Edit security settings on a Group Policy object
To edit a security setting on a Group Policy object
Choose the appropriate environment for which you want to edit a security setting:
For your local computer
-
Open Local Security Settings.
-
In the console tree, click Security Settings.
-
Do one of the following:
-
To edit Password Policy or Account Lockout Policy, click Account Policies.
-
To edit an Audit Policy, a User Right Assignment, or Security Options, click Local Policies.
-
Double-click the security setting in the details pane that you want to modify.
-
Modify the security setting, and then click OK.
Notes
-
To perform this procedure, you must be a member of the Administrators
group on the local computer, or you must have been delegated the
appropriate authority. If the computer is joined to a domain, members of
the Domain Admins group might be able to perform this procedure. As a
security best practice, consider using Run as to perform this procedure.
-
To open Local Security Policy, click Start, point to Settings, click Control Panel, double-click Administrative Tools, and then double-click Local Security Policy.
For a Group Policy object, when you are on a workstation or server that is joined to a domain.
-
On the taskbar, click Start, point to Run, type mmc, and then click OK.
-
In the console, on the File menu, click Add/Remove snap-in.
-
In Add/Remove Snap-in, click Add, and then, in Add Standalone Snap-in, double-click Group Policy Object Editor.
-
In Select Group Policy Object, click Browse, browse to the policy object you would like to modify, and then click Finish.
-
Click Close, and then click OK.
-
In the console tree, click Security Settings.
Where?
-
GroupPolicyObject [ComputerName] Policy\Computer Configuration\Windows Settings\Security Settings
-
Do one of the following:
-
To edit Password Policy, Account Lockout Policy, or Kerberos Policy, in the details pane, double-click Account Policies.
-
To edit Audit Policy, User Rights Assignment, or Security Options, in the details pane, double-click Local Policies.
-
To edit event log settings, on the console tree, click Event Log.
-
In the details pane, double-click the security setting that you want to modify.
-
(Optional) If this security setting has not yet been defined, select the Define these policy settings check box.
-
Modify the security setting and then click OK.
Note
-
To perform this procedure, you must be a member of the Domain Admins
group or the Enterprise Admins group in Active Directory, or you must
have been delegated the appropriate authority. As a security best
practice, consider using Run as to perform this procedure. For more
information, see Default local groups, Default groups, and Using Run as.
For a Group Policy object, when you are
on a domain controller or on a workstation that has the Windows
Server 2003Administration Tools Pack installed.
-
Open Active Directory Users and Computers.
-
In the console tree, right-click the Group Policy object for which you want to edit security settings.
-
Click Properties, and then click the Group Policy tab.
-
Do one of the following:
-
To edit an existing Group Policy object, click Edit.
-
To create a new Group Policy object, click New, and then click Edit.
-
In the console tree, click Security Settings.
Where?
-
GroupPolicyObject [ComputerName] Policy\Computer Configuration\Windows Settings\Security Settings
-
Do one of the following:
-
To edit Password Policy, Account Lockout Policy, or Kerberos Policy, click Account Policies.
-
To edit Audit Policy, User Rights Assignment, or Security Options, click Local Policies.
-
To edit Event log settings, click Event Log.
-
Double-click the security setting in the details pane that you want to modify.
-
(Optional) If this security setting has not yet been defined, select the Define these policy settings check box.
-
Modify the security setting and then click OK.
Notes
-
To perform this procedure, you must be a member of the Domain Admins
group or the Enterprise Admins group in Active Directory, or you must
have been delegated the appropriate authority. As a security best
practice, consider using Run as to perform this procedure. For more
information, see Default local groups, Default groups, and Using Run as.
-
To open Active Directory Users and Computers, click Start, click Control Panel, double-click Administrative Tools, and then double-click Active Directory Users and Computers.
For only domain controllers, when you are on a domain controller.
-
Open Domain Controller Security Policy.
-
In the console tree, click Security Settings.
Where?
-
GroupPolicyObject [ComputerName] Policy\Computer Configuration\Windows Settings\Security Settings
-
Do one of the following:
-
To edit Password Policy, Account Lockout Policy, or Kerberos Policy, in the console tree, double-click Account Policies.
-
To edit Audit Policy, User Rights Assignment, or Security Options, in the console tree, click Local Policies.
-
To edit event log settings, in the console tree, click Event Log.
-
In the details pane, double-click the security setting that you want to modify.
-
(Optional) If this security setting has not yet been defined, select the Define these policy settings check box.
-
Modify the security setting, and then click OK.
Notes
-
To perform this procedure, you must be a member of the Domain Admins
group or the Enterprise Admins group in Active Directory, or you must
have been delegated the appropriate authority. As a security best
practice, consider using Run as to perform this procedure. For more
information, see Default local groups, Default groups, and Using Run as.
-
To open Domain Controller Security Policy, click Start, click Control Panel, double-click Administrative Tools, and then double-click Domain Controller Security Policy.
Notes
-
Always test a newly-created policy on a test organizational unit before applying it to your network.
-
When you change a security setting and click OK, that setting will take effect in the next refresh of settings.
-
The security settings are refreshed every 90 minutes on a workstation or
server and every 5 minutes on a domain controller. The settings are
also refreshed every 16 hours, whether or not there are any changes.
No comments:
Post a Comment