If the group doesn't have permissions to modify the GPOs, you can grant it
edit permissions. You can either do this on a per-GPO basis, by modifying
the DACL of the GPO in question, or you can modify the permissions on
CN=Policies, CN=System, DC=domain-name, DC=com. The former can be
accomplished using GPMC, DSA.MSC, ADSIEdit.msc, etc. The latter DSA.MSC or
ADSIEdit.msc (or any command line tool, LDP or script for both of course).
--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net |
http://forums.msresource.net