Subscribe to Windows IT Pro
March 12, 2009 12:00 AM

Q: Can I restore the Default Domain Policy and Default Domain Controllers Policy to their default states without a backup?

Windows IT Pro
InstantDoc ID #101496
Rating: (1)

A: Microsoft provides the Dcgpofix (dcgpofix.exe) utility in Windows Server 2008 and Windows Server 2003 that let you reset the default domain and default domain controllers policies to their original states. You must be logged in as a domain or enterprise administrator to run the tool.

Click to expand

When you run the tool, you'll lose all changes you made to the Default Domain Policy and Default Domain Controllers Policy after you brought the first DC in your domain online. Be aware that the tool doesn't return the security settings in the Default Domain Controllers Policy to their original states. As such, Microsoft advises you manually check the security settings in the Default Domain Controllers Policy after you run the tool. See this Microsoft article for more details.

As a general best practice, you should always have a backup of the Default Domain Policy and Default Domain Controllers Policy and use Dcgpofix only as a last resort. You can easily backup and restore Group Policy Objects from Group Policy Management Console (GPMC), as shown here for a backup of the Default Domain Controllers Policy.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.