Can you let me know how to reverse a group policy on a domain controller that prevents me from adding new Windows components? I've attempted to apply a local security policy to reverse the settings, but this hasn't had any effect.
We've just put in new Citrix servers and I applied a policy to lock down the user environment, but messed up and am pretty sure I allowed the policy to be applied to all users without excluding domain admins. Any assistance would be greatly appreciated. Thanks in advance.
You'll need to write an opposite
to revoke the changes made by your first GPO. Delete the erroneous GPO, then apply the anti-GPO. Then start over. Since GPOs are applied in Local - site - domain - OU order, just changing the local GPO does not eliminate the changes made by a poor GPO.