Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

March 04, 2004 12:00 AM

How can I restore the contents of the Default Domain and Default Domain Controller (DC) Group Policy Objects (GPOs)?

Windows IT Pro
InstantDoc ID #41878
Rating: (13)

A. Best practice stipulates that you shouldn't modify the Default Domain and Default DC GPOs. Instead, you should create new GPOs and link them to the relevant containers. However, if you've already modified the GPO and want to restore the default content, perform the following steps:

  1. Log on as a domain administrator to a DC.
  2. Start a command session.
  3. To reset the Domain GPO, type
    dcgpofix /target:Domain
    To reset the Default DC GPO, type
    dcgpofix /target:DC
    To reset both the Domain and Default DC GPOs, type
    dcgpofix /target:both
  4. After you enter the appropriate command in Step 3, enter Y to both prompts.
  5. Close the command window.

For example, when I type

dcgpofix /target:both

my computer returns the following output:

  Microsoft(R) Windows(R) Operating System Default Group Policy Restore
  Utility v5.1

  Copyright (C) Microsoft Corporation. 1981-2003

  Description: Recreates the Default Group Policy Objects (GPOs) for a
  domain

  Syntax: DcGPOFix [/ignoreschema] [/Target: Domain | DC | BOTH]

  This utility can restore either or both the Default Domain policy or
  the Default Domain Controller policy to the state that exists
  immediately after a clean install. You must be a domain administrator
  to perform this operation.

  WARNING: YOU WILL LOSE ANY CHANGES YOU HAVE MADE TO THESE GPOs. THIS
  UTILITY IS INTENDED ONLY FOR DISASTER RECOVERY PURPOSES.

  You are about to restore Default Domain policy and Default Domain
  Controller policy for the following domain
  
  savilltech.com
  
  Do you want to continue: ? Y

  WARNING: This operation will replace all 'User Rights Assignments'
  made in the chosen GPOs. This may render some server applications to
  fail. 

  Do you want to continue: ? Y

  The Default Domain Policy was restored successfully.

  Note: Only the contents of the Default Domain policy was restored.
  Group Policy links to this Group Policy Object were not altered.
  By default, the Default Domain policy is linked to the Domain.

  The Default Domain Controller policy was restored successfully.

  Note: Only the contents of the Default Domain Controller policy was
  restored. Group Policy links to this Group Policy Object were not
  altered.

  By default, the Default Domain Controller policy is linked to the
  Domain Controllers OU.

Related Content:

ARTICLE TOOLS

Comments
  • eslamfarouk
    2 months ago
    Dec 01, 2011

    dear john
    i send you my best regards for your topic.
    my best regars;

    islam salem

  • Anonymous User
    7 years ago
    Aug 24, 2005

    It is very imformative.

  • lazyadm1n
    7 years ago
    Jan 19, 2005

    http://support.microsoft.com/?kbid=226243

    See this KB Article for 2000

  • Kostya
    8 years ago
    Mar 17, 2004

    How can I restore the contents of the Default Domain and Default Domain Controller (DC) Group Policy Objects (GPOs)? in windows 2000 server

  • Erwin Mendoza
    8 years ago
    Mar 16, 2004

    Good day!

    It is very imformative.

    How about for windows 2000 default controller policy? Is there a way to restore the content?

    More power.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.