Well, something was over-riding the policy on the workstations. At the closest workstation, I logged in and disabled the GPO on the PC, rebooted, and let a user sign on. So far, nothing in the Default Domain Policy has been over-ridden (almost 20 hours now).
I'm still confused as to why the GPO would be over-ridden at the workstation level. Thanks for all the help though. As long as nothing is overridden at the workstation, I will make the same changes on the remaining PC's. Charles -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rick Kingslan Sent: Thursday, July 31, 2003 22:46 To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] GP overridden Charles, I'd suggest strongly not to conclude that there's a problem simply because of this output. If you aren't seeing errors, there is no problems on the system (i.e. incorrect behavior, crashing, improper application of GPO or missing / incorrect settings) and the Application and System Event logs are not showing anything other than the successful SceCli messages - I'd not get too worried. Now, Tony mentioned that it's not a good idea to mess with the Default policies in Windows 2000. He's right, but I'm going to contradict my good friend Mr. Murray. I don't know of anything that READS the NAME of the policy. Much like a user, group or computer being identified by SID rather than display name, the Default policies are identified by GUID. You cannot delete the Default policies and recreate them by simply creating a new policy and naming them Default Domain Policy or Default Domain Controller Policy and expect them to work. The GUID must be exact. So, IMHO, if you want to rename it - you can. However, I'd leave it alone lest you forget what it really is and delete it - which, sadly, would be much worse than the report of duplicate objects in GPRESULT ======================================= Wait - I just thought of a situation where I have seen duplicate GPO names in GPRESULT. This was caused by a conflict resolved object that was visible via GPRESULT. I found it by using ADSIEdit and drilling into the Domain NC/System/Policies node. Here I found an object prefixed with a CNF: that needed to be removed. Caveat - this IN NOT an operation to be taken lightly! AND! In my case it was NOT the Default Domain Policy. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
