I hope I am not labouring this point but can I ask. Does anyone know if the ability to use GPO MMC snap-in is dependent on connectivity to the FSMO holding DC's ?
Using the AD Users and Computers snap-in on my troublesome DC, I have just tried to look at the GPO's for the domain. I am however told I do not have the rights to do so and I am prompted to choose one of three other options, one of which to is connect to the PDC Emulator role holder. So I am wondering if GPO creation and editing is dependent on the ability of the DC being used to contact the FSMO machines ? When the GPO snap-in is opened is there some authentication going on that involves the FSMO role holders ? Any thoughts ? I am surfing like crazy but just cannot word my query to bring back any helpful results ! List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
