Answered by:
This tool was unable to recreate the EFS certificates in the Default Domain Policy GPO.

Question
-
C:\Users\Administrator>dcgpofix
Microsoft(R) Windows(R) Operating System Default Group Policy Restore Utility v5
.1
Copyright (C) Microsoft Corporation. 1981-2003
Description: Recreates the Default Group Policy Objects (GPOs) for a domain
Syntax: DcGPOFix [/ignoreschema] [/Target: Domain | DC | BOTH]
This utility can restore either or both the Default Domain Policy or the
Default Domain Controllers Policy to the state that exists immediately after
domain creation. You must be a domain administrator to perform this operation.
WARNING: YOU WILL LOSE ANY CHANGES YOU HAVE MADE TO THESE GPOs. THIS UTILITY
IS INTENDED ONLY FOR DISASTER RECOVERY PURPOSES.
You are about to restore Default Domain Policy and Default Domain Controller Pol
icy for the following domain
Kadasco.Com
Do you want to continue: <Y/N>? y
WARNING: This operation will replace all 'User Rights Assignments' made in the c
hosen GPOs. This might cause some server applications to fail. Do you want to co
ntinue: <Y/N>? y
Warning: This tool was unable to recreate the EFS certificates in the Default Do
main Policy GPO. The Default Domain Policy was restored successfully
Note: Only the contents of the Default Domain Policy were restored. Group Policy
links to this Group Policy Object were not altered.
By default, the Default Domain Policy is linked to the domain.
The Default Domain Controller Policy was restored successfully
Note: Only the contents of the Default Domain Controller Policy were restored. G
roup Policy links to this Group Policy Object were not altered.
By default, the Default Domain Controller Policy is linked to the domain control
lers OU.
Best Regard Mohammad Reza Abdi
Sunday, March 11, 2018 4:01 PM
Answers
-
hi
Correct Answer :
Remove-ADGroupMember
Best Regard Mohammad Reza Abdi
- Marked as answer by AbdiMreza Friday, March 16, 2018 6:28 PM
Tuesday, March 13, 2018 7:28 AM
All replies
-
Are you using EFS in your environment? If not, ignore the message. If yes, you should import your recovery agent certificate or other configuration you had.
This posting is provided AS IS with no warranties or guarantees , and confers no rights.
Ahmed MALEK
- Proposed as answer by William LiangMicrosoft contingent staff Monday, March 12, 2018 8:17 AM
Monday, March 12, 2018 1:03 AM -
Hi,
Just checking in to see if the information provided was helpful. Please let us know if you would like further assistance.
Best Regards,
WilliamPlease remember to mark the replies as answers if they help and unmark them if they provide no help.
If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.Monday, March 12, 2018 8:17 AM -
In general, you should avoid using dcgpofix for the reasons described in https://support.microsoft.com/en-us/help/833783/the-dcgpofix-tool-does-not-restore-security-settings-in-the-default-do
Instead, the recommendation is to use the backup/restore functionality available in GPMC.
To better understand your particular scenario, it would be helpful if you clarified why you are running gpofix in the first place
hth
MarcinMonday, March 12, 2018 10:45 AM -
Best Regard Mohammad Reza Abdi
Monday, March 12, 2018 6:25 PM -
Hello Abdi,
To be able to assist you further, please provide us with more details.
This posting is provided AS IS with no warranties or guarantees , and confers no rights.
Ahmed MALEK
Tuesday, March 13, 2018 1:41 AM -
hi
Correct Answer :
Remove-ADGroupMember
Best Regard Mohammad Reza Abdi
- Proposed as answer by William LiangMicrosoft contingent staff Tuesday, March 13, 2018 8:12 AM
Tuesday, March 13, 2018 7:28 AM -
hi
Correct Answer :
Remove-ADGroupMember
Best Regard Mohammad Reza Abdi
- Marked as answer by AbdiMreza Friday, March 16, 2018 6:28 PM
Tuesday, March 13, 2018 7:28 AM -
That's the way to create and solve this warning
Tuesday, August 4, 2020 2:20 PM