Unable to save changes to Group Policy

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I have posted in several groups already, no responses. Trying again! See
previous posts below.

Since I posted the last time, I have done a "repair" install of Server 2k3
complete with all updates etc. Recreated the domain, same issue.

On a second server, i created a new/different domain, same issue.
I have repeatedly tried resetting permissions/ownership/etc, no effect on
the problem

I am certain this issue is related to the Symantec AV V10.0.2 as I have
another new out of the box unit with R2 which has never had SAV installed, no
issues there.

I am sure this is an early detection of a problem that will be plaguing R2
users as I see it posted through out the newsgroups and have yet to see a
resolution. So any suggestions/fixes would be greatly appreciated. I am on my
way to formatting and reinstalling on three brand new servers as a result.
While I have that luxery in the lab I am sure there are many in a production
environment who dont.
ORIGINAL POSTS:
I have seen numerous posts regarding this issue, no real answers.
My scenero: Three new Windows 2003 Servers Standard Edition R2. Lab
environment, everything fresh. the only setups done are basic domain and
active directory and entering users. Symantec Antivirus Corporate 10.0
installed but disabled. One server is PDC, others are BDC and connected by
VPN (again, lab environment with VPN up and running.) All seems to work well.
Settings replicate properly, licenses replicate properly. No real issues
other than when trying to set GPO, the following error occurs: "group policy
snapin was unable to save your changes due to the following error: the
process cannot access the file because it is being used by another process".
I have read post after post and tried all the suggestions given (which were
few) but none has helped. I thought perhaps replication between the servers
was the issue, but shutting down the BDCs does not effect the situation. If i
go to
D:\WINDOWS\SYSVOL\sysvol\mydomain.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows
NT\SecEdit\GptTmpl.inf and edit the file manually, it still does not let me
save returning an error saying it cannot create the file followed by the full
path. I have reset permissions, ownership, all to no avail. Any responses
greatly appreciated!

UPDATE: I spoke with Symantec support today, found v10.0.2 of SAV Corp. is
not compatible and is problematic when used with Windows server 2003 R2. I
removed SAV from all three servers, removed the domain controller roll from
all three and recreated the domain on the primary server. I still have the
above error when trying to change GPO. In removing the rolls, it seems there
are numerous problems created by installing the SAV V10.0.2 BEWARE!! At this
point it looks as if I will have to start from scratch, format and
reninstall. Any suggestions guys?? I really do not want to go through the
process of reloading 3 servers!
THANKS~~!!
 
Clearly some process has a handle on the files in the GPT (SYSVOL portion of
the GPO) that are preventing that GPO from being saved. Here's what I'd do.
Download the process explorer utility from www.sysinternals.com and fire it
up on the PDC emulator (default server where GP changes are made). Do a
search for handles within the tool for any file in the path of that gpo
(path would be \\<domainname>\sysvol\<domainname>\policies\<GUID of GPO>\.
When you find the handle, it should tell you what process has that file open
and what kind of open it is. That should narrow down the problem. In
general, the rule for AV products running on DC is to make sure you exclude
all files within SYSVOL\policies from being scanned.

--
Darren Mar-Elia
MS-MVP-Windows Server--Group Policy
Check out http://www.gpoguy.com -- The Windows Group Policy Information Hub:
FAQs, Whitepapers and Utilities for all things Group Policy-related
And, the Windows Group Policy Guide is out from Microsoft Press!!! Check it
out at http://www.microsoft.com/mspress/books/8763.asp
GPOGUY Blog: http://blogs.dirteam.com/blogs/gpoguy
 
Thanks for the response Darren. I downloaded the tool, did a search on
D:\WINDOWS\SYSVOL\sysvol\mydomain.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\WindowsBottom line is if you are using R2, do not install SAV v10.0.2!!
 
Back
Top