Security.msc - Dumbest mistake EVER!

  • Thread starter Thread starter Dan \(Blushing\)
  • Start date Start date
D

Dan \(Blushing\)

Condensed version:
Set up group policy so that only three programs would run
on a computer.
Disabled control panel
Can't get anything besides the aforementioned three
programs to run (cannot even open an mmc or an .msc file
to make changes to the system.
---------------------------------

Excuse filled version:
Ok, before I start, I want to say I already feel as stupid
as can be, and I accept that abuse is warranted.

Running Win2k Sp 3

While setting up a computer for a high risk/high security
environment, I got a little carried away. While in an mmc,
I set the security so that only three programs would be
allowed to run. I also disabled the control panel and cmd
prompt. You probably see this coming. After I saved, just
as I closed the mmc, it dawned on me that in telling it to
only allow three programs, I would no longer be able to
open my "Security.msc"

Stuff I've tried:
Accessing the computer via another computer on the
network. I get an RPC error.
Under the "Just for the hell of it""
Tried accessing anything in Safe mode - no go
Tried logging in locally (as well as domain)
Begging the computer to loosen up

All to no avail


Have I totally hosed this system? I mean, it works, but if
left to my own devices, I'll never be able to make any
changes. A complete reinstall would be more embarrassing
than catastrophic.
TIA,
Dan

PS If some kind soul would like to email the answer to me
I promise to post any words of wisdom to the group (foul
language and name calling excluded).
 
Is this a local GPO? If so, create a new OU, set the OU's
gpo to the opposite of everything done locally, move a
user into the OU with the new/reverse GPO and login to the
domain. Make sure the user has admin rights locally. Then
you should be able to open the mmc and change the local
gpo back.

If it is a domain gpo, set the security on the gpo to deny
access to the domain admins group. Then it will only apply
to users.
 
Back
Top