la directiva combinada.


    ----Revertir la inicialización del motor de configuración...

    Procesar plantilla de directiva de grupo gpt00001.inf.

    Éste no es el último GPO.
    -------------------------------------------
    viernes, 24 de marzo de 2017 12:45:29 a.m.


    ----Revertir la inicialización del motor de configuración...

    Procesar plantilla de directiva de grupo gpt00002.inf.

    Éste no es el último GPO.
    -------------------------------------------
    viernes, 24 de marzo de 2017 12:45:29 a.m.


    ----Revertir la inicialización del motor de configuración...

    Procesar plantilla de directiva de grupo gpt00003.inf.
    -------------------------------------------
    viernes, 24 de marzo de 2017 12:45:29 a.m.
    ----El motor de configuración se inicializó correctamente.----

    ----Leyendo información de la plantilla de configuración...


    ----Configurar derechos del usuario...
    SeSystemtimePrivilege debe asignarse a los administradores. Esta configuración está ajustada.
    Configurar S-1-5-20.
    Configurar S-1-5-19.
    Configurar S-1-5-32-544.
    Configurar S-1-5-32-545.
    Configurar S-1-5-21-1471758060-1716801018-5522801-24250.
    Configurar S-1-5-32-546.
    Configurar S-1-5-21-559411705-2390216488-1948274254-501.
    Configurar S-1-5-21-1471758060-1716801018-5522801-512.
    Configurar S-1-5-21-1471758060-1716801018-5522801-50573.
    Configurar S-1-5-21-1471758060-1716801018-5522801-24435.

    Se completó correctamente la configuración de derechos del usuario.


    ----Configurar pertenencia a grupos...
    Configurar DP_NACION\Domain Admins.
    el objeto ya es miembro de Administradores.
    Configurar DP_NACION\GBNDesktopAdmins.
    el objeto ya es miembro de Administradores.

    Se completó correctamente la configuración de pertenencia a grupos.


    ----Configurar directiva de seguridad...
    Configurar la información sobre contraseñas.
    Configurar la información sobre final de sesión de cuenta forzado.
    Cambiar el nombre de la cuenta de administrador a BNETAdmin.
    Cambiar el nombre de la cuenta de invitado a CuentaBNInvitado.
    La cuenta de invitado está deshabilitada.

    La configuración del acceso al sistema se completó correctamente.
    Configuración de nombres de búsqueda anónima LSA: SD existente = D:(D;;0x800;;;AN)(A;;0xf1fff;;;BA)(A;;0x20801;;;WD)(A;;0x801;;;AN)(A;;0x1000;;;LS)(A;;0x1000;;;NS)(A;;0x1000;;;S-1-5-17).
    Establecer la configuración de búsqueda anónima LSA.
    Configurar machine\software\microsoft\windows nt\currentversion\setup\recoveryconsole\securitylevel.
    Configurar machine\software\microsoft\windows nt\currentversion\winlogon\allocatedasd.
    Configurar machine\software\microsoft\windows nt\currentversion\winlogon\cachedlogonscount.
    Configurar machine\software\microsoft\windows nt\currentversion\winlogon\forceunlocklogon.
    Configurar machine\software\microsoft\windows nt\currentversion\winlogon\passwordexpirywarning.
    Configurar machine\software\microsoft\windows nt\currentversion\winlogon\screensavergraceperiod.
    Configurar machine\software\microsoft\windows nt\currentversion\winlogon\scremoveoption.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\consentpromptbehavioradmin.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\consentpromptbehavioruser.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\disablecad.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\enableinstallerdetection.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\enablelua.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\enablesecureuiapaths.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\enableuiadesktoptoggle.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\enablevirtualization.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\filteradministratortoken.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\legalnoticecaption.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\legalnoticetext.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\promptonsecuredesktop.
    Configurar machine\software\microsoft\windows\currentversion\policies\system\validateadmincodesignatures.
    Configurar machine\system\currentcontrolset\control\lsa\crashonauditfail.
    Configurar machine\system\currentcontrolset\control\lsa\disabledomaincreds.
    Configurar machine\system\currentcontrolset\control\lsa\everyoneincludesanonymous.
    Configurar machine\system\currentcontrolset\control\lsa\forceguest.
    Configurar machine\system\currentcontrolset\control\lsa\limitblankpassworduse.
    Configurar machine\system\currentcontrolset\control\lsa\lmcompatibilitylevel.
    Configurar machine\system\currentcontrolset\control\lsa\msv1_0\ntlmminclientsec.
    Configurar machine\system\currentcontrolset\control\lsa\msv1_0\ntlmminserversec.
    Configurar machine\system\currentcontrolset\control\lsa\nolmhash.
    Configurar machine\system\currentcontrolset\control\lsa\restrictanonymous.
    Configurar machine\system\currentcontrolset\control\lsa\restrictanonymoussam.
    Configurar machine\system\currentcontrolset\control\print\providers\lanman print services\servers\addprinterdrivers.
    Configurar machine\system\currentcontrolset\control\session manager\memory management\clearpagefileatshutdown.
    Configurar machine\system\currentcontrolset\control\session manager\protectionmode.
    Configurar machine\system\currentcontrolset\control\session manager\safedllsearchmode.
    Configurar machine\system\currentcontrolset\services\ipsec\nodefaultexempt.
    Configurar machine\system\currentcontrolset\services\lanmanserver\parameters\autodisconnect.
    Configurar machine\system\currentcontrolset\services\lanmanserver\parameters\enableforcedlogoff.
    Configurar machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.
    Configurar machine\system\currentcontrolset\services\lanmanserver\parameters\requiresecuritysignature.
    Configurar machine\system\currentcontrolset\services\lanmanserver\parameters\restrictnullsessaccess.
    Configurar machine\system\currentcontrolset\services\lanmanworkstation\parameters\enableplaintextpassword.
    Configurar machine\system\currentcontrolset\services\lanmanworkstation\parameters\enablesecuritysignature.
    Configurar machine\system\currentcontrolset\services\lanmanworkstation\parameters\requiresecuritysignature.
    Configurar machine\system\currentcontrolset\services\ldap\ldapclientintegrity.
    Configurar machine\system\currentcontrolset\services\netlogon\parameters\disablepasswordchange.
    Configurar machine\system\currentcontrolset\services\netlogon\parameters\maximumpasswordage.
    Configurar machine\system\currentcontrolset\services\netlogon\parameters\requiresignorseal.
    Configurar machine\system\currentcontrolset\services\netlogon\parameters\requirestrongkey.
    Configurar machine\system\currentcontrolset\services\netlogon\parameters\sealsecurechannel.
    Configurar machine\system\currentcontrolset\services\netlogon\parameters\signsecurechannel.

    Se completó correctamente la configuración de valores del Registro.
    Configurar los valores del registro.
    La configuración de auditoría heredada está deshabilitada. Se omitió el establecimiento de la configuración de auditoría heredada.

    Se completó correctamente la configuración de auditoría y el registro.


    ----Configurar los motores de anexión de datos disponibles...

    Se completó correctamente la configuración de los motores de anexión de datos.


    ----Revertir la inicialización del motor de configuración...

    éste es el último GPO.

    Friday, March 24, 2017 8:02 PM
  • if you mistakenly/incorrectly configured the Advanced Audit settings, and are trying to revert/rollback to basic audit policy, this discussion may be helpful:

    http://serverfault.com/questions/631530/mistakenly-configured-advanced-audit-policies-return-to-basic


    Don [doesn't work for MSFT, and they're probably glad about that ;]

    Sunday, March 26, 2017 5:45 AM
  • Hi,

    Just want to confirm the current situations.

    Please feel free to let us know if you need further assistance.

    Best Regards,

    Alvin Wang


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, April 03, 2017 2:18 AM
    Moderator