Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Windows Small Business Server > Group Policy not applying on one client

Reply
Thread Tools Display Modes

Group Policy not applying on one client

 
 
Adam Butler
Guest
Posts: n/a

 
      09-21-2005
Hello,

I was recently selected to beta test the Windows OneCare package.

So I tried it on one of my SBS 2003 client machines.
The client machine is an XP pro box with SP2.

OneCare seemed to be causing performance issues so I uninstalled it.
Soon after, I noticed that my Group Policies were no longer being applied to
this machine regardless of which user logged on.
All other client machines are working well.

The specific group policy has to do with Windows Firewall.
I had created a custom port exception list that is applied to all client
machines.

Now on this machine, my port exceptions no longer appear in Windows
Firewall.
It seems as if something on this client is blocking the ability to apply the
GPO from the SBS server.
I did post in the beta newsgroup for OneCare as well but no help.

Anyone have any ideas of where to look so I can correct this?
This is driving me crazy!

I've posted a gpresult /v below as well as an ipconfig /all from the bad
client and the server.

Thanks All!

Output from GPRESULT:

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\adam>gpresult /v

Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001

Created On 9/20/2005 at 23:55:42


RSOP results for MISSILEONE\adam on MAINXP : Logging Mode
-------------------------------------------------------------

OS Type: Microsoft Windows XP Professional
OS Configuration: Member Workstation
OS Version: 5.1.2600
Domain Name: MISSILEONE
Domain Type: Windows 2000
Site Name: Default-First-Site-Name
Roaming Profile:
Local Profile: C:\Documents and Settings\adam
Connected over a slow link?: No


COMPUTER SETTINGS
------------------
CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=missileone,DC=local
Last time Group Policy was applied: 9/20/2005 at 23:41:31
Group Policy was applied from: wx98.missileone.local
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
-----------------------------
Small Business Server Windows Firewall
Small Business Server Client Computer
Small Business Server Remote Assistance Policy
Small Business Server Lockout Policy
Small Business Server Domain Password Policy
Default Domain Policy
Rename Administrator Account
Local Group Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Internet Connection Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PreSP2

The computer is a part of the following security groups:
--------------------------------------------------------
BUILTIN\Administrators
Everyone
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
mainxp$
Domain Computers

Resultant Set Of Policies for Computer:
----------------------------------------

Software Installations
----------------------
N/A

Startup Scripts
---------------
N/A

Shutdown Scripts
----------------
N/A

Account Policies
----------------
GPO: Small Business Server Domain Password Policy
Policy: MinimumPasswordAge
Computer Setting: N/A

GPO: Small Business Server Domain Password Policy
Policy: PasswordHistorySize
Computer Setting: 24

GPO: Small Business Server Lockout Policy
Policy: LockoutDuration
Computer Setting: 10

GPO: Small Business Server Lockout Policy
Policy: ResetLockoutCount
Computer Setting: 10

GPO: Small Business Server Domain Password Policy
Policy: MinimumPasswordLength
Computer Setting: N/A

GPO: Small Business Server Lockout Policy
Policy: LockoutBadCount
Computer Setting: 50

GPO: Small Business Server Domain Password Policy
Policy: MaximumPasswordAge
Computer Setting: 4294967295

Audit Policy
------------
N/A

User Rights
-----------
N/A

Security Options
----------------
GPO: Default Domain Policy
Policy: RequireLogonToChangePassword
Computer Setting: Not Enabled

GPO: Small Business Server Domain Password Policy
Policy: PasswordComplexity
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: ForceLogoffWhenHourExpire
Computer Setting: Not Enabled

GPO: Small Business Server Domain Password Policy
Policy: ClearTextPassword
Computer Setting: Not Enabled

Event Log Settings
------------------
N/A

Restricted Groups
-----------------
N/A

System Services
---------------
N/A

Registry Settings
-----------------
N/A

File System Settings
--------------------
N/A

Public Key Policies
-------------------
N/A

Administrative Templates
------------------------
GPO: Small Business Server Client Computer
Setting: software\policies\microsoft\windows\network
connections
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Remote Assistance Policy
Setting: software\policies\microsoft\windows NT\Terminal
Services
State: Enabled

GPO: Small Business Server Windows Firewall
Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
Center
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Remote Assistance Policy
Setting: software\policies\microsoft\windows NT\Terminal
Services
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
State: Enabled

GPO: Small Business Server Client Computer
Setting:
software\microsoft\windows\currentversion\policies \explorer
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
State: Enabled

GPO: Small Business Server Client Computer
Setting: software\policies\microsoft\windows\network
connections
State: Enabled

GPO: Small Business Server Client Computer
Setting: software\microsoft\windows
nt\currentversion\winlogon
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
State: Enabled

GPO: Small Business Server Remote Assistance Policy
Setting: software\policies\microsoft\windows NT\Terminal
Services\RAUnsolicit
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
State: Enabled


USER SETTINGS
--------------
CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=mis sileone,DC=local
Last time Group Policy was applied: 9/20/2005 at 23:41:31
Group Policy was applied from: wx98.missileone.local
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
-----------------------------
Default Domain Policy
Local Group Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Internet Connection Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PreSP2

Small Business Server Lockout Policy
Filtering: Disabled (GPO)

Rename Administrator Account
Filtering: Not Applied (Empty)

Small Business Server Domain Password Policy
Filtering: Not Applied (Empty)

Small Business Server Remote Assistance Policy
Filtering: Disabled (GPO)

Small Business Server Client Computer
Filtering: Not Applied (Empty)

Small Business Server Windows Firewall
Filtering: Not Applied (Empty)

The user is a part of the following security groups:
----------------------------------------------------
Domain Users
Everyone
Debugger Users
Offer Remote Assistance Helpers
BUILTIN\Administrators
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
LOCAL
Group Policy Creator Owners
Domain Admins
Schema Admins
Enterprise Admins
SBS Report Users
SBS Mobile Users
Offer Remote Assistance Helpers

Resultant Set Of Policies for User:
------------------------------------

Software Installations
----------------------
N/A

Public Key Policies
-------------------
N/A

Administrative Templates
------------------------
N/A

Folder Redirection
------------------
N/A

Internet Explorer Browser User Interface
----------------------------------------
N/A

Internet Explorer Connection
----------------------------
N/A

Internet Explorer URLs
----------------------
N/A

Internet Explorer Security
--------------------------
N/A

Internet Explorer Programs
--------------------------
N/A

C:\Documents and Settings\mike>

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\steve>gpresults /v
'gpresults' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\steve>gpresult /v

Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001

Created On 9/20/2005 at 23:55:42


RSOP results for KRUSEMISSILE\steve on MAINXP : Logging Mode
-------------------------------------------------------------

OS Type: Microsoft Windows XP Professional
OS Configuration: Member Workstation
OS Version: 5.1.2600
Domain Name: KRUSEMISSILE
Domain Type: Windows 2000
Site Name: Default-First-Site-Name
Roaming Profile:
Local Profile: C:\Documents and Settings\steve
Connected over a slow link?: No


COMPUTER SETTINGS
------------------
CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=krusemissile,DC=local
Last time Group Policy was applied: 9/20/2005 at 23:41:31
Group Policy was applied from: wx98.krusemissile.local
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
-----------------------------
Small Business Server Windows Firewall
Small Business Server Client Computer
Small Business Server Remote Assistance Policy
Small Business Server Lockout Policy
Small Business Server Domain Password Policy
Default Domain Policy
Rename Administrator Account
Local Group Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Internet Connection Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PreSP2

The computer is a part of the following security groups:
--------------------------------------------------------
BUILTIN\Administrators
Everyone
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
mainxp$
Domain Computers

Resultant Set Of Policies for Computer:
----------------------------------------

Software Installations
----------------------
N/A

Startup Scripts
---------------
N/A

Shutdown Scripts
----------------
N/A

Account Policies
----------------
GPO: Small Business Server Domain Password Policy
Policy: MinimumPasswordAge
Computer Setting: N/A

GPO: Small Business Server Domain Password Policy
Policy: PasswordHistorySize
Computer Setting: 24

GPO: Small Business Server Lockout Policy
Policy: LockoutDuration
Computer Setting: 10

GPO: Small Business Server Lockout Policy
Policy: ResetLockoutCount
Computer Setting: 10

GPO: Small Business Server Domain Password Policy
Policy: MinimumPasswordLength
Computer Setting: N/A

GPO: Small Business Server Lockout Policy
Policy: LockoutBadCount
Computer Setting: 50

GPO: Small Business Server Domain Password Policy
Policy: MaximumPasswordAge
Computer Setting: 4294967295

Audit Policy
------------
N/A

User Rights
-----------
N/A

Security Options
----------------
GPO: Default Domain Policy
Policy: RequireLogonToChangePassword
Computer Setting: Not Enabled

GPO: Small Business Server Domain Password Policy
Policy: PasswordComplexity
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: ForceLogoffWhenHourExpire
Computer Setting: Not Enabled

GPO: Small Business Server Domain Password Policy
Policy: ClearTextPassword
Computer Setting: Not Enabled

Event Log Settings
------------------
N/A

Restricted Groups
-----------------
N/A

System Services
---------------
N/A

Registry Settings
-----------------
N/A

File System Settings
--------------------
N/A

Public Key Policies
-------------------
N/A

Administrative Templates
------------------------
GPO: Small Business Server Client Computer
Setting: software\policies\microsoft\windows\network
connections
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Remote Assistance Policy
Setting: software\policies\microsoft\windows NT\Terminal
Services
State: Enabled

GPO: Small Business Server Windows Firewall
Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
Center
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Remote Assistance Policy
Setting: software\policies\microsoft\windows NT\Terminal
Services
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
State: Enabled

GPO: Small Business Server Client Computer
Setting:
software\microsoft\windows\currentversion\policies \explorer
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
State: Enabled

GPO: Small Business Server Client Computer
Setting: software\policies\microsoft\windows\network
connections
State: Enabled

GPO: Small Business Server Client Computer
Setting: software\microsoft\windows
nt\currentversion\winlogon
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
State: Enabled

GPO: Small Business Server Remote Assistance Policy
Setting: software\policies\microsoft\windows NT\Terminal
Services\RAUnsolicit
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
State: Enabled


USER SETTINGS
--------------
CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=kru semissile,DC=local
Last time Group Policy was applied: 9/20/2005 at 23:41:31
Group Policy was applied from: wx98.krusemissile.local
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
-----------------------------
Default Domain Policy
Local Group Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Internet Connection Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PreSP2

Small Business Server Lockout Policy
Filtering: Disabled (GPO)

Rename Administrator Account
Filtering: Not Applied (Empty)

Small Business Server Domain Password Policy
Filtering: Not Applied (Empty)

Small Business Server Remote Assistance Policy
Filtering: Disabled (GPO)

Small Business Server Client Computer
Filtering: Not Applied (Empty)

Small Business Server Windows Firewall
Filtering: Not Applied (Empty)

The user is a part of the following security groups:
----------------------------------------------------
Domain Users
Everyone
Debugger Users
Offer Remote Assistance Helpers
BUILTIN\Administrators
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
LOCAL
Group Policy Creator Owners
Domain Admins
Schema Admins
Enterprise Admins
SBS Report Users
SBS Mobile Users
Offer Remote Assistance Helpers

Resultant Set Of Policies for User:
------------------------------------

Software Installations
----------------------
N/A

Public Key Policies
-------------------
N/A

Administrative Templates
------------------------
N/A

Folder Redirection
------------------
N/A

Internet Explorer Browser User Interface
----------------------------------------
N/A

Internet Explorer Connection
----------------------------
N/A

Internet Explorer URLs
----------------------
N/A

Internet Explorer Security
--------------------------
N/A

Internet Explorer Programs
--------------------------
N/A

C:\Documents and Settings\steve>gpresult /v

Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001

Created On 9/21/2005 at 00:01:34


RSOP results for KRUSEMISSILE\steve on MAINXP : Logging Mode
-------------------------------------------------------------

OS Type: Microsoft Windows XP Professional
OS Configuration: Member Workstation
OS Version: 5.1.2600
Domain Name: KRUSEMISSILE
Domain Type: Windows 2000
Site Name: Default-First-Site-Name
Roaming Profile:
Local Profile: C:\Documents and Settings\steve
Connected over a slow link?: No


COMPUTER SETTINGS
------------------
CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=krusemissile,DC=local
Last time Group Policy was applied: 9/20/2005 at 23:41:31
Group Policy was applied from: wx98.krusemissile.local
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
-----------------------------
Small Business Server Windows Firewall
Small Business Server Client Computer
Small Business Server Remote Assistance Policy
Small Business Server Lockout Policy
Small Business Server Domain Password Policy
Default Domain Policy
Rename Administrator Account
Local Group Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Internet Connection Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PreSP2

The computer is a part of the following security groups:
--------------------------------------------------------
BUILTIN\Administrators
Everyone
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
mainxp$
Domain Computers

Resultant Set Of Policies for Computer:
----------------------------------------

Software Installations
----------------------
N/A

Startup Scripts
---------------
N/A

Shutdown Scripts
----------------
N/A

Account Policies
----------------
GPO: Small Business Server Domain Password Policy
Policy: MinimumPasswordAge
Computer Setting: N/A

GPO: Small Business Server Domain Password Policy
Policy: PasswordHistorySize
Computer Setting: 24

GPO: Small Business Server Lockout Policy
Policy: LockoutDuration
Computer Setting: 10

GPO: Small Business Server Lockout Policy
Policy: ResetLockoutCount
Computer Setting: 10

GPO: Small Business Server Domain Password Policy
Policy: MinimumPasswordLength
Computer Setting: N/A

GPO: Small Business Server Lockout Policy
Policy: LockoutBadCount
Computer Setting: 50

GPO: Small Business Server Domain Password Policy
Policy: MaximumPasswordAge
Computer Setting: 4294967295

Audit Policy
------------
N/A

User Rights
-----------
N/A

Security Options
----------------
GPO: Default Domain Policy
Policy: RequireLogonToChangePassword
Computer Setting: Not Enabled

GPO: Small Business Server Domain Password Policy
Policy: PasswordComplexity
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: ForceLogoffWhenHourExpire
Computer Setting: Not Enabled

GPO: Small Business Server Domain Password Policy
Policy: ClearTextPassword
Computer Setting: Not Enabled

Event Log Settings
------------------
N/A

Restricted Groups
-----------------
N/A

System Services
---------------
N/A

Registry Settings
-----------------
N/A

File System Settings
--------------------
N/A

Public Key Policies
-------------------
N/A

Administrative Templates
------------------------
GPO: Small Business Server Client Computer
Setting: software\policies\microsoft\windows\network
connections
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Remote Assistance Policy
Setting: software\policies\microsoft\windows NT\Terminal
Services
State: Enabled

GPO: Small Business Server Windows Firewall
Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
Center
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Remote Assistance Policy
Setting: software\policies\microsoft\windows NT\Terminal
Services
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
State: Enabled

GPO: Small Business Server Client Computer
Setting:
software\microsoft\windows\currentversion\policies \explorer
State: Enabled

GPO: Default Domain Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
State: Enabled

GPO: Small Business Server Client Computer
Setting: software\policies\microsoft\windows\network
connections
State: Enabled

GPO: Small Business Server Client Computer
Setting: software\microsoft\windows
nt\currentversion\winlogon
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
State: Enabled

GPO: Small Business Server Remote Assistance Policy
Setting: software\policies\microsoft\windows NT\Terminal
Services\RAUnsolicit
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
State: Enabled

GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Small Business Server Windows Firewall
Setting:
SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
State: Enabled


USER SETTINGS
--------------
CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=kru semissile,DC=local
Last time Group Policy was applied: 9/20/2005 at 23:41:31
Group Policy was applied from: wx98.krusemissile.local
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
-----------------------------
Default Domain Policy
Local Group Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Internet Connection Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PreSP2

Small Business Server Lockout Policy
Filtering: Disabled (GPO)

Rename Administrator Account
Filtering: Not Applied (Empty)

Small Business Server Domain Password Policy
Filtering: Not Applied (Empty)

Small Business Server Remote Assistance Policy
Filtering: Disabled (GPO)

Small Business Server Client Computer
Filtering: Not Applied (Empty)

Small Business Server Windows Firewall
Filtering: Not Applied (Empty)

The user is a part of the following security groups:
----------------------------------------------------
Domain Users
Everyone
Debugger Users
Offer Remote Assistance Helpers
BUILTIN\Administrators
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
LOCAL
Group Policy Creator Owners
Domain Admins
Schema Admins
Enterprise Admins
SBS Report Users
SBS Mobile Users
Offer Remote Assistance Helpers

Resultant Set Of Policies for User:
------------------------------------

Software Installations
----------------------
N/A

Public Key Policies
-------------------
N/A

Administrative Templates
------------------------
N/A

Folder Redirection
------------------
N/A

Internet Explorer Browser User Interface
----------------------------------------
N/A

Internet Explorer Connection
----------------------------
N/A

Internet Explorer URLs
----------------------
N/A

Internet Explorer Security
--------------------------
N/A

Internet Explorer Programs
--------------------------
N/A


IPCONFIG /ALL from bad Client machine:


C:\Documents and Settings\mike>ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : mainxp
Primary Dns Suffix . . . . . . . :missileone.local
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : missileone.local
missileone.local

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . : missileone.local
Description . . . . . . . . . . . : Intel(R) PRO/100 VE Network
Connection
Physical Address. . . . . . . . . : 00-11-11-25-21-01
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.103.4
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.103.1
DHCP Server . . . . . . . . . . . : 192.168.103.53
DNS Servers . . . . . . . . . . . : 192.168.103.53
Primary WINS Server . . . . . . . : 192.168.103.53
Lease Obtained. . . . . . . . . . : Tuesday, September 20, 2005
23:40:05
Lease Expires . . . . . . . . . . : Wednesday, September 28, 2005
23:40:05

C:\Documents and Settings\mike>


IPCONFIG from Server:

Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\Administrator>ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : wx98
Primary Dns Suffix . . . . . . . : missileone.local
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : missileone.local

Ethernet adapter Server Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection
Physical Address. . . . . . . . . : 00-0C-F1-C9-B6-67
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.103.53
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.103.1
DNS Servers . . . . . . . . . . . : 192.168.103.53
Primary WINS Server . . . . . . . : 192.168.103.53

C:\Documents and Settings\Administrator>


 
Reply With Quote
 
 
 
 
Adam Butler
Guest
Posts: n/a

 
      09-21-2005
Somehow in my original post I sent two copies of the GPRESULT output.
The first copy is the correct one.

"Adam Butler" <> wrote in message
news:...
> Hello,
>
> I was recently selected to beta test the Windows OneCare package.
>
> So I tried it on one of my SBS 2003 client machines.
> The client machine is an XP pro box with SP2.
>
> OneCare seemed to be causing performance issues so I uninstalled it.
> Soon after, I noticed that my Group Policies were no longer being applied
> to this machine regardless of which user logged on.
> All other client machines are working well.
>
> The specific group policy has to do with Windows Firewall.
> I had created a custom port exception list that is applied to all client
> machines.
>
> Now on this machine, my port exceptions no longer appear in Windows
> Firewall.
> It seems as if something on this client is blocking the ability to apply
> the GPO from the SBS server.
> I did post in the beta newsgroup for OneCare as well but no help.
>
> Anyone have any ideas of where to look so I can correct this?
> This is driving me crazy!
>
> I've posted a gpresult /v below as well as an ipconfig /all from the bad
> client and the server.
>
> Thanks All!
>
> Output from GPRESULT:
>
> Microsoft Windows XP [Version 5.1.2600]
> (C) Copyright 1985-2001 Microsoft Corp.
>
> C:\Documents and Settings\adam>gpresult /v
>
> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool
> v2.0
> Copyright (C) Microsoft Corp. 1981-2001
>
> Created On 9/20/2005 at 23:55:42
>
>
> RSOP results for MISSILEONE\adam on MAINXP : Logging Mode
> -------------------------------------------------------------
>
> OS Type: Microsoft Windows XP Professional
> OS Configuration: Member Workstation
> OS Version: 5.1.2600
> Domain Name: MISSILEONE
> Domain Type: Windows 2000
> Site Name: Default-First-Site-Name
> Roaming Profile:
> Local Profile: C:\Documents and Settings\adam
> Connected over a slow link?: No
>
>
> COMPUTER SETTINGS
> ------------------
>
> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=missileone,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.missileone.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Small Business Server Windows Firewall
> Small Business Server Client Computer
> Small Business Server Remote Assistance Policy
> Small Business Server Lockout Policy
> Small Business Server Domain Password Policy
> Default Domain Policy
> Rename Administrator Account
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> The computer is a part of the following security groups:
> --------------------------------------------------------
> BUILTIN\Administrators
> Everyone
> BUILTIN\Users
> NT AUTHORITY\NETWORK
> NT AUTHORITY\Authenticated Users
> mainxp$
> Domain Computers
>
> Resultant Set Of Policies for Computer:
> ----------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Startup Scripts
> ---------------
> N/A
>
> Shutdown Scripts
> ----------------
> N/A
>
> Account Policies
> ----------------
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordAge
> Computer Setting: N/A
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordHistorySize
> Computer Setting: 24
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutDuration
> Computer Setting: 10
>
> GPO: Small Business Server Lockout Policy
> Policy: ResetLockoutCount
> Computer Setting: 10
>
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordLength
> Computer Setting: N/A
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutBadCount
> Computer Setting: 50
>
> GPO: Small Business Server Domain Password Policy
> Policy: MaximumPasswordAge
> Computer Setting: 4294967295
>
> Audit Policy
> ------------
> N/A
>
> User Rights
> -----------
> N/A
>
> Security Options
> ----------------
> GPO: Default Domain Policy
> Policy: RequireLogonToChangePassword
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordComplexity
> Computer Setting: Not Enabled
>
> GPO: Default Domain Policy
> Policy: ForceLogoffWhenHourExpire
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: ClearTextPassword
> Computer Setting: Not Enabled
>
> Event Log Settings
> ------------------
> N/A
>
> Restricted Groups
> -----------------
> N/A
>
> System Services
> ---------------
> N/A
>
> Registry Settings
> -----------------
> N/A
>
> File System Settings
> --------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
> Center
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting:
> software\microsoft\windows\currentversion\policies \explorer
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\microsoft\windows
> nt\currentversion\winlogon
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services\RAUnsolicit
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
>
> USER SETTINGS
> --------------
> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=mis sileone,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.missileone.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Default Domain Policy
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> Small Business Server Lockout Policy
> Filtering: Disabled (GPO)
>
> Rename Administrator Account
> Filtering: Not Applied (Empty)
>
> Small Business Server Domain Password Policy
> Filtering: Not Applied (Empty)
>
> Small Business Server Remote Assistance Policy
> Filtering: Disabled (GPO)
>
> Small Business Server Client Computer
> Filtering: Not Applied (Empty)
>
> Small Business Server Windows Firewall
> Filtering: Not Applied (Empty)
>
> The user is a part of the following security groups:
> ----------------------------------------------------
> Domain Users
> Everyone
> Debugger Users
> Offer Remote Assistance Helpers
> BUILTIN\Administrators
> BUILTIN\Users
> NT AUTHORITY\INTERACTIVE
> NT AUTHORITY\Authenticated Users
> LOCAL
> Group Policy Creator Owners
> Domain Admins
> Schema Admins
> Enterprise Admins
> SBS Report Users
> SBS Mobile Users
> Offer Remote Assistance Helpers
>
> Resultant Set Of Policies for User:
> ------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> N/A
>
> Folder Redirection
> ------------------
> N/A
>
> Internet Explorer Browser User Interface
> ----------------------------------------
> N/A
>
> Internet Explorer Connection
> ----------------------------
> N/A
>
> Internet Explorer URLs
> ----------------------
> N/A
>
> Internet Explorer Security
> --------------------------
> N/A
>
> Internet Explorer Programs
> --------------------------
> N/A
>
> C:\Documents and Settings\mike>
>
> Microsoft Windows XP [Version 5.1.2600]
> (C) Copyright 1985-2001 Microsoft Corp.
>
> C:\Documents and Settings\steve>gpresults /v
> 'gpresults' is not recognized as an internal or external command,
> operable program or batch file.
>
> C:\Documents and Settings\steve>gpresult /v
>
> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool
> v2.0
> Copyright (C) Microsoft Corp. 1981-2001
>
> Created On 9/20/2005 at 23:55:42
>
>
> RSOP results for KRUSEMISSILE\steve on MAINXP : Logging Mode
> -------------------------------------------------------------
>
> OS Type: Microsoft Windows XP Professional
> OS Configuration: Member Workstation
> OS Version: 5.1.2600
> Domain Name: KRUSEMISSILE
> Domain Type: Windows 2000
> Site Name: Default-First-Site-Name
> Roaming Profile:
> Local Profile: C:\Documents and Settings\steve
> Connected over a slow link?: No
>
>
> COMPUTER SETTINGS
> ------------------
>
> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=krusemissile,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.krusemissile.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Small Business Server Windows Firewall
> Small Business Server Client Computer
> Small Business Server Remote Assistance Policy
> Small Business Server Lockout Policy
> Small Business Server Domain Password Policy
> Default Domain Policy
> Rename Administrator Account
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> The computer is a part of the following security groups:
> --------------------------------------------------------
> BUILTIN\Administrators
> Everyone
> BUILTIN\Users
> NT AUTHORITY\NETWORK
> NT AUTHORITY\Authenticated Users
> mainxp$
> Domain Computers
>
> Resultant Set Of Policies for Computer:
> ----------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Startup Scripts
> ---------------
> N/A
>
> Shutdown Scripts
> ----------------
> N/A
>
> Account Policies
> ----------------
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordAge
> Computer Setting: N/A
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordHistorySize
> Computer Setting: 24
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutDuration
> Computer Setting: 10
>
> GPO: Small Business Server Lockout Policy
> Policy: ResetLockoutCount
> Computer Setting: 10
>
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordLength
> Computer Setting: N/A
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutBadCount
> Computer Setting: 50
>
> GPO: Small Business Server Domain Password Policy
> Policy: MaximumPasswordAge
> Computer Setting: 4294967295
>
> Audit Policy
> ------------
> N/A
>
> User Rights
> -----------
> N/A
>
> Security Options
> ----------------
> GPO: Default Domain Policy
> Policy: RequireLogonToChangePassword
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordComplexity
> Computer Setting: Not Enabled
>
> GPO: Default Domain Policy
> Policy: ForceLogoffWhenHourExpire
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: ClearTextPassword
> Computer Setting: Not Enabled
>
> Event Log Settings
> ------------------
> N/A
>
> Restricted Groups
> -----------------
> N/A
>
> System Services
> ---------------
> N/A
>
> Registry Settings
> -----------------
> N/A
>
> File System Settings
> --------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
> Center
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting:
> software\microsoft\windows\currentversion\policies \explorer
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\microsoft\windows
> nt\currentversion\winlogon
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services\RAUnsolicit
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
>
> USER SETTINGS
> --------------
> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=kru semissile,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.krusemissile.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Default Domain Policy
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> Small Business Server Lockout Policy
> Filtering: Disabled (GPO)
>
> Rename Administrator Account
> Filtering: Not Applied (Empty)
>
> Small Business Server Domain Password Policy
> Filtering: Not Applied (Empty)
>
> Small Business Server Remote Assistance Policy
> Filtering: Disabled (GPO)
>
> Small Business Server Client Computer
> Filtering: Not Applied (Empty)
>
> Small Business Server Windows Firewall
> Filtering: Not Applied (Empty)
>
> The user is a part of the following security groups:
> ----------------------------------------------------
> Domain Users
> Everyone
> Debugger Users
> Offer Remote Assistance Helpers
> BUILTIN\Administrators
> BUILTIN\Users
> NT AUTHORITY\INTERACTIVE
> NT AUTHORITY\Authenticated Users
> LOCAL
> Group Policy Creator Owners
> Domain Admins
> Schema Admins
> Enterprise Admins
> SBS Report Users
> SBS Mobile Users
> Offer Remote Assistance Helpers
>
> Resultant Set Of Policies for User:
> ------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> N/A
>
> Folder Redirection
> ------------------
> N/A
>
> Internet Explorer Browser User Interface
> ----------------------------------------
> N/A
>
> Internet Explorer Connection
> ----------------------------
> N/A
>
> Internet Explorer URLs
> ----------------------
> N/A
>
> Internet Explorer Security
> --------------------------
> N/A
>
> Internet Explorer Programs
> --------------------------
> N/A
>
> C:\Documents and Settings\steve>gpresult /v
>
> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool
> v2.0
> Copyright (C) Microsoft Corp. 1981-2001
>
> Created On 9/21/2005 at 00:01:34
>
>
> RSOP results for KRUSEMISSILE\steve on MAINXP : Logging Mode
> -------------------------------------------------------------
>
> OS Type: Microsoft Windows XP Professional
> OS Configuration: Member Workstation
> OS Version: 5.1.2600
> Domain Name: KRUSEMISSILE
> Domain Type: Windows 2000
> Site Name: Default-First-Site-Name
> Roaming Profile:
> Local Profile: C:\Documents and Settings\steve
> Connected over a slow link?: No
>
>
> COMPUTER SETTINGS
> ------------------
>
> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=krusemissile,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.krusemissile.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Small Business Server Windows Firewall
> Small Business Server Client Computer
> Small Business Server Remote Assistance Policy
> Small Business Server Lockout Policy
> Small Business Server Domain Password Policy
> Default Domain Policy
> Rename Administrator Account
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> The computer is a part of the following security groups:
> --------------------------------------------------------
> BUILTIN\Administrators
> Everyone
> BUILTIN\Users
> NT AUTHORITY\NETWORK
> NT AUTHORITY\Authenticated Users
> mainxp$
> Domain Computers
>
> Resultant Set Of Policies for Computer:
> ----------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Startup Scripts
> ---------------
> N/A
>
> Shutdown Scripts
> ----------------
> N/A
>
> Account Policies
> ----------------
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordAge
> Computer Setting: N/A
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordHistorySize
> Computer Setting: 24
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutDuration
> Computer Setting: 10
>
> GPO: Small Business Server Lockout Policy
> Policy: ResetLockoutCount
> Computer Setting: 10
>
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordLength
> Computer Setting: N/A
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutBadCount
> Computer Setting: 50
>
> GPO: Small Business Server Domain Password Policy
> Policy: MaximumPasswordAge
> Computer Setting: 4294967295
>
> Audit Policy
> ------------
> N/A
>
> User Rights
> -----------
> N/A
>
> Security Options
> ----------------
> GPO: Default Domain Policy
> Policy: RequireLogonToChangePassword
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordComplexity
> Computer Setting: Not Enabled
>
> GPO: Default Domain Policy
> Policy: ForceLogoffWhenHourExpire
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: ClearTextPassword
> Computer Setting: Not Enabled
>
> Event Log Settings
> ------------------
> N/A
>
> Restricted Groups
> -----------------
> N/A
>
> System Services
> ---------------
> N/A
>
> Registry Settings
> -----------------
> N/A
>
> File System Settings
> --------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
> Center
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting:
> software\microsoft\windows\currentversion\policies \explorer
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\microsoft\windows
> nt\currentversion\winlogon
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services\RAUnsolicit
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
>
> USER SETTINGS
> --------------
> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=kru semissile,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.krusemissile.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Default Domain Policy
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> Small Business Server Lockout Policy
> Filtering: Disabled (GPO)
>
> Rename Administrator Account
> Filtering: Not Applied (Empty)
>
> Small Business Server Domain Password Policy
> Filtering: Not Applied (Empty)
>
> Small Business Server Remote Assistance Policy
> Filtering: Disabled (GPO)
>
> Small Business Server Client Computer
> Filtering: Not Applied (Empty)
>
> Small Business Server Windows Firewall
> Filtering: Not Applied (Empty)
>
> The user is a part of the following security groups:
> ----------------------------------------------------
> Domain Users
> Everyone
> Debugger Users
> Offer Remote Assistance Helpers
> BUILTIN\Administrators
> BUILTIN\Users
> NT AUTHORITY\INTERACTIVE
> NT AUTHORITY\Authenticated Users
> LOCAL
> Group Policy Creator Owners
> Domain Admins
> Schema Admins
> Enterprise Admins
> SBS Report Users
> SBS Mobile Users
> Offer Remote Assistance Helpers
>
> Resultant Set Of Policies for User:
> ------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> N/A
>
> Folder Redirection
> ------------------
> N/A
>
> Internet Explorer Browser User Interface
> ----------------------------------------
> N/A
>
> Internet Explorer Connection
> ----------------------------
> N/A
>
> Internet Explorer URLs
> ----------------------
> N/A
>
> Internet Explorer Security
> --------------------------
> N/A
>
> Internet Explorer Programs
> --------------------------
> N/A
>
>
> IPCONFIG /ALL from bad Client machine:
>
>
> C:\Documents and Settings\mike>ipconfig /all
>
> Windows IP Configuration
>
> Host Name . . . . . . . . . . . . : mainxp
> Primary Dns Suffix . . . . . . . :missileone.local
> Node Type . . . . . . . . . . . . : Hybrid
> IP Routing Enabled. . . . . . . . : No
> WINS Proxy Enabled. . . . . . . . : No
> DNS Suffix Search List. . . . . . : missileone.local
> missileone.local
>
> Ethernet adapter Local Area Connection:
>
> Connection-specific DNS Suffix . : missileone.local
> Description . . . . . . . . . . . : Intel(R) PRO/100 VE Network
> Connection
> Physical Address. . . . . . . . . : 00-11-11-25-21-01
> Dhcp Enabled. . . . . . . . . . . : Yes
> Autoconfiguration Enabled . . . . : Yes
> IP Address. . . . . . . . . . . . : 192.168.103.4
> Subnet Mask . . . . . . . . . . . : 255.255.255.0
> Default Gateway . . . . . . . . . : 192.168.103.1
> DHCP Server . . . . . . . . . . . : 192.168.103.53
> DNS Servers . . . . . . . . . . . : 192.168.103.53
> Primary WINS Server . . . . . . . : 192.168.103.53
> Lease Obtained. . . . . . . . . . : Tuesday, September 20, 2005
> 23:40:05
> Lease Expires . . . . . . . . . . : Wednesday, September 28, 2005
> 23:40:05
>
> C:\Documents and Settings\mike>
>
>
> IPCONFIG from Server:
>
> Microsoft Windows [Version 5.2.3790]
> (C) Copyright 1985-2003 Microsoft Corp.
>
> C:\Documents and Settings\Administrator>ipconfig /all
>
> Windows IP Configuration
>
> Host Name . . . . . . . . . . . . : wx98
> Primary Dns Suffix . . . . . . . : missileone.local
> Node Type . . . . . . . . . . . . : Hybrid
> IP Routing Enabled. . . . . . . . : No
> WINS Proxy Enabled. . . . . . . . : No
> DNS Suffix Search List. . . . . . : missileone.local
>
> Ethernet adapter Server Local Area Connection:
>
> Connection-specific DNS Suffix . :
> Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
> Connection
> Physical Address. . . . . . . . . : 00-0C-F1-C9-B6-67
> DHCP Enabled. . . . . . . . . . . : No
> IP Address. . . . . . . . . . . . : 192.168.103.53
> Subnet Mask . . . . . . . . . . . : 255.255.255.0
> Default Gateway . . . . . . . . . : 192.168.103.1
> DNS Servers . . . . . . . . . . . : 192.168.103.53
> Primary WINS Server . . . . . . . : 192.168.103.53
>
> C:\Documents and Settings\Administrator>
>



 
Reply With Quote
 
Wood Contour
Guest
Posts: n/a

 
      09-21-2005
Adam Butler wrote:
> Hello,
>
> I was recently selected to beta test the Windows OneCare package.
>
> So I tried it on one of my SBS 2003 client machines.
> The client machine is an XP pro box with SP2.
>
> OneCare seemed to be causing performance issues so I uninstalled it.
> Soon after, I noticed that my Group Policies were no longer being applied to
> this machine regardless of which user logged on.
> All other client machines are working well.
>
> The specific group policy has to do with Windows Firewall.
> I had created a custom port exception list that is applied to all client
> machines.
>
> Now on this machine, my port exceptions no longer appear in Windows
> Firewall.
> It seems as if something on this client is blocking the ability to apply the
> GPO from the SBS server.
> I did post in the beta newsgroup for OneCare as well but no help.
>
> Anyone have any ideas of where to look so I can correct this?
> This is driving me crazy!
>
> I've posted a gpresult /v below as well as an ipconfig /all from the bad
> client and the server.
>
> Thanks All!
>
> Output from GPRESULT:
>
> Microsoft Windows XP [Version 5.1.2600]
> (C) Copyright 1985-2001 Microsoft Corp.
>
> C:\Documents and Settings\adam>gpresult /v
>
> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
> Copyright (C) Microsoft Corp. 1981-2001
>
> Created On 9/20/2005 at 23:55:42
>
>
> RSOP results for MISSILEONE\adam on MAINXP : Logging Mode
> -------------------------------------------------------------
>
> OS Type: Microsoft Windows XP Professional
> OS Configuration: Member Workstation
> OS Version: 5.1.2600
> Domain Name: MISSILEONE
> Domain Type: Windows 2000
> Site Name: Default-First-Site-Name
> Roaming Profile:
> Local Profile: C:\Documents and Settings\adam
> Connected over a slow link?: No
>
>
> COMPUTER SETTINGS
> ------------------
> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=missileone,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.missileone.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Small Business Server Windows Firewall
> Small Business Server Client Computer
> Small Business Server Remote Assistance Policy
> Small Business Server Lockout Policy
> Small Business Server Domain Password Policy
> Default Domain Policy
> Rename Administrator Account
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> The computer is a part of the following security groups:
> --------------------------------------------------------
> BUILTIN\Administrators
> Everyone
> BUILTIN\Users
> NT AUTHORITY\NETWORK
> NT AUTHORITY\Authenticated Users
> mainxp$
> Domain Computers
>
> Resultant Set Of Policies for Computer:
> ----------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Startup Scripts
> ---------------
> N/A
>
> Shutdown Scripts
> ----------------
> N/A
>
> Account Policies
> ----------------
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordAge
> Computer Setting: N/A
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordHistorySize
> Computer Setting: 24
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutDuration
> Computer Setting: 10
>
> GPO: Small Business Server Lockout Policy
> Policy: ResetLockoutCount
> Computer Setting: 10
>
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordLength
> Computer Setting: N/A
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutBadCount
> Computer Setting: 50
>
> GPO: Small Business Server Domain Password Policy
> Policy: MaximumPasswordAge
> Computer Setting: 4294967295
>
> Audit Policy
> ------------
> N/A
>
> User Rights
> -----------
> N/A
>
> Security Options
> ----------------
> GPO: Default Domain Policy
> Policy: RequireLogonToChangePassword
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordComplexity
> Computer Setting: Not Enabled
>
> GPO: Default Domain Policy
> Policy: ForceLogoffWhenHourExpire
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: ClearTextPassword
> Computer Setting: Not Enabled
>
> Event Log Settings
> ------------------
> N/A
>
> Restricted Groups
> -----------------
> N/A
>
> System Services
> ---------------
> N/A
>
> Registry Settings
> -----------------
> N/A
>
> File System Settings
> --------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
> Center
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting:
> software\microsoft\windows\currentversion\policies \explorer
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\microsoft\windows
> nt\currentversion\winlogon
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services\RAUnsolicit
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
>
> USER SETTINGS
> --------------
> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=mis sileone,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.missileone.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Default Domain Policy
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> Small Business Server Lockout Policy
> Filtering: Disabled (GPO)
>
> Rename Administrator Account
> Filtering: Not Applied (Empty)
>
> Small Business Server Domain Password Policy
> Filtering: Not Applied (Empty)
>
> Small Business Server Remote Assistance Policy
> Filtering: Disabled (GPO)
>
> Small Business Server Client Computer
> Filtering: Not Applied (Empty)
>
> Small Business Server Windows Firewall
> Filtering: Not Applied (Empty)
>
> The user is a part of the following security groups:
> ----------------------------------------------------
> Domain Users
> Everyone
> Debugger Users
> Offer Remote Assistance Helpers
> BUILTIN\Administrators
> BUILTIN\Users
> NT AUTHORITY\INTERACTIVE
> NT AUTHORITY\Authenticated Users
> LOCAL
> Group Policy Creator Owners
> Domain Admins
> Schema Admins
> Enterprise Admins
> SBS Report Users
> SBS Mobile Users
> Offer Remote Assistance Helpers
>
> Resultant Set Of Policies for User:
> ------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> N/A
>
> Folder Redirection
> ------------------
> N/A
>
> Internet Explorer Browser User Interface
> ----------------------------------------
> N/A
>
> Internet Explorer Connection
> ----------------------------
> N/A
>
> Internet Explorer URLs
> ----------------------
> N/A
>
> Internet Explorer Security
> --------------------------
> N/A
>
> Internet Explorer Programs
> --------------------------
> N/A
>
> C:\Documents and Settings\mike>
>
> Microsoft Windows XP [Version 5.1.2600]
> (C) Copyright 1985-2001 Microsoft Corp.
>
> C:\Documents and Settings\steve>gpresults /v
> 'gpresults' is not recognized as an internal or external command,
> operable program or batch file.
>
> C:\Documents and Settings\steve>gpresult /v
>
> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
> Copyright (C) Microsoft Corp. 1981-2001
>
> Created On 9/20/2005 at 23:55:42
>
>
> RSOP results for KRUSEMISSILE\steve on MAINXP : Logging Mode
> -------------------------------------------------------------
>
> OS Type: Microsoft Windows XP Professional
> OS Configuration: Member Workstation
> OS Version: 5.1.2600
> Domain Name: KRUSEMISSILE
> Domain Type: Windows 2000
> Site Name: Default-First-Site-Name
> Roaming Profile:
> Local Profile: C:\Documents and Settings\steve
> Connected over a slow link?: No
>
>
> COMPUTER SETTINGS
> ------------------
> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=krusemissile,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.krusemissile.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Small Business Server Windows Firewall
> Small Business Server Client Computer
> Small Business Server Remote Assistance Policy
> Small Business Server Lockout Policy
> Small Business Server Domain Password Policy
> Default Domain Policy
> Rename Administrator Account
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> The computer is a part of the following security groups:
> --------------------------------------------------------
> BUILTIN\Administrators
> Everyone
> BUILTIN\Users
> NT AUTHORITY\NETWORK
> NT AUTHORITY\Authenticated Users
> mainxp$
> Domain Computers
>
> Resultant Set Of Policies for Computer:
> ----------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Startup Scripts
> ---------------
> N/A
>
> Shutdown Scripts
> ----------------
> N/A
>
> Account Policies
> ----------------
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordAge
> Computer Setting: N/A
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordHistorySize
> Computer Setting: 24
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutDuration
> Computer Setting: 10
>
> GPO: Small Business Server Lockout Policy
> Policy: ResetLockoutCount
> Computer Setting: 10
>
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordLength
> Computer Setting: N/A
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutBadCount
> Computer Setting: 50
>
> GPO: Small Business Server Domain Password Policy
> Policy: MaximumPasswordAge
> Computer Setting: 4294967295
>
> Audit Policy
> ------------
> N/A
>
> User Rights
> -----------
> N/A
>
> Security Options
> ----------------
> GPO: Default Domain Policy
> Policy: RequireLogonToChangePassword
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordComplexity
> Computer Setting: Not Enabled
>
> GPO: Default Domain Policy
> Policy: ForceLogoffWhenHourExpire
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: ClearTextPassword
> Computer Setting: Not Enabled
>
> Event Log Settings
> ------------------
> N/A
>
> Restricted Groups
> -----------------
> N/A
>
> System Services
> ---------------
> N/A
>
> Registry Settings
> -----------------
> N/A
>
> File System Settings
> --------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
> Center
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting:
> software\microsoft\windows\currentversion\policies \explorer
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\microsoft\windows
> nt\currentversion\winlogon
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services\RAUnsolicit
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
>
> USER SETTINGS
> --------------
> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=kru semissile,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.krusemissile.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Default Domain Policy
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> Small Business Server Lockout Policy
> Filtering: Disabled (GPO)
>
> Rename Administrator Account
> Filtering: Not Applied (Empty)
>
> Small Business Server Domain Password Policy
> Filtering: Not Applied (Empty)
>
> Small Business Server Remote Assistance Policy
> Filtering: Disabled (GPO)
>
> Small Business Server Client Computer
> Filtering: Not Applied (Empty)
>
> Small Business Server Windows Firewall
> Filtering: Not Applied (Empty)
>
> The user is a part of the following security groups:
> ----------------------------------------------------
> Domain Users
> Everyone
> Debugger Users
> Offer Remote Assistance Helpers
> BUILTIN\Administrators
> BUILTIN\Users
> NT AUTHORITY\INTERACTIVE
> NT AUTHORITY\Authenticated Users
> LOCAL
> Group Policy Creator Owners
> Domain Admins
> Schema Admins
> Enterprise Admins
> SBS Report Users
> SBS Mobile Users
> Offer Remote Assistance Helpers
>
> Resultant Set Of Policies for User:
> ------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> N/A
>
> Folder Redirection
> ------------------
> N/A
>
> Internet Explorer Browser User Interface
> ----------------------------------------
> N/A
>
> Internet Explorer Connection
> ----------------------------
> N/A
>
> Internet Explorer URLs
> ----------------------
> N/A
>
> Internet Explorer Security
> --------------------------
> N/A
>
> Internet Explorer Programs
> --------------------------
> N/A
>
> C:\Documents and Settings\steve>gpresult /v
>
> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
> Copyright (C) Microsoft Corp. 1981-2001
>
> Created On 9/21/2005 at 00:01:34
>
>
> RSOP results for KRUSEMISSILE\steve on MAINXP : Logging Mode
> -------------------------------------------------------------
>
> OS Type: Microsoft Windows XP Professional
> OS Configuration: Member Workstation
> OS Version: 5.1.2600
> Domain Name: KRUSEMISSILE
> Domain Type: Windows 2000
> Site Name: Default-First-Site-Name
> Roaming Profile:
> Local Profile: C:\Documents and Settings\steve
> Connected over a slow link?: No
>
>
> COMPUTER SETTINGS
> ------------------
> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=krusemissile,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.krusemissile.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Small Business Server Windows Firewall
> Small Business Server Client Computer
> Small Business Server Remote Assistance Policy
> Small Business Server Lockout Policy
> Small Business Server Domain Password Policy
> Default Domain Policy
> Rename Administrator Account
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> The computer is a part of the following security groups:
> --------------------------------------------------------
> BUILTIN\Administrators
> Everyone
> BUILTIN\Users
> NT AUTHORITY\NETWORK
> NT AUTHORITY\Authenticated Users
> mainxp$
> Domain Computers
>
> Resultant Set Of Policies for Computer:
> ----------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Startup Scripts
> ---------------
> N/A
>
> Shutdown Scripts
> ----------------
> N/A
>
> Account Policies
> ----------------
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordAge
> Computer Setting: N/A
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordHistorySize
> Computer Setting: 24
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutDuration
> Computer Setting: 10
>
> GPO: Small Business Server Lockout Policy
> Policy: ResetLockoutCount
> Computer Setting: 10
>
> GPO: Small Business Server Domain Password Policy
> Policy: MinimumPasswordLength
> Computer Setting: N/A
>
> GPO: Small Business Server Lockout Policy
> Policy: LockoutBadCount
> Computer Setting: 50
>
> GPO: Small Business Server Domain Password Policy
> Policy: MaximumPasswordAge
> Computer Setting: 4294967295
>
> Audit Policy
> ------------
> N/A
>
> User Rights
> -----------
> N/A
>
> Security Options
> ----------------
> GPO: Default Domain Policy
> Policy: RequireLogonToChangePassword
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: PasswordComplexity
> Computer Setting: Not Enabled
>
> GPO: Default Domain Policy
> Policy: ForceLogoffWhenHourExpire
> Computer Setting: Not Enabled
>
> GPO: Small Business Server Domain Password Policy
> Policy: ClearTextPassword
> Computer Setting: Not Enabled
>
> Event Log Settings
> ------------------
> N/A
>
> Restricted Groups
> -----------------
> N/A
>
> System Services
> ---------------
> N/A
>
> Registry Settings
> -----------------
> N/A
>
> File System Settings
> --------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
> Center
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting:
> software\microsoft\windows\currentversion\policies \explorer
> State: Enabled
>
> GPO: Default Domain Policy
> Setting:
> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\policies\microsoft\windows\network
> connections
> State: Enabled
>
> GPO: Small Business Server Client Computer
> Setting: software\microsoft\windows
> nt\currentversion\winlogon
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
> State: Enabled
>
> GPO: Small Business Server Remote Assistance Policy
> Setting: software\policies\microsoft\windows NT\Terminal
> Services\RAUnsolicit
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
> State: Enabled
>
> GPO: Default Domain Policy
> Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
> State: Enabled
>
> GPO: Small Business Server Windows Firewall
> Setting:
> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
> State: Enabled
>
>
> USER SETTINGS
> --------------
> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=kru semissile,DC=local
> Last time Group Policy was applied: 9/20/2005 at 23:41:31
> Group Policy was applied from: wx98.krusemissile.local
> Group Policy slow link threshold: 500 kbps
>
> Applied Group Policy Objects
> -----------------------------
> Default Domain Policy
> Local Group Policy
>
> The following GPOs were not applied because they were filtered out
> -------------------------------------------------------------------
> Small Business Server Internet Connection Firewall
> Filtering: Denied (WMI Filter)
> WMI Filter: PreSP2
>
> Small Business Server Lockout Policy
> Filtering: Disabled (GPO)
>
> Rename Administrator Account
> Filtering: Not Applied (Empty)
>
> Small Business Server Domain Password Policy
> Filtering: Not Applied (Empty)
>
> Small Business Server Remote Assistance Policy
> Filtering: Disabled (GPO)
>
> Small Business Server Client Computer
> Filtering: Not Applied (Empty)
>
> Small Business Server Windows Firewall
> Filtering: Not Applied (Empty)
>
> The user is a part of the following security groups:
> ----------------------------------------------------
> Domain Users
> Everyone
> Debugger Users
> Offer Remote Assistance Helpers
> BUILTIN\Administrators
> BUILTIN\Users
> NT AUTHORITY\INTERACTIVE
> NT AUTHORITY\Authenticated Users
> LOCAL
> Group Policy Creator Owners
> Domain Admins
> Schema Admins
> Enterprise Admins
> SBS Report Users
> SBS Mobile Users
> Offer Remote Assistance Helpers
>
> Resultant Set Of Policies for User:
> ------------------------------------
>
> Software Installations
> ----------------------
> N/A
>
> Public Key Policies
> -------------------
> N/A
>
> Administrative Templates
> ------------------------
> N/A
>
> Folder Redirection
> ------------------
> N/A
>
> Internet Explorer Browser User Interface
> ----------------------------------------
> N/A
>
> Internet Explorer Connection
> ----------------------------
> N/A
>
> Internet Explorer URLs
> ----------------------
> N/A
>
> Internet Explorer Security
> --------------------------
> N/A
>
> Internet Explorer Programs
> --------------------------
> N/A
>
>
> IPCONFIG /ALL from bad Client machine:
>
>
> C:\Documents and Settings\mike>ipconfig /all
>
> Windows IP Configuration
>
> Host Name . . . . . . . . . . . . : mainxp
> Primary Dns Suffix . . . . . . . :missileone.local
> Node Type . . . . . . . . . . . . : Hybrid
> IP Routing Enabled. . . . . . . . : No
> WINS Proxy Enabled. . . . . . . . : No
> DNS Suffix Search List. . . . . . : missileone.local
> missileone.local
>
> Ethernet adapter Local Area Connection:
>
> Connection-specific DNS Suffix . : missileone.local
> Description . . . . . . . . . . . : Intel(R) PRO/100 VE Network
> Connection
> Physical Address. . . . . . . . . : 00-11-11-25-21-01
> Dhcp Enabled. . . . . . . . . . . : Yes
> Autoconfiguration Enabled . . . . : Yes
> IP Address. . . . . . . . . . . . : 192.168.103.4
> Subnet Mask . . . . . . . . . . . : 255.255.255.0
> Default Gateway . . . . . . . . . : 192.168.103.1
> DHCP Server . . . . . . . . . . . : 192.168.103.53
> DNS Servers . . . . . . . . . . . : 192.168.103.53
> Primary WINS Server . . . . . . . : 192.168.103.53
> Lease Obtained. . . . . . . . . . : Tuesday, September 20, 2005
> 23:40:05
> Lease Expires . . . . . . . . . . : Wednesday, September 28, 2005
> 23:40:05
>
> C:\Documents and Settings\mike>
>
>
> IPCONFIG from Server:
>
> Microsoft Windows [Version 5.2.3790]
> (C) Copyright 1985-2003 Microsoft Corp.
>
> C:\Documents and Settings\Administrator>ipconfig /all
>
> Windows IP Configuration
>
> Host Name . . . . . . . . . . . . : wx98
> Primary Dns Suffix . . . . . . . : missileone.local
> Node Type . . . . . . . . . . . . : Hybrid
> IP Routing Enabled. . . . . . . . : No
> WINS Proxy Enabled. . . . . . . . : No
> DNS Suffix Search List. . . . . . : missileone.local
>
> Ethernet adapter Server Local Area Connection:
>
> Connection-specific DNS Suffix . :
> Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
> Connection
> Physical Address. . . . . . . . . : 00-0C-F1-C9-B6-67
> DHCP Enabled. . . . . . . . . . . : No
> IP Address. . . . . . . . . . . . : 192.168.103.53
> Subnet Mask . . . . . . . . . . . : 255.255.255.0
> Default Gateway . . . . . . . . . : 192.168.103.1
> DNS Servers . . . . . . . . . . . : 192.168.103.53
> Primary WINS Server . . . . . . . : 192.168.103.53
>
> C:\Documents and Settings\Administrator>
>
>

I have no clue what Windows OneCare package, but for start, I would
delete the firewall key from the said registry,and copy one from another
machine, then apply the policy again.

--
Dana
http://www.woodcontour.com
Solid wood and stone PC Peripherals
 
Reply With Quote
 
Adam Butler
Guest
Posts: n/a

 
      09-21-2005
I did visually compare many keys that appear to have something to do with
the windows firewall.
My list of ports that is setup on the server is listed on all my clients
including the one that is not working.
I found no differences between any of the reg keys I looked at between a
working client and the one that the policy is not loading on.

I'd bet it is in there somewhere but , where is the question!

"Wood Contour" <> wrote in message
news:f07Ye.17168$zG1.14828@trnddc05...
> Adam Butler wrote:
>> Hello,
>>
>> I was recently selected to beta test the Windows OneCare package.
>>
>> So I tried it on one of my SBS 2003 client machines.
>> The client machine is an XP pro box with SP2.
>>
>> OneCare seemed to be causing performance issues so I uninstalled it.
>> Soon after, I noticed that my Group Policies were no longer being applied
>> to this machine regardless of which user logged on.
>> All other client machines are working well.
>>
>> The specific group policy has to do with Windows Firewall.
>> I had created a custom port exception list that is applied to all client
>> machines.
>>
>> Now on this machine, my port exceptions no longer appear in Windows
>> Firewall.
>> It seems as if something on this client is blocking the ability to apply
>> the GPO from the SBS server.
>> I did post in the beta newsgroup for OneCare as well but no help.
>>
>> Anyone have any ideas of where to look so I can correct this?
>> This is driving me crazy!
>>
>> I've posted a gpresult /v below as well as an ipconfig /all from the bad
>> client and the server.
>>
>> Thanks All!
>>
>> Output from GPRESULT:
>>
>> Microsoft Windows XP [Version 5.1.2600]
>> (C) Copyright 1985-2001 Microsoft Corp.
>>
>> C:\Documents and Settings\adam>gpresult /v
>>
>> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool
>> v2.0
>> Copyright (C) Microsoft Corp. 1981-2001
>>
>> Created On 9/20/2005 at 23:55:42
>>
>>
>> RSOP results for MISSILEONE\adam on MAINXP : Logging Mode
>> -------------------------------------------------------------
>>
>> OS Type: Microsoft Windows XP Professional
>> OS Configuration: Member Workstation
>> OS Version: 5.1.2600
>> Domain Name: MISSILEONE
>> Domain Type: Windows 2000
>> Site Name: Default-First-Site-Name
>> Roaming Profile:
>> Local Profile: C:\Documents and Settings\adam
>> Connected over a slow link?: No
>>
>>
>> COMPUTER SETTINGS
>> ------------------
>>
>> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=missileone,DC=local
>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>> Group Policy was applied from: wx98.missileone.local
>> Group Policy slow link threshold: 500 kbps
>>
>> Applied Group Policy Objects
>> -----------------------------
>> Small Business Server Windows Firewall
>> Small Business Server Client Computer
>> Small Business Server Remote Assistance Policy
>> Small Business Server Lockout Policy
>> Small Business Server Domain Password Policy
>> Default Domain Policy
>> Rename Administrator Account
>> Local Group Policy
>>
>> The following GPOs were not applied because they were filtered out
>> -------------------------------------------------------------------
>> Small Business Server Internet Connection Firewall
>> Filtering: Denied (WMI Filter)
>> WMI Filter: PreSP2
>>
>> The computer is a part of the following security groups:
>> --------------------------------------------------------
>> BUILTIN\Administrators
>> Everyone
>> BUILTIN\Users
>> NT AUTHORITY\NETWORK
>> NT AUTHORITY\Authenticated Users
>> mainxp$
>> Domain Computers
>>
>> Resultant Set Of Policies for Computer:
>> ----------------------------------------
>>
>> Software Installations
>> ----------------------
>> N/A
>>
>> Startup Scripts
>> ---------------
>> N/A
>>
>> Shutdown Scripts
>> ----------------
>> N/A
>>
>> Account Policies
>> ----------------
>> GPO: Small Business Server Domain Password Policy
>> Policy: MinimumPasswordAge
>> Computer Setting: N/A
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: PasswordHistorySize
>> Computer Setting: 24
>>
>> GPO: Small Business Server Lockout Policy
>> Policy: LockoutDuration
>> Computer Setting: 10
>>
>> GPO: Small Business Server Lockout Policy
>> Policy: ResetLockoutCount
>> Computer Setting: 10
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: MinimumPasswordLength
>> Computer Setting: N/A
>>
>> GPO: Small Business Server Lockout Policy
>> Policy: LockoutBadCount
>> Computer Setting: 50
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: MaximumPasswordAge
>> Computer Setting: 4294967295
>>
>> Audit Policy
>> ------------
>> N/A
>>
>> User Rights
>> -----------
>> N/A
>>
>> Security Options
>> ----------------
>> GPO: Default Domain Policy
>> Policy: RequireLogonToChangePassword
>> Computer Setting: Not Enabled
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: PasswordComplexity
>> Computer Setting: Not Enabled
>>
>> GPO: Default Domain Policy
>> Policy: ForceLogoffWhenHourExpire
>> Computer Setting: Not Enabled
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: ClearTextPassword
>> Computer Setting: Not Enabled
>>
>> Event Log Settings
>> ------------------
>> N/A
>>
>> Restricted Groups
>> -----------------
>> N/A
>>
>> System Services
>> ---------------
>> N/A
>>
>> Registry Settings
>> -----------------
>> N/A
>>
>> File System Settings
>> --------------------
>> N/A
>>
>> Public Key Policies
>> -------------------
>> N/A
>>
>> Administrative Templates
>> ------------------------
>> GPO: Small Business Server Client Computer
>> Setting: software\policies\microsoft\windows\network
>> connections
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Remote Assistance Policy
>> Setting: software\policies\microsoft\windows NT\Terminal
>> Services
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
>> Center
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Remote Assistance Policy
>> Setting: software\policies\microsoft\windows NT\Terminal
>> Services
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>> State: Enabled
>>
>> GPO: Small Business Server Client Computer
>> Setting:
>> software\microsoft\windows\currentversion\policies \explorer
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>> State: Enabled
>>
>> GPO: Small Business Server Client Computer
>> Setting: software\policies\microsoft\windows\network
>> connections
>> State: Enabled
>>
>> GPO: Small Business Server Client Computer
>> Setting: software\microsoft\windows
>> nt\currentversion\winlogon
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>> State: Enabled
>>
>> GPO: Small Business Server Remote Assistance Policy
>> Setting: software\policies\microsoft\windows NT\Terminal
>> Services\RAUnsolicit
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>> State: Enabled
>>
>>
>> USER SETTINGS
>> --------------
>> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=mis sileone,DC=local
>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>> Group Policy was applied from: wx98.missileone.local
>> Group Policy slow link threshold: 500 kbps
>>
>> Applied Group Policy Objects
>> -----------------------------
>> Default Domain Policy
>> Local Group Policy
>>
>> The following GPOs were not applied because they were filtered out
>> -------------------------------------------------------------------
>> Small Business Server Internet Connection Firewall
>> Filtering: Denied (WMI Filter)
>> WMI Filter: PreSP2
>>
>> Small Business Server Lockout Policy
>> Filtering: Disabled (GPO)
>>
>> Rename Administrator Account
>> Filtering: Not Applied (Empty)
>>
>> Small Business Server Domain Password Policy
>> Filtering: Not Applied (Empty)
>>
>> Small Business Server Remote Assistance Policy
>> Filtering: Disabled (GPO)
>>
>> Small Business Server Client Computer
>> Filtering: Not Applied (Empty)
>>
>> Small Business Server Windows Firewall
>> Filtering: Not Applied (Empty)
>>
>> The user is a part of the following security groups:
>> ----------------------------------------------------
>> Domain Users
>> Everyone
>> Debugger Users
>> Offer Remote Assistance Helpers
>> BUILTIN\Administrators
>> BUILTIN\Users
>> NT AUTHORITY\INTERACTIVE
>> NT AUTHORITY\Authenticated Users
>> LOCAL
>> Group Policy Creator Owners
>> Domain Admins
>> Schema Admins
>> Enterprise Admins
>> SBS Report Users
>> SBS Mobile Users
>> Offer Remote Assistance Helpers
>>
>> Resultant Set Of Policies for User:
>> ------------------------------------
>>
>> Software Installations
>> ----------------------
>> N/A
>>
>> Public Key Policies
>> -------------------
>> N/A
>>
>> Administrative Templates
>> ------------------------
>> N/A
>>
>> Folder Redirection
>> ------------------
>> N/A
>>
>> Internet Explorer Browser User Interface
>> ----------------------------------------
>> N/A
>>
>> Internet Explorer Connection
>> ----------------------------
>> N/A
>>
>> Internet Explorer URLs
>> ----------------------
>> N/A
>>
>> Internet Explorer Security
>> --------------------------
>> N/A
>>
>> Internet Explorer Programs
>> --------------------------
>> N/A
>>
>> C:\Documents and Settings\mike>
>>
>> Microsoft Windows XP [Version 5.1.2600]
>> (C) Copyright 1985-2001 Microsoft Corp.
>>
>> C:\Documents and Settings\steve>gpresults /v
>> 'gpresults' is not recognized as an internal or external command,
>> operable program or batch file.
>>
>> C:\Documents and Settings\steve>gpresult /v
>>
>> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool
>> v2.0
>> Copyright (C) Microsoft Corp. 1981-2001
>>
>> Created On 9/20/2005 at 23:55:42
>>
>>
>> RSOP results for KRUSEMISSILE\steve on MAINXP : Logging Mode
>> -------------------------------------------------------------
>>
>> OS Type: Microsoft Windows XP Professional
>> OS Configuration: Member Workstation
>> OS Version: 5.1.2600
>> Domain Name: KRUSEMISSILE
>> Domain Type: Windows 2000
>> Site Name: Default-First-Site-Name
>> Roaming Profile:
>> Local Profile: C:\Documents and Settings\steve
>> Connected over a slow link?: No
>>
>>
>> COMPUTER SETTINGS
>> ------------------
>>
>> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=krusemissile,DC=local
>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>> Group Policy was applied from: wx98.krusemissile.local
>> Group Policy slow link threshold: 500 kbps
>>
>> Applied Group Policy Objects
>> -----------------------------
>> Small Business Server Windows Firewall
>> Small Business Server Client Computer
>> Small Business Server Remote Assistance Policy
>> Small Business Server Lockout Policy
>> Small Business Server Domain Password Policy
>> Default Domain Policy
>> Rename Administrator Account
>> Local Group Policy
>>
>> The following GPOs were not applied because they were filtered out
>> -------------------------------------------------------------------
>> Small Business Server Internet Connection Firewall
>> Filtering: Denied (WMI Filter)
>> WMI Filter: PreSP2
>>
>> The computer is a part of the following security groups:
>> --------------------------------------------------------
>> BUILTIN\Administrators
>> Everyone
>> BUILTIN\Users
>> NT AUTHORITY\NETWORK
>> NT AUTHORITY\Authenticated Users
>> mainxp$
>> Domain Computers
>>
>> Resultant Set Of Policies for Computer:
>> ----------------------------------------
>>
>> Software Installations
>> ----------------------
>> N/A
>>
>> Startup Scripts
>> ---------------
>> N/A
>>
>> Shutdown Scripts
>> ----------------
>> N/A
>>
>> Account Policies
>> ----------------
>> GPO: Small Business Server Domain Password Policy
>> Policy: MinimumPasswordAge
>> Computer Setting: N/A
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: PasswordHistorySize
>> Computer Setting: 24
>>
>> GPO: Small Business Server Lockout Policy
>> Policy: LockoutDuration
>> Computer Setting: 10
>>
>> GPO: Small Business Server Lockout Policy
>> Policy: ResetLockoutCount
>> Computer Setting: 10
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: MinimumPasswordLength
>> Computer Setting: N/A
>>
>> GPO: Small Business Server Lockout Policy
>> Policy: LockoutBadCount
>> Computer Setting: 50
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: MaximumPasswordAge
>> Computer Setting: 4294967295
>>
>> Audit Policy
>> ------------
>> N/A
>>
>> User Rights
>> -----------
>> N/A
>>
>> Security Options
>> ----------------
>> GPO: Default Domain Policy
>> Policy: RequireLogonToChangePassword
>> Computer Setting: Not Enabled
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: PasswordComplexity
>> Computer Setting: Not Enabled
>>
>> GPO: Default Domain Policy
>> Policy: ForceLogoffWhenHourExpire
>> Computer Setting: Not Enabled
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: ClearTextPassword
>> Computer Setting: Not Enabled
>>
>> Event Log Settings
>> ------------------
>> N/A
>>
>> Restricted Groups
>> -----------------
>> N/A
>>
>> System Services
>> ---------------
>> N/A
>>
>> Registry Settings
>> -----------------
>> N/A
>>
>> File System Settings
>> --------------------
>> N/A
>>
>> Public Key Policies
>> -------------------
>> N/A
>>
>> Administrative Templates
>> ------------------------
>> GPO: Small Business Server Client Computer
>> Setting: software\policies\microsoft\windows\network
>> connections
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Remote Assistance Policy
>> Setting: software\policies\microsoft\windows NT\Terminal
>> Services
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
>> Center
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Remote Assistance Policy
>> Setting: software\policies\microsoft\windows NT\Terminal
>> Services
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>> State: Enabled
>>
>> GPO: Small Business Server Client Computer
>> Setting:
>> software\microsoft\windows\currentversion\policies \explorer
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>> State: Enabled
>>
>> GPO: Small Business Server Client Computer
>> Setting: software\policies\microsoft\windows\network
>> connections
>> State: Enabled
>>
>> GPO: Small Business Server Client Computer
>> Setting: software\microsoft\windows
>> nt\currentversion\winlogon
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>> State: Enabled
>>
>> GPO: Small Business Server Remote Assistance Policy
>> Setting: software\policies\microsoft\windows NT\Terminal
>> Services\RAUnsolicit
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>> State: Enabled
>>
>>
>> USER SETTINGS
>> --------------
>> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=kru semissile,DC=local
>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>> Group Policy was applied from: wx98.krusemissile.local
>> Group Policy slow link threshold: 500 kbps
>>
>> Applied Group Policy Objects
>> -----------------------------
>> Default Domain Policy
>> Local Group Policy
>>
>> The following GPOs were not applied because they were filtered out
>> -------------------------------------------------------------------
>> Small Business Server Internet Connection Firewall
>> Filtering: Denied (WMI Filter)
>> WMI Filter: PreSP2
>>
>> Small Business Server Lockout Policy
>> Filtering: Disabled (GPO)
>>
>> Rename Administrator Account
>> Filtering: Not Applied (Empty)
>>
>> Small Business Server Domain Password Policy
>> Filtering: Not Applied (Empty)
>>
>> Small Business Server Remote Assistance Policy
>> Filtering: Disabled (GPO)
>>
>> Small Business Server Client Computer
>> Filtering: Not Applied (Empty)
>>
>> Small Business Server Windows Firewall
>> Filtering: Not Applied (Empty)
>>
>> The user is a part of the following security groups:
>> ----------------------------------------------------
>> Domain Users
>> Everyone
>> Debugger Users
>> Offer Remote Assistance Helpers
>> BUILTIN\Administrators
>> BUILTIN\Users
>> NT AUTHORITY\INTERACTIVE
>> NT AUTHORITY\Authenticated Users
>> LOCAL
>> Group Policy Creator Owners
>> Domain Admins
>> Schema Admins
>> Enterprise Admins
>> SBS Report Users
>> SBS Mobile Users
>> Offer Remote Assistance Helpers
>>
>> Resultant Set Of Policies for User:
>> ------------------------------------
>>
>> Software Installations
>> ----------------------
>> N/A
>>
>> Public Key Policies
>> -------------------
>> N/A
>>
>> Administrative Templates
>> ------------------------
>> N/A
>>
>> Folder Redirection
>> ------------------
>> N/A
>>
>> Internet Explorer Browser User Interface
>> ----------------------------------------
>> N/A
>>
>> Internet Explorer Connection
>> ----------------------------
>> N/A
>>
>> Internet Explorer URLs
>> ----------------------
>> N/A
>>
>> Internet Explorer Security
>> --------------------------
>> N/A
>>
>> Internet Explorer Programs
>> --------------------------
>> N/A
>>
>> C:\Documents and Settings\steve>gpresult /v
>>
>> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool
>> v2.0
>> Copyright (C) Microsoft Corp. 1981-2001
>>
>> Created On 9/21/2005 at 00:01:34
>>
>>
>> RSOP results for KRUSEMISSILE\steve on MAINXP : Logging Mode
>> -------------------------------------------------------------
>>
>> OS Type: Microsoft Windows XP Professional
>> OS Configuration: Member Workstation
>> OS Version: 5.1.2600
>> Domain Name: KRUSEMISSILE
>> Domain Type: Windows 2000
>> Site Name: Default-First-Site-Name
>> Roaming Profile:
>> Local Profile: C:\Documents and Settings\steve
>> Connected over a slow link?: No
>>
>>
>> COMPUTER SETTINGS
>> ------------------
>>
>> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=krusemissile,DC=local
>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>> Group Policy was applied from: wx98.krusemissile.local
>> Group Policy slow link threshold: 500 kbps
>>
>> Applied Group Policy Objects
>> -----------------------------
>> Small Business Server Windows Firewall
>> Small Business Server Client Computer
>> Small Business Server Remote Assistance Policy
>> Small Business Server Lockout Policy
>> Small Business Server Domain Password Policy
>> Default Domain Policy
>> Rename Administrator Account
>> Local Group Policy
>>
>> The following GPOs were not applied because they were filtered out
>> -------------------------------------------------------------------
>> Small Business Server Internet Connection Firewall
>> Filtering: Denied (WMI Filter)
>> WMI Filter: PreSP2
>>
>> The computer is a part of the following security groups:
>> --------------------------------------------------------
>> BUILTIN\Administrators
>> Everyone
>> BUILTIN\Users
>> NT AUTHORITY\NETWORK
>> NT AUTHORITY\Authenticated Users
>> mainxp$
>> Domain Computers
>>
>> Resultant Set Of Policies for Computer:
>> ----------------------------------------
>>
>> Software Installations
>> ----------------------
>> N/A
>>
>> Startup Scripts
>> ---------------
>> N/A
>>
>> Shutdown Scripts
>> ----------------
>> N/A
>>
>> Account Policies
>> ----------------
>> GPO: Small Business Server Domain Password Policy
>> Policy: MinimumPasswordAge
>> Computer Setting: N/A
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: PasswordHistorySize
>> Computer Setting: 24
>>
>> GPO: Small Business Server Lockout Policy
>> Policy: LockoutDuration
>> Computer Setting: 10
>>
>> GPO: Small Business Server Lockout Policy
>> Policy: ResetLockoutCount
>> Computer Setting: 10
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: MinimumPasswordLength
>> Computer Setting: N/A
>>
>> GPO: Small Business Server Lockout Policy
>> Policy: LockoutBadCount
>> Computer Setting: 50
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: MaximumPasswordAge
>> Computer Setting: 4294967295
>>
>> Audit Policy
>> ------------
>> N/A
>>
>> User Rights
>> -----------
>> N/A
>>
>> Security Options
>> ----------------
>> GPO: Default Domain Policy
>> Policy: RequireLogonToChangePassword
>> Computer Setting: Not Enabled
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: PasswordComplexity
>> Computer Setting: Not Enabled
>>
>> GPO: Default Domain Policy
>> Policy: ForceLogoffWhenHourExpire
>> Computer Setting: Not Enabled
>>
>> GPO: Small Business Server Domain Password Policy
>> Policy: ClearTextPassword
>> Computer Setting: Not Enabled
>>
>> Event Log Settings
>> ------------------
>> N/A
>>
>> Restricted Groups
>> -----------------
>> N/A
>>
>> System Services
>> ---------------
>> N/A
>>
>> Registry Settings
>> -----------------
>> N/A
>>
>> File System Settings
>> --------------------
>> N/A
>>
>> Public Key Policies
>> -------------------
>> N/A
>>
>> Administrative Templates
>> ------------------------
>> GPO: Small Business Server Client Computer
>> Setting: software\policies\microsoft\windows\network
>> connections
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Remote Assistance Policy
>> Setting: software\policies\microsoft\windows NT\Terminal
>> Services
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
>> Center
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Remote Assistance Policy
>> Setting: software\policies\microsoft\windows NT\Terminal
>> Services
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>> State: Enabled
>>
>> GPO: Small Business Server Client Computer
>> Setting:
>> software\microsoft\windows\currentversion\policies \explorer
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>> State: Enabled
>>
>> GPO: Small Business Server Client Computer
>> Setting: software\policies\microsoft\windows\network
>> connections
>> State: Enabled
>>
>> GPO: Small Business Server Client Computer
>> Setting: software\microsoft\windows
>> nt\currentversion\winlogon
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>> State: Enabled
>>
>> GPO: Small Business Server Remote Assistance Policy
>> Setting: software\policies\microsoft\windows NT\Terminal
>> Services\RAUnsolicit
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>> State: Enabled
>>
>> GPO: Default Domain Policy
>> Setting:
>> Software\Policies\Microsoft\Windows\WindowsUpdate
>> State: Enabled
>>
>> GPO: Small Business Server Windows Firewall
>> Setting:
>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>> State: Enabled
>>
>>
>> USER SETTINGS
>> --------------
>> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=kru semissile,DC=local
>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>> Group Policy was applied from: wx98.krusemissile.local
>> Group Policy slow link threshold: 500 kbps
>>
>> Applied Group Policy Objects
>> -----------------------------
>> Default Domain Policy
>> Local Group Policy
>>
>> The following GPOs were not applied because they were filtered out
>> -------------------------------------------------------------------
>> Small Business Server Internet Connection Firewall
>> Filtering: Denied (WMI Filter)
>> WMI Filter: PreSP2
>>
>> Small Business Server Lockout Policy
>> Filtering: Disabled (GPO)
>>
>> Rename Administrator Account
>> Filtering: Not Applied (Empty)
>>
>> Small Business Server Domain Password Policy
>> Filtering: Not Applied (Empty)
>>
>> Small Business Server Remote Assistance Policy
>> Filtering: Disabled (GPO)
>>
>> Small Business Server Client Computer
>> Filtering: Not Applied (Empty)
>>
>> Small Business Server Windows Firewall
>> Filtering: Not Applied (Empty)
>>
>> The user is a part of the following security groups:
>> ----------------------------------------------------
>> Domain Users
>> Everyone
>> Debugger Users
>> Offer Remote Assistance Helpers
>> BUILTIN\Administrators
>> BUILTIN\Users
>> NT AUTHORITY\INTERACTIVE
>> NT AUTHORITY\Authenticated Users
>> LOCAL
>> Group Policy Creator Owners
>> Domain Admins
>> Schema Admins
>> Enterprise Admins
>> SBS Report Users
>> SBS Mobile Users
>> Offer Remote Assistance Helpers
>>
>> Resultant Set Of Policies for User:
>> ------------------------------------
>>
>> Software Installations
>> ----------------------
>> N/A
>>
>> Public Key Policies
>> -------------------
>> N/A
>>
>> Administrative Templates
>> ------------------------
>> N/A
>>
>> Folder Redirection
>> ------------------
>> N/A
>>
>> Internet Explorer Browser User Interface
>> ----------------------------------------
>> N/A
>>
>> Internet Explorer Connection
>> ----------------------------
>> N/A
>>
>> Internet Explorer URLs
>> ----------------------
>> N/A
>>
>> Internet Explorer Security
>> --------------------------
>> N/A
>>
>> Internet Explorer Programs
>> --------------------------
>> N/A
>>
>>
>> IPCONFIG /ALL from bad Client machine:
>>
>>
>> C:\Documents and Settings\mike>ipconfig /all
>>
>> Windows IP Configuration
>>
>> Host Name . . . . . . . . . . . . : mainxp
>> Primary Dns Suffix . . . . . . . :missileone.local
>> Node Type . . . . . . . . . . . . : Hybrid
>> IP Routing Enabled. . . . . . . . : No
>> WINS Proxy Enabled. . . . . . . . : No
>> DNS Suffix Search List. . . . . . : missileone.local
>> missileone.local
>>
>> Ethernet adapter Local Area Connection:
>>
>> Connection-specific DNS Suffix . : missileone.local
>> Description . . . . . . . . . . . : Intel(R) PRO/100 VE Network
>> Connection
>> Physical Address. . . . . . . . . : 00-11-11-25-21-01
>> Dhcp Enabled. . . . . . . . . . . : Yes
>> Autoconfiguration Enabled . . . . : Yes
>> IP Address. . . . . . . . . . . . : 192.168.103.4
>> Subnet Mask . . . . . . . . . . . : 255.255.255.0
>> Default Gateway . . . . . . . . . : 192.168.103.1
>> DHCP Server . . . . . . . . . . . : 192.168.103.53
>> DNS Servers . . . . . . . . . . . : 192.168.103.53
>> Primary WINS Server . . . . . . . : 192.168.103.53
>> Lease Obtained. . . . . . . . . . : Tuesday, September 20, 2005
>> 23:40:05
>> Lease Expires . . . . . . . . . . : Wednesday, September 28, 2005
>> 23:40:05
>>
>> C:\Documents and Settings\mike>
>>
>>
>> IPCONFIG from Server:
>>
>> Microsoft Windows [Version 5.2.3790]
>> (C) Copyright 1985-2003 Microsoft Corp.
>>
>> C:\Documents and Settings\Administrator>ipconfig /all
>>
>> Windows IP Configuration
>>
>> Host Name . . . . . . . . . . . . : wx98
>> Primary Dns Suffix . . . . . . . : missileone.local
>> Node Type . . . . . . . . . . . . : Hybrid
>> IP Routing Enabled. . . . . . . . : No
>> WINS Proxy Enabled. . . . . . . . : No
>> DNS Suffix Search List. . . . . . : missileone.local
>>
>> Ethernet adapter Server Local Area Connection:
>>
>> Connection-specific DNS Suffix . :
>> Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
>> Connection
>> Physical Address. . . . . . . . . : 00-0C-F1-C9-B6-67
>> DHCP Enabled. . . . . . . . . . . : No
>> IP Address. . . . . . . . . . . . : 192.168.103.53
>> Subnet Mask . . . . . . . . . . . : 255.255.255.0
>> Default Gateway . . . . . . . . . : 192.168.103.1
>> DNS Servers . . . . . . . . . . . : 192.168.103.53
>> Primary WINS Server . . . . . . . : 192.168.103.53
>>
>> C:\Documents and Settings\Administrator>

> I have no clue what Windows OneCare package, but for start, I would delete
> the firewall key from the said registry,and copy one from another machine,
> then apply the policy again.
>
> --
> Dana
> http://www.woodcontour.com
> Solid wood and stone PC Peripherals



 
Reply With Quote
 
A. Feiner
Guest
Posts: n/a

 
      09-21-2005
Adam Butler wrote:
> I did visually compare many keys that appear to have something to do with
> the windows firewall.
> My list of ports that is setup on the server is listed on all my clients
> including the one that is not working.
> I found no differences between any of the reg keys I looked at between a
> working client and the one that the policy is not loading on.
>
> I'd bet it is in there somewhere but , where is the question!
>
> "Wood Contour" <> wrote in message
> news:f07Ye.17168$zG1.14828@trnddc05...
>> Adam Butler wrote:
>>> Hello,
>>>
>>> I was recently selected to beta test the Windows OneCare package.
>>>
>>> So I tried it on one of my SBS 2003 client machines.
>>> The client machine is an XP pro box with SP2.
>>>
>>> OneCare seemed to be causing performance issues so I uninstalled it.
>>> Soon after, I noticed that my Group Policies were no longer being applied
>>> to this machine regardless of which user logged on.
>>> All other client machines are working well.
>>>
>>> The specific group policy has to do with Windows Firewall.
>>> I had created a custom port exception list that is applied to all client
>>> machines.
>>>
>>> Now on this machine, my port exceptions no longer appear in Windows
>>> Firewall.
>>> It seems as if something on this client is blocking the ability to apply
>>> the GPO from the SBS server.
>>> I did post in the beta newsgroup for OneCare as well but no help.
>>>
>>> Anyone have any ideas of where to look so I can correct this?
>>> This is driving me crazy!
>>>
>>> I've posted a gpresult /v below as well as an ipconfig /all from the bad
>>> client and the server.
>>>
>>> Thanks All!
>>>
>>> Output from GPRESULT:
>>>
>>> Microsoft Windows XP [Version 5.1.2600]
>>> (C) Copyright 1985-2001 Microsoft Corp.
>>>
>>> C:\Documents and Settings\adam>gpresult /v
>>>
>>> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool
>>> v2.0
>>> Copyright (C) Microsoft Corp. 1981-2001
>>>
>>> Created On 9/20/2005 at 23:55:42
>>>
>>>
>>> RSOP results for MISSILEONE\adam on MAINXP : Logging Mode
>>> -------------------------------------------------------------
>>>
>>> OS Type: Microsoft Windows XP Professional
>>> OS Configuration: Member Workstation
>>> OS Version: 5.1.2600
>>> Domain Name: MISSILEONE
>>> Domain Type: Windows 2000
>>> Site Name: Default-First-Site-Name
>>> Roaming Profile:
>>> Local Profile: C:\Documents and Settings\adam
>>> Connected over a slow link?: No
>>>
>>>
>>> COMPUTER SETTINGS
>>> ------------------
>>>
>>> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=missileone,DC=local
>>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>>> Group Policy was applied from: wx98.missileone.local
>>> Group Policy slow link threshold: 500 kbps
>>>
>>> Applied Group Policy Objects
>>> -----------------------------
>>> Small Business Server Windows Firewall
>>> Small Business Server Client Computer
>>> Small Business Server Remote Assistance Policy
>>> Small Business Server Lockout Policy
>>> Small Business Server Domain Password Policy
>>> Default Domain Policy
>>> Rename Administrator Account
>>> Local Group Policy
>>>
>>> The following GPOs were not applied because they were filtered out
>>> -------------------------------------------------------------------
>>> Small Business Server Internet Connection Firewall
>>> Filtering: Denied (WMI Filter)
>>> WMI Filter: PreSP2
>>>
>>> The computer is a part of the following security groups:
>>> --------------------------------------------------------
>>> BUILTIN\Administrators
>>> Everyone
>>> BUILTIN\Users
>>> NT AUTHORITY\NETWORK
>>> NT AUTHORITY\Authenticated Users
>>> mainxp$
>>> Domain Computers
>>>
>>> Resultant Set Of Policies for Computer:
>>> ----------------------------------------
>>>
>>> Software Installations
>>> ----------------------
>>> N/A
>>>
>>> Startup Scripts
>>> ---------------
>>> N/A
>>>
>>> Shutdown Scripts
>>> ----------------
>>> N/A
>>>
>>> Account Policies
>>> ----------------
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: MinimumPasswordAge
>>> Computer Setting: N/A
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: PasswordHistorySize
>>> Computer Setting: 24
>>>
>>> GPO: Small Business Server Lockout Policy
>>> Policy: LockoutDuration
>>> Computer Setting: 10
>>>
>>> GPO: Small Business Server Lockout Policy
>>> Policy: ResetLockoutCount
>>> Computer Setting: 10
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: MinimumPasswordLength
>>> Computer Setting: N/A
>>>
>>> GPO: Small Business Server Lockout Policy
>>> Policy: LockoutBadCount
>>> Computer Setting: 50
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: MaximumPasswordAge
>>> Computer Setting: 4294967295
>>>
>>> Audit Policy
>>> ------------
>>> N/A
>>>
>>> User Rights
>>> -----------
>>> N/A
>>>
>>> Security Options
>>> ----------------
>>> GPO: Default Domain Policy
>>> Policy: RequireLogonToChangePassword
>>> Computer Setting: Not Enabled
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: PasswordComplexity
>>> Computer Setting: Not Enabled
>>>
>>> GPO: Default Domain Policy
>>> Policy: ForceLogoffWhenHourExpire
>>> Computer Setting: Not Enabled
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: ClearTextPassword
>>> Computer Setting: Not Enabled
>>>
>>> Event Log Settings
>>> ------------------
>>> N/A
>>>
>>> Restricted Groups
>>> -----------------
>>> N/A
>>>
>>> System Services
>>> ---------------
>>> N/A
>>>
>>> Registry Settings
>>> -----------------
>>> N/A
>>>
>>> File System Settings
>>> --------------------
>>> N/A
>>>
>>> Public Key Policies
>>> -------------------
>>> N/A
>>>
>>> Administrative Templates
>>> ------------------------
>>> GPO: Small Business Server Client Computer
>>> Setting: software\policies\microsoft\windows\network
>>> connections
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Remote Assistance Policy
>>> Setting: software\policies\microsoft\windows NT\Terminal
>>> Services
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
>>> Center
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Remote Assistance Policy
>>> Setting: software\policies\microsoft\windows NT\Terminal
>>> Services
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>>> State: Enabled
>>>
>>> GPO: Small Business Server Client Computer
>>> Setting:
>>> software\microsoft\windows\currentversion\policies \explorer
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>>> State: Enabled
>>>
>>> GPO: Small Business Server Client Computer
>>> Setting: software\policies\microsoft\windows\network
>>> connections
>>> State: Enabled
>>>
>>> GPO: Small Business Server Client Computer
>>> Setting: software\microsoft\windows
>>> nt\currentversion\winlogon
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>>> State: Enabled
>>>
>>> GPO: Small Business Server Remote Assistance Policy
>>> Setting: software\policies\microsoft\windows NT\Terminal
>>> Services\RAUnsolicit
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>>> State: Enabled
>>>
>>>
>>> USER SETTINGS
>>> --------------
>>> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=mis sileone,DC=local
>>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>>> Group Policy was applied from: wx98.missileone.local
>>> Group Policy slow link threshold: 500 kbps
>>>
>>> Applied Group Policy Objects
>>> -----------------------------
>>> Default Domain Policy
>>> Local Group Policy
>>>
>>> The following GPOs were not applied because they were filtered out
>>> -------------------------------------------------------------------
>>> Small Business Server Internet Connection Firewall
>>> Filtering: Denied (WMI Filter)
>>> WMI Filter: PreSP2
>>>
>>> Small Business Server Lockout Policy
>>> Filtering: Disabled (GPO)
>>>
>>> Rename Administrator Account
>>> Filtering: Not Applied (Empty)
>>>
>>> Small Business Server Domain Password Policy
>>> Filtering: Not Applied (Empty)
>>>
>>> Small Business Server Remote Assistance Policy
>>> Filtering: Disabled (GPO)
>>>
>>> Small Business Server Client Computer
>>> Filtering: Not Applied (Empty)
>>>
>>> Small Business Server Windows Firewall
>>> Filtering: Not Applied (Empty)
>>>
>>> The user is a part of the following security groups:
>>> ----------------------------------------------------
>>> Domain Users
>>> Everyone
>>> Debugger Users
>>> Offer Remote Assistance Helpers
>>> BUILTIN\Administrators
>>> BUILTIN\Users
>>> NT AUTHORITY\INTERACTIVE
>>> NT AUTHORITY\Authenticated Users
>>> LOCAL
>>> Group Policy Creator Owners
>>> Domain Admins
>>> Schema Admins
>>> Enterprise Admins
>>> SBS Report Users
>>> SBS Mobile Users
>>> Offer Remote Assistance Helpers
>>>
>>> Resultant Set Of Policies for User:
>>> ------------------------------------
>>>
>>> Software Installations
>>> ----------------------
>>> N/A
>>>
>>> Public Key Policies
>>> -------------------
>>> N/A
>>>
>>> Administrative Templates
>>> ------------------------
>>> N/A
>>>
>>> Folder Redirection
>>> ------------------
>>> N/A
>>>
>>> Internet Explorer Browser User Interface
>>> ----------------------------------------
>>> N/A
>>>
>>> Internet Explorer Connection
>>> ----------------------------
>>> N/A
>>>
>>> Internet Explorer URLs
>>> ----------------------
>>> N/A
>>>
>>> Internet Explorer Security
>>> --------------------------
>>> N/A
>>>
>>> Internet Explorer Programs
>>> --------------------------
>>> N/A
>>>
>>> C:\Documents and Settings\mike>
>>>
>>> Microsoft Windows XP [Version 5.1.2600]
>>> (C) Copyright 1985-2001 Microsoft Corp.
>>>
>>> C:\Documents and Settings\steve>gpresults /v
>>> 'gpresults' is not recognized as an internal or external command,
>>> operable program or batch file.
>>>
>>> C:\Documents and Settings\steve>gpresult /v
>>>
>>> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool
>>> v2.0
>>> Copyright (C) Microsoft Corp. 1981-2001
>>>
>>> Created On 9/20/2005 at 23:55:42
>>>
>>>
>>> RSOP results for KRUSEMISSILE\steve on MAINXP : Logging Mode
>>> -------------------------------------------------------------
>>>
>>> OS Type: Microsoft Windows XP Professional
>>> OS Configuration: Member Workstation
>>> OS Version: 5.1.2600
>>> Domain Name: KRUSEMISSILE
>>> Domain Type: Windows 2000
>>> Site Name: Default-First-Site-Name
>>> Roaming Profile:
>>> Local Profile: C:\Documents and Settings\steve
>>> Connected over a slow link?: No
>>>
>>>
>>> COMPUTER SETTINGS
>>> ------------------
>>>
>>> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=krusemissile,DC=local
>>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>>> Group Policy was applied from: wx98.krusemissile.local
>>> Group Policy slow link threshold: 500 kbps
>>>
>>> Applied Group Policy Objects
>>> -----------------------------
>>> Small Business Server Windows Firewall
>>> Small Business Server Client Computer
>>> Small Business Server Remote Assistance Policy
>>> Small Business Server Lockout Policy
>>> Small Business Server Domain Password Policy
>>> Default Domain Policy
>>> Rename Administrator Account
>>> Local Group Policy
>>>
>>> The following GPOs were not applied because they were filtered out
>>> -------------------------------------------------------------------
>>> Small Business Server Internet Connection Firewall
>>> Filtering: Denied (WMI Filter)
>>> WMI Filter: PreSP2
>>>
>>> The computer is a part of the following security groups:
>>> --------------------------------------------------------
>>> BUILTIN\Administrators
>>> Everyone
>>> BUILTIN\Users
>>> NT AUTHORITY\NETWORK
>>> NT AUTHORITY\Authenticated Users
>>> mainxp$
>>> Domain Computers
>>>
>>> Resultant Set Of Policies for Computer:
>>> ----------------------------------------
>>>
>>> Software Installations
>>> ----------------------
>>> N/A
>>>
>>> Startup Scripts
>>> ---------------
>>> N/A
>>>
>>> Shutdown Scripts
>>> ----------------
>>> N/A
>>>
>>> Account Policies
>>> ----------------
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: MinimumPasswordAge
>>> Computer Setting: N/A
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: PasswordHistorySize
>>> Computer Setting: 24
>>>
>>> GPO: Small Business Server Lockout Policy
>>> Policy: LockoutDuration
>>> Computer Setting: 10
>>>
>>> GPO: Small Business Server Lockout Policy
>>> Policy: ResetLockoutCount
>>> Computer Setting: 10
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: MinimumPasswordLength
>>> Computer Setting: N/A
>>>
>>> GPO: Small Business Server Lockout Policy
>>> Policy: LockoutBadCount
>>> Computer Setting: 50
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: MaximumPasswordAge
>>> Computer Setting: 4294967295
>>>
>>> Audit Policy
>>> ------------
>>> N/A
>>>
>>> User Rights
>>> -----------
>>> N/A
>>>
>>> Security Options
>>> ----------------
>>> GPO: Default Domain Policy
>>> Policy: RequireLogonToChangePassword
>>> Computer Setting: Not Enabled
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: PasswordComplexity
>>> Computer Setting: Not Enabled
>>>
>>> GPO: Default Domain Policy
>>> Policy: ForceLogoffWhenHourExpire
>>> Computer Setting: Not Enabled
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: ClearTextPassword
>>> Computer Setting: Not Enabled
>>>
>>> Event Log Settings
>>> ------------------
>>> N/A
>>>
>>> Restricted Groups
>>> -----------------
>>> N/A
>>>
>>> System Services
>>> ---------------
>>> N/A
>>>
>>> Registry Settings
>>> -----------------
>>> N/A
>>>
>>> File System Settings
>>> --------------------
>>> N/A
>>>
>>> Public Key Policies
>>> -------------------
>>> N/A
>>>
>>> Administrative Templates
>>> ------------------------
>>> GPO: Small Business Server Client Computer
>>> Setting: software\policies\microsoft\windows\network
>>> connections
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Remote Assistance Policy
>>> Setting: software\policies\microsoft\windows NT\Terminal
>>> Services
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
>>> Center
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Remote Assistance Policy
>>> Setting: software\policies\microsoft\windows NT\Terminal
>>> Services
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>>> State: Enabled
>>>
>>> GPO: Small Business Server Client Computer
>>> Setting:
>>> software\microsoft\windows\currentversion\policies \explorer
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>>> State: Enabled
>>>
>>> GPO: Small Business Server Client Computer
>>> Setting: software\policies\microsoft\windows\network
>>> connections
>>> State: Enabled
>>>
>>> GPO: Small Business Server Client Computer
>>> Setting: software\microsoft\windows
>>> nt\currentversion\winlogon
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>>> State: Enabled
>>>
>>> GPO: Small Business Server Remote Assistance Policy
>>> Setting: software\policies\microsoft\windows NT\Terminal
>>> Services\RAUnsolicit
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>>> State: Enabled
>>>
>>>
>>> USER SETTINGS
>>> --------------
>>> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=kru semissile,DC=local
>>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>>> Group Policy was applied from: wx98.krusemissile.local
>>> Group Policy slow link threshold: 500 kbps
>>>
>>> Applied Group Policy Objects
>>> -----------------------------
>>> Default Domain Policy
>>> Local Group Policy
>>>
>>> The following GPOs were not applied because they were filtered out
>>> -------------------------------------------------------------------
>>> Small Business Server Internet Connection Firewall
>>> Filtering: Denied (WMI Filter)
>>> WMI Filter: PreSP2
>>>
>>> Small Business Server Lockout Policy
>>> Filtering: Disabled (GPO)
>>>
>>> Rename Administrator Account
>>> Filtering: Not Applied (Empty)
>>>
>>> Small Business Server Domain Password Policy
>>> Filtering: Not Applied (Empty)
>>>
>>> Small Business Server Remote Assistance Policy
>>> Filtering: Disabled (GPO)
>>>
>>> Small Business Server Client Computer
>>> Filtering: Not Applied (Empty)
>>>
>>> Small Business Server Windows Firewall
>>> Filtering: Not Applied (Empty)
>>>
>>> The user is a part of the following security groups:
>>> ----------------------------------------------------
>>> Domain Users
>>> Everyone
>>> Debugger Users
>>> Offer Remote Assistance Helpers
>>> BUILTIN\Administrators
>>> BUILTIN\Users
>>> NT AUTHORITY\INTERACTIVE
>>> NT AUTHORITY\Authenticated Users
>>> LOCAL
>>> Group Policy Creator Owners
>>> Domain Admins
>>> Schema Admins
>>> Enterprise Admins
>>> SBS Report Users
>>> SBS Mobile Users
>>> Offer Remote Assistance Helpers
>>>
>>> Resultant Set Of Policies for User:
>>> ------------------------------------
>>>
>>> Software Installations
>>> ----------------------
>>> N/A
>>>
>>> Public Key Policies
>>> -------------------
>>> N/A
>>>
>>> Administrative Templates
>>> ------------------------
>>> N/A
>>>
>>> Folder Redirection
>>> ------------------
>>> N/A
>>>
>>> Internet Explorer Browser User Interface
>>> ----------------------------------------
>>> N/A
>>>
>>> Internet Explorer Connection
>>> ----------------------------
>>> N/A
>>>
>>> Internet Explorer URLs
>>> ----------------------
>>> N/A
>>>
>>> Internet Explorer Security
>>> --------------------------
>>> N/A
>>>
>>> Internet Explorer Programs
>>> --------------------------
>>> N/A
>>>
>>> C:\Documents and Settings\steve>gpresult /v
>>>
>>> Microsoft (R) Windows (R) XP Operating System Group Policy Result tool
>>> v2.0
>>> Copyright (C) Microsoft Corp. 1981-2001
>>>
>>> Created On 9/21/2005 at 00:01:34
>>>
>>>
>>> RSOP results for KRUSEMISSILE\steve on MAINXP : Logging Mode
>>> -------------------------------------------------------------
>>>
>>> OS Type: Microsoft Windows XP Professional
>>> OS Configuration: Member Workstation
>>> OS Version: 5.1.2600
>>> Domain Name: KRUSEMISSILE
>>> Domain Type: Windows 2000
>>> Site Name: Default-First-Site-Name
>>> Roaming Profile:
>>> Local Profile: C:\Documents and Settings\steve
>>> Connected over a slow link?: No
>>>
>>>
>>> COMPUTER SETTINGS
>>> ------------------
>>>
>>> CN=mainxp,OU=SBSComputers,OU=Computers,OU=MyBusine ss,DC=krusemissile,DC=local
>>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>>> Group Policy was applied from: wx98.krusemissile.local
>>> Group Policy slow link threshold: 500 kbps
>>>
>>> Applied Group Policy Objects
>>> -----------------------------
>>> Small Business Server Windows Firewall
>>> Small Business Server Client Computer
>>> Small Business Server Remote Assistance Policy
>>> Small Business Server Lockout Policy
>>> Small Business Server Domain Password Policy
>>> Default Domain Policy
>>> Rename Administrator Account
>>> Local Group Policy
>>>
>>> The following GPOs were not applied because they were filtered out
>>> -------------------------------------------------------------------
>>> Small Business Server Internet Connection Firewall
>>> Filtering: Denied (WMI Filter)
>>> WMI Filter: PreSP2
>>>
>>> The computer is a part of the following security groups:
>>> --------------------------------------------------------
>>> BUILTIN\Administrators
>>> Everyone
>>> BUILTIN\Users
>>> NT AUTHORITY\NETWORK
>>> NT AUTHORITY\Authenticated Users
>>> mainxp$
>>> Domain Computers
>>>
>>> Resultant Set Of Policies for Computer:
>>> ----------------------------------------
>>>
>>> Software Installations
>>> ----------------------
>>> N/A
>>>
>>> Startup Scripts
>>> ---------------
>>> N/A
>>>
>>> Shutdown Scripts
>>> ----------------
>>> N/A
>>>
>>> Account Policies
>>> ----------------
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: MinimumPasswordAge
>>> Computer Setting: N/A
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: PasswordHistorySize
>>> Computer Setting: 24
>>>
>>> GPO: Small Business Server Lockout Policy
>>> Policy: LockoutDuration
>>> Computer Setting: 10
>>>
>>> GPO: Small Business Server Lockout Policy
>>> Policy: ResetLockoutCount
>>> Computer Setting: 10
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: MinimumPasswordLength
>>> Computer Setting: N/A
>>>
>>> GPO: Small Business Server Lockout Policy
>>> Policy: LockoutBadCount
>>> Computer Setting: 50
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: MaximumPasswordAge
>>> Computer Setting: 4294967295
>>>
>>> Audit Policy
>>> ------------
>>> N/A
>>>
>>> User Rights
>>> -----------
>>> N/A
>>>
>>> Security Options
>>> ----------------
>>> GPO: Default Domain Policy
>>> Policy: RequireLogonToChangePassword
>>> Computer Setting: Not Enabled
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: PasswordComplexity
>>> Computer Setting: Not Enabled
>>>
>>> GPO: Default Domain Policy
>>> Policy: ForceLogoffWhenHourExpire
>>> Computer Setting: Not Enabled
>>>
>>> GPO: Small Business Server Domain Password Policy
>>> Policy: ClearTextPassword
>>> Computer Setting: Not Enabled
>>>
>>> Event Log Settings
>>> ------------------
>>> N/A
>>>
>>> Restricted Groups
>>> -----------------
>>> N/A
>>>
>>> System Services
>>> ---------------
>>> N/A
>>>
>>> Registry Settings
>>> -----------------
>>> N/A
>>>
>>> File System Settings
>>> --------------------
>>> N/A
>>>
>>> Public Key Policies
>>> -------------------
>>> N/A
>>>
>>> Administrative Templates
>>> ------------------------
>>> GPO: Small Business Server Client Computer
>>> Setting: software\policies\microsoft\windows\network
>>> connections
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\GloballyOpenPorts
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Remote Assistance Policy
>>> Setting: software\policies\microsoft\windows NT\Terminal
>>> Services
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting: SOFTWARE\Policies\Microsoft\Windows NT\Security
>>> Center
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications\List
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Remote Assistance Policy
>>> Setting: software\policies\microsoft\windows NT\Terminal
>>> Services
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\RemoteDesktop
>>> State: Enabled
>>>
>>> GPO: Small Business Server Client Computer
>>> Setting:
>>> software\microsoft\windows\currentversion\policies \explorer
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate\ AU
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts
>>> State: Enabled
>>>
>>> GPO: Small Business Server Client Computer
>>> Setting: software\policies\microsoft\windows\network
>>> connections
>>> State: Enabled
>>>
>>> GPO: Small Business Server Client Computer
>>> Setting: software\microsoft\windows
>>> nt\currentversion\winlogon
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Standa rdProfile\AuthorizedApplications
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\Services\FileAndPrint
>>> State: Enabled
>>>
>>> GPO: Small Business Server Remote Assistance Policy
>>> Setting: software\policies\microsoft\windows NT\Terminal
>>> Services\RAUnsolicit
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\GloballyOpenPorts\List
>>> State: Enabled
>>>
>>> GPO: Default Domain Policy
>>> Setting:
>>> Software\Policies\Microsoft\Windows\WindowsUpdate
>>> State: Enabled
>>>
>>> GPO: Small Business Server Windows Firewall
>>> Setting:
>>> SOFTWARE\Policies\Microsoft\WindowsFirewall\Domain Profile\AuthorizedApplications
>>> State: Enabled
>>>
>>>
>>> USER SETTINGS
>>> --------------
>>> CN=steve,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=kru semissile,DC=local
>>> Last time Group Policy was applied: 9/20/2005 at 23:41:31
>>> Group Policy was applied from: wx98.krusemissile.local
>>> Group Policy slow link threshold: 500 kbps
>>>
>>> Applied Group Policy Objects
>>> -----------------------------
>>> Default Domain Policy
>>> Local Group Policy
>>>
>>> The following GPOs were not applied because they were filtered out
>>> -------------------------------------------------------------------
>>> Small Business Server Internet Connection Firewall
>>> Filtering: Denied (WMI Filter)
>>> WMI Filter: PreSP2
>>>
>>> Small Business Server Lockout Policy
>>> Filtering: Disabled (GPO)
>>>
>>> Rename Administrator Account
>>> Filtering: Not Applied (Empty)
>>>
>>> Small Business Server Domain Password Policy
>>> Filtering: Not Applied (Empty)
>>>
>>> Small Business Server Remote Assistance Policy
>>> Filtering: Disabled (GPO)
>>>
>>> Small Business Server Client Computer
>>> Filtering: Not Applied (Empty)
>>>
>>> Small Business Server Windows Firewall
>>> Filtering: Not Applied (Empty)
>>>
>>> The user is a part of the following security groups:
>>> ----------------------------------------------------
>>> Domain Users
>>> Everyone
>>> Debugger Users
>>> Offer Remote Assistance Helpers
>>> BUILTIN\Administrators
>>> BUILTIN\Users
>>> NT AUTHORITY\INTERACTIVE
>>> NT AUTHORITY\Authenticated Users
>>> LOCAL
>>> Group Policy Creator Owners
>>> Domain Admins
>>> Schema Admins
>>> Enterprise Admins
>>> SBS Report Users
>>> SBS Mobile Users
>>> Offer Remote Assistance Helpers
>>>
>>> Resultant Set Of Policies for User:
>>> ------------------------------------
>>>
>>> Software Installations
>>> ----------------------
>>> N/A
>>>
>>> Public Key Policies
>>> -------------------
>>> N/A
>>>
>>> Administrative Templates
>>> ------------------------
>>> N/A
>>>
>>> Folder Redirection
>>> ------------------
>>> N/A
>>>
>>> Internet Explorer Browser User Interface
>>> ----------------------------------------
>>> N/A
>>>
>>> Internet Explorer Connection
>>> ----------------------------
>>> N/A
>>>
>>> Internet Explorer URLs
>>> ----------------------
>>> N/A
>>>
>>> Internet Explorer Security
>>> --------------------------
>>> N/A
>>>
>>> Internet Explorer Programs
>>> --------------------------
>>> N/A
>>>
>>>
>>> IPCONFIG /ALL from bad Client machine:
>>>
>>>
>>> C:\Documents and Settings\mike>ipconfig /all
>>>
>>> Windows IP Configuration
>>>
>>> Host Name . . . . . . . . . . . . : mainxp
>>> Primary Dns Suffix . . . . . . . :missileone.local
>>> Node Type . . . . . . . . . . . . : Hybrid
>>> IP Routing Enabled. . . . . . . . : No
>>> WINS Proxy Enabled. . . . . . . . : No
>>> DNS Suffix Search List. . . . . . : missileone.local
>>> missileone.local
>>>
>>> Ethernet adapter Local Area Connection:
>>>
>>> Connection-specific DNS Suffix . : missileone.local
>>> Description . . . . . . . . . . . : Intel(R) PRO/100 VE Network
>>> Connection
>>> Physical Address. . . . . . . . . : 00-11-11-25-21-01
>>> Dhcp Enabled. . . . . . . . . . . : Yes
>>> Autoconfiguration Enabled . . . . : Yes
>>> IP Address. . . . . . . . . . . . : 192.168.103.4
>>> Subnet Mask . . . . . . . . . . . : 255.255.255.0
>>> Default Gateway . . . . . . . . . : 192.168.103.1
>>> DHCP Server . . . . . . . . . . . : 192.168.103.53
>>> DNS Servers . . . . . . . . . . . : 192.168.103.53
>>> Primary WINS Server . . . . . . . : 192.168.103.53
>>> Lease Obtained. . . . . . . . . . : Tuesday, September 20, 2005
>>> 23:40:05
>>> Lease Expires . . . . . . . . . . : Wednesday, September 28, 2005
>>> 23:40:05
>>>
>>> C:\Documents and Settings\mike>
>>>
>>>
>>> IPCONFIG from Server:
>>>
>>> Microsoft Windows [Version 5.2.3790]
>>> (C) Copyright 1985-2003 Microsoft Corp.
>>>
>>> C:\Documents and Settings\Administrator>ipconfig /all
>>>
>>> Windows IP Configuration
>>>
>>> Host Name . . . . . . . . . . . . : wx98
>>> Primary Dns Suffix . . . . . . . : missileone.local
>>> Node Type . . . . . . . . . . . . : Hybrid
>>> IP Routing Enabled. . . . . . . . : No
>>> WINS Proxy Enabled. . . . . . . . : No
>>> DNS Suffix Search List. . . . . . : missileone.local
>>>
>>> Ethernet adapter Server Local Area Connection:
>>>
>>> Connection-specific DNS Suffix . :
>>> Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
>>> Connection
>>> Physical Address. . . . . . . . . : 00-0C-F1-C9-B6-67
>>> DHCP Enabled. . . . . . . . . . . : No
>>> IP Address. . . . . . . . . . . . : 192.168.103.53
>>> Subnet Mask . . . . . . . . . . . : 255.255.255.0
>>> Default Gateway . . . . . . . . . : 192.168.103.1
>>> DNS Servers . . . . . . . . . . . : 192.168.103.53
>>> Primary WINS Server . . . . . . . : 192.168.103.53
>>>
>>> C:\Documents and Settings\Administrator>

>> I have no clue what Windows OneCare package, but for start, I would delete
>> the firewall key from the said registry,and copy one from another machine,
>> then apply the policy again.
>>
>> --
>> Dana
>> http://www.woodcontour.com
>> Solid wood and stone PC Peripherals

>
>

"I'd bet it is in there somewhere but , where is the question!" I have
been saying that for years.
Did you try wiping out your key? Create it without inheritance from the
top?

--
A. Feiner
http://www.woodcontour.com
Solid wood and stone PC Peripherals
 
Reply With Quote
 
Adam Butler
Guest
Posts: n/a

 
      09-21-2005
I think I found the issue.
Now to figure out how to correct it.
It seems that something has forced this client to use the Standard versus
the Domain windows firewall policy.
Something is blocking what they call "Network Determination" from what I can
tell.

So when I click on my Windows Firewall tab, I see at the bottom of the
window that it is using my non-domain settings while it should be using my
domain settings.

I'm going to make a new post now I suppose.
"A. Feiner" <> wrote in message
news:BnjYe.7639$9a2.4732@trnddc04...
> Adam Butler wrote:
>> I did visually compare many keys that appear to have something to do with
>> the windows firewall.
>> My list of ports that is setup on the server is listed on all my clients
>> including the one that is not working.
>> I found no differences between any of the reg keys I looked at between a
>> working client and the one that the policy is not loading on.
>>
>> I'd bet it is in there somewhere but , where is the question!
>>
>> "Wood Contour" <> wrote in message
>> news:f07Ye.17168$zG1.14828@trnddc05...
>>> Adam Butler wrote:
>>>> Hello,
>>>>
>>>> I was recently selected to beta test the Windows OneCare package.
>>>>
>>>> So I tried it on one of my SBS 2003 client machines.
>>>> The client machine is an XP pro box with SP2.
>>>>
>>>> OneCare seemed to be causing performance issues so I uninstalled it.
>>>> Soon after, I noticed that my Group Policies were no longer being
>>>> applied to this machine regardless of which user logged on.
>>>> All other client machines are working well.
>>>>
>>>> The specific group policy has to do with Windows Firewall.
>>>> I had created a custom port exception list that is applied to all
>>>> client machines.
>>>>
>>>> Now on this machine, my port exceptions no longer appear in Windows
>>>> Firewall.
>>>> It seems as if something on this client is blocking the ability to
>>>> apply the GPO from the SBS server.
>>>> I did post in the beta newsgroup for OneCare as well but no help.
>>>>
>>>> Anyone have any ideas of where to look so I can correct this?
>>>> This is driving me crazy!
>>>>


>>> I have no clue what Windows OneCare package, but for start, I would
>>> delete the firewall key from the said registry,and copy one from another
>>> machine, then apply the policy again.
>>>
>>> --
>>> Dana
>>> http://www.woodcontour.com
>>> Solid wood and stone PC Peripherals

>>
>>

> "I'd bet it is in there somewhere but , where is the question!" I have
> been saying that for years.
> Did you try wiping out your key? Create it without inheritance from the
> top?
>
> --
> A. Feiner
> http://www.woodcontour.com
> Solid wood and stone PC Peripherals



 
Reply With Quote
 
Adam Butler
Guest
Posts: n/a

 
      09-21-2005
One stupid question.
Where is the "firewall key" located?

>>> I have no clue what Windows OneCare package, but for start, I would
>>> delete the firewall key from the said registry,and copy one from another
>>> machine, then apply the policy again.
>>>
>>> --
>>> Dana
>>> http://www.woodcontour.com
>>> Solid wood and stone PC Peripherals

>>
>>

> "I'd bet it is in there somewhere but , where is the question!" I have
> been saying that for years.
> Did you try wiping out your key? Create it without inheritance from the
> top?
>
> --
> A. Feiner
> http://www.woodcontour.com
> Solid wood and stone PC Peripherals



 
Reply With Quote
 
A. Feiner
Guest
Posts: n/a

 
      09-22-2005
"SOFTWARE\Policies\Microsoft\WindowsFirewall\. ..
"Adam Butler" <> wrote in message
news:...
> One stupid question.
> Where is the "firewall key" located?
>
>>>> I have no clue what Windows OneCare package, but for start, I would
>>>> delete the firewall key from the said registry,and copy one from
>>>> another machine, then apply the policy again.
>>>>
>>>> --
>>>> Dana
>>>> http://www.woodcontour.com
>>>> Solid wood and stone PC Peripherals
>>>
>>>

>> "I'd bet it is in there somewhere but , where is the question!" I have
>> been saying that for years.
>> Did you try wiping out your key? Create it without inheritance from the
>> top?
>>
>> --
>> A. Feiner
>> http://www.woodcontour.com
>> Solid wood and stone PC Peripherals

>
>



 
Reply With Quote
 
Adam Butler
Guest
Posts: n/a

 
      09-22-2005
OK, Thanks for that location.
I tried removing the keys and then let the group policy recreate the keys.
All my port exceptions or GloballyOpenPorts are listed in the key but the
darn thing still will not use my domain policy.
It keeps using the Standard or non-domain policy.
At least it is picking up the group policy but something is refusing to
allow this client to use it!

I've even removed the client from the domain and renamed the client and then
added it back to the domain under the new name.
Still same problem.

I guess I'll give it a few days and see if anyone over in the OneCare beta
group has any suggestions and if not then it looks like the time to format.
Thanks for your suggestions and of course if anyone has anything further for
me to try then please let me know!

"A. Feiner" <> wrote in message
news:vIpYe.2255$EH.571@trnddc01...
> "SOFTWARE\Policies\Microsoft\WindowsFirewall\. ..
> "Adam Butler" <> wrote in message
> news:...
>> One stupid question.
>> Where is the "firewall key" located?
>>
>>>>> I have no clue what Windows OneCare package, but for start, I would
>>>>> delete the firewall key from the said registry,and copy one from
>>>>> another machine, then apply the policy again.
>>>>>
>>>>> --
>>>>> Dana
>>>>> http://www.woodcontour.com
>>>>> Solid wood and stone PC Peripherals
>>>>
>>>>
>>> "I'd bet it is in there somewhere but , where is the question!" I have
>>> been saying that for years.
>>> Did you try wiping out your key? Create it without inheritance from the
>>> top?
>>>
>>> --
>>> A. Feiner
>>> http://www.woodcontour.com
>>> Solid wood and stone PC Peripherals

>>
>>

>
>



 
Reply With Quote
 
A. Feiner
Guest
Posts: n/a

 
      09-22-2005
Are permissions on the keys inherited from the top? Try disable inheritance.
"Adam Butler" <> wrote in message
news:...
> OK, Thanks for that location.
> I tried removing the keys and then let the group policy recreate the keys.
> All my port exceptions or GloballyOpenPorts are listed in the key but the
> darn thing still will not use my domain policy.
> It keeps using the Standard or non-domain policy.
> At least it is picking up the group policy but something is refusing to
> allow this client to use it!
>
> I've even removed the client from the domain and renamed the client and
> then added it back to the domain under the new name.
> Still same problem.
>
> I guess I'll give it a few days and see if anyone over in the OneCare beta
> group has any suggestions and if not then it looks like the time to
> format.
> Thanks for your suggestions and of course if anyone has anything further
> for me to try then please let me know!
>
> "A. Feiner" <> wrote in message
> news:vIpYe.2255$EH.571@trnddc01...
>> "SOFTWARE\Policies\Microsoft\WindowsFirewall\. ..
>> "Adam Butler" <> wrote in message
>> news:...
>>> One stupid question.
>>> Where is the "firewall key" located?
>>>
>>>>>> I have no clue what Windows OneCare package, but for start, I would
>>>>>> delete the firewall key from the said registry,and copy one from
>>>>>> another machine, then apply the policy again.
>>>>>>
>>>>>> --
>>>>>> Dana
>>>>>> http://www.woodcontour.com
>>>>>> Solid wood and stone PC Peripherals
>>>>>
>>>>>
>>>> "I'd bet it is in there somewhere but , where is the question!" I have
>>>> been saying that for years.
>>>> Did you try wiping out your key? Create it without inheritance from the
>>>> top?
>>>>
>>>> --
>>>> A. Feiner
>>>> http://www.woodcontour.com
>>>> Solid wood and stone PC Peripherals
>>>
>>>

>>
>>

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows cannot load the locally stored profile charlestek Windows Server 1 05-01-2007 10:04 AM
Error binding to local domain Steve Larson Windows Small Business Server 20 12-30-2005 06:29 AM
Group policy does not work Group Policy Does not work Windows Small Business Server 10 09-09-2005 09:19 AM
group policy question Marcia Windows Small Business Server 4 04-28-2005 05:05 PM
Password Policy .. Need Help Erica Windows Small Business Server 1 04-27-2004 06:29 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59