<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Apply_LGPO_Delta 1.0:  utility to apply custom changes to Local Policy</title><link>http://blogs.technet.com/b/fdcc/archive/2008/05/07/apply-lgpo-delta-1-0.aspx</link><description>Apply_LGPO_Delta 1.0, a utility to automate custom changes to Local Group Policy.</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Apply_LGPO_Delta updated, v1.01</title><link>http://blogs.technet.com/b/fdcc/archive/2008/05/07/apply-lgpo-delta-1-0.aspx#3215018</link><pubDate>Thu, 19 Mar 2009 08:27:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3215018</guid><dc:creator>Federal Desktop Core Configuration</dc:creator><description>&lt;p&gt;Apply_LGPO_Delta, a utility for automating the management of local group policy, is updated with a minor fix to prevent sharing-violation errors. The set of &amp;quot;starter&amp;quot; files is also updated.&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3215018" width="1" height="1"&gt;</description></item><item><title>re: Apply_LGPO_Delta 1.0:  utility to apply custom changes to Local Policy</title><link>http://blogs.technet.com/b/fdcc/archive/2008/05/07/apply-lgpo-delta-1-0.aspx#3200879</link><pubDate>Wed, 11 Feb 2009 19:32:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3200879</guid><dc:creator>rliepins</dc:creator><description>&lt;P&gt;Our Apply_LGPO_Delta application repeatedly produces the following error in the error log file:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Policy save failed; error code 0x80070020&lt;/P&gt;
&lt;P&gt;The log file itself ends with the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;----Un-initialize configuration engine...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;SECEDIT.EXE exited with exit code 3&lt;/P&gt;
&lt;P&gt;Any clues? &amp;nbsp;It sounds similar to the errors the old version of Set_FDCC_LGPO was receiving.&lt;/P&gt;
&lt;P&gt;Any help would be most appreciated.&lt;/P&gt;
&lt;DIV class=fdccReply&gt;
&lt;P&gt;&lt;EM&gt;[Aaron Margosis]&amp;nbsp; Apologies for the delay.&amp;nbsp; Apply_LGPO_Delta has now been updated with the same fix:&amp;nbsp; &lt;/EM&gt;&lt;A href="http://blogs.technet.com/fdcc/pages/LGPO-Utilities.aspx"&gt;&lt;EM&gt;http://blogs.technet.com/fdcc/pages/LGPO-Utilities.aspx&lt;/EM&gt;&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3200879" width="1" height="1"&gt;</description></item><item><title>re: Apply_LGPO_Delta 1.0:  utility to apply custom changes to Local Policy</title><link>http://blogs.technet.com/b/fdcc/archive/2008/05/07/apply-lgpo-delta-1-0.aspx#3121318</link><pubDate>Tue, 09 Sep 2008 07:18:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3121318</guid><dc:creator>rliepins</dc:creator><description>&lt;P&gt;Another option to this is that the command scripts we created also included a command line ntbackup line to back up the system state. &amp;nbsp;This could also be used to revert a system back to pre FDCC settings.&lt;/P&gt;
&lt;DIV class=fdccReply&gt;
&lt;P&gt;&lt;EM&gt;[Aaron Margosis]&amp;nbsp; So...&amp;nbsp; for Set_FDCC_LGPO there are two setting types that are applied:&amp;nbsp; &lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;security settings:&amp;nbsp; these can be edited using secpol.msc and are applied to the system by Set_FDCC_LGPO using secedit.exe; and&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;true policy settings:&amp;nbsp; these can be edited using gpedit.msc, and are applied to&amp;nbsp;the system by Set_FDCC_LGPO using policy APIs.&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;To revert the security settings, which generally don't have a "not configured" that you can roll back to, the best approximation to a rollback is to run secedit.exe before applying FDCC settings to get a snapshot of the current system; then use that later to restore settings.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;To revert the policy settings, simply set all the applied settings back to "not configured".&amp;nbsp; One way to do that is to run Set_FDCC_LGPO with the /log option, then take the /log output and change it into an input file for Apply_LGPO_Delta, where all the settings that are applied get deleted.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Note that this will only be an approximation of a rollback, not a 100% rollback, and that it doesn't touch file ACL or service configuration settings.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3121318" width="1" height="1"&gt;</description></item><item><title>re: Apply_LGPO_Delta 1.0:  utility to apply custom changes to Local Policy</title><link>http://blogs.technet.com/b/fdcc/archive/2008/05/07/apply-lgpo-delta-1-0.aspx#3121317</link><pubDate>Tue, 09 Sep 2008 07:16:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3121317</guid><dc:creator>rliepins</dc:creator><description>&lt;p&gt;I have been working extensively in the virtual environment for testing. &amp;nbsp;It has been the best thing for this.&lt;/p&gt;
&lt;p&gt;As for what has been created, the scripts I created were to automate the implementation of FDCC with our line office &amp;quot;exceptions&amp;quot; which are temporary at best, anyway. &amp;nbsp;THe scripts to remove all the settings were worked on for those field systems that don't have any local IT support and give the end user a troubleshooting technique to revert their system back to default settings.&lt;/p&gt;
&lt;p&gt;As I don't have enough expertise to take a snapshot of all settings, put them in a template file and revert to those settings, I did the research necessary to try to revert to as close as possible to XP default settings. &amp;nbsp;It was a long process.&lt;/p&gt;
&lt;p&gt;But these may be of use to people - to get a good understanding of what is happening under the hood. &amp;nbsp;I'd still be willing to let everyone see what I set up. &amp;nbsp;Plus it would help to get feedback. &amp;nbsp;I just can't do it on a personal blog. &amp;nbsp;I am sure there are some sort of federal ethics rules I would be bending.&lt;/p&gt;
&lt;p&gt;How about setting up new blog entries to go over specific settings for the registry based template files and security templates. &amp;nbsp;We could discuss various aspects of what settings could be reverted to, etc.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3121317" width="1" height="1"&gt;</description></item><item><title>re: Apply_LGPO_Delta 1.0:  utility to apply custom changes to Local Policy</title><link>http://blogs.technet.com/b/fdcc/archive/2008/05/07/apply-lgpo-delta-1-0.aspx#3121285</link><pubDate>Tue, 09 Sep 2008 05:31:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3121285</guid><dc:creator>tardboy21</dc:creator><description>&lt;P&gt;That is not the purpose, nor target market of the document proposed. It is simply for testing purposes. Also, no two applications are exactly the same. Looking at work someone else has done can help if a problem arises in the future with the FDCC (as many have already), and allow a quicker solution than having to wipe a system and re-image. &lt;/P&gt;
&lt;P&gt;While most tools on this website are offered on the "AS-IS" basis, it had become my impression the objective of the forum was to offer better "understanding" through a variety of ways. Applying a different INF file and comparing would certainly help me as well as at least one other (Singood).&lt;/P&gt;
&lt;DIV class=fdccReply&gt;
&lt;P&gt;&lt;EM&gt;[Aaron Margosis]&amp;nbsp; As I understood it, the request was for help composing scripts/templates to "undo" application of FDCC settings.&amp;nbsp; In my work I strive for results that are accurate and complete, and in this case that is difficult to achieve at best.&amp;nbsp; As I mentioned, IMHO there are better options.&amp;nbsp; Using virtual machines with "undo disks" is actually faster than running "undo" scripts and gives you much cleaner results.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3121285" width="1" height="1"&gt;</description></item><item><title>re: Apply_LGPO_Delta 1.0:  utility to apply custom changes to Local Policy</title><link>http://blogs.technet.com/b/fdcc/archive/2008/05/07/apply-lgpo-delta-1-0.aspx#3121277</link><pubDate>Tue, 09 Sep 2008 05:05:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3121277</guid><dc:creator>Aaron Margosis</dc:creator><description>&lt;DIV class=fdccReply&gt;
&lt;P&gt;[Aaron Margosis] My apologies for delayed response. &amp;nbsp;At this point we haven't opted to post anything that claims to revert FDCC settings to defaults, because it is difficult to assure that you are getting 100% reversion to pre-application state. &amp;nbsp;This is especially true with the file ACL edits that FDCC applies on XP systems, as well as with security options.&lt;/P&gt;
&lt;P&gt;The way I personally prefer to work for all my development and testing purposes is to use virtual machine technology (such as &lt;A class="" href="http://www.microsoft.com/windows/products/winfamily/virtualpc/default.mspx" target=_blank&gt;Virtual PC&lt;/A&gt;, &lt;A class="" href="http://www.microsoft.com/windowsserversystem/virtualserver/" target=_blank&gt;Virtual Server&lt;/A&gt;, or &lt;A class="" href="http://www.microsoft.com/windowsserver2008/en/us/hyperv.aspx" target=_blank&gt;Hyper-V&lt;/A&gt;) with "undo disks". &amp;nbsp;This gives me guaranteed 100% reversion with no side effects from previous testing. &amp;nbsp;On physical (non-virtual) systems, I prefer just wiping/loading from a well-defined repeatable deployment image.&lt;/P&gt;
&lt;P&gt;For production systems, I don't understand why you would ever want to &lt;EM&gt;completely&lt;/EM&gt; revert to defaults after applying FDCC settings.&lt;/P&gt;&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3121277" width="1" height="1"&gt;</description></item><item><title>re: Apply_LGPO_Delta 1.0:  utility to apply custom changes to Local Policy</title><link>http://blogs.technet.com/b/fdcc/archive/2008/05/07/apply-lgpo-delta-1-0.aspx#3121257</link><pubDate>Tue, 09 Sep 2008 04:11:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3121257</guid><dc:creator>tardboy21</dc:creator><description>&lt;p&gt;if you would like rliepins, attach the documents and send them to my public profile email, and I can upload them to some web space for you an post a link. Just be sure you give me permission to distribute them in the email, and I will post the link here.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3121257" width="1" height="1"&gt;</description></item><item><title>re: Apply_LGPO_Delta 1.0:  utility to apply custom changes to Local Policy</title><link>http://blogs.technet.com/b/fdcc/archive/2008/05/07/apply-lgpo-delta-1-0.aspx#3121001</link><pubDate>Mon, 08 Sep 2008 17:34:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3121001</guid><dc:creator>rliepins</dc:creator><description>&lt;p&gt;I tried contacting him regarding attaching the templates, but have heard no response back.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3121001" width="1" height="1"&gt;</description></item><item><title>re: Apply_LGPO_Delta 1.0:  utility to apply custom changes to Local Policy</title><link>http://blogs.technet.com/b/fdcc/archive/2008/05/07/apply-lgpo-delta-1-0.aspx#3120002</link><pubDate>Sat, 06 Sep 2008 00:13:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3120002</guid><dc:creator>Singood</dc:creator><description>&lt;p&gt;Attachments might be an option - although I don't readily see how to do so...maybe A. Margosis might chime in and assist with providing all of us the ability to check out the rollback templates that rliepins developed? &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3120002" width="1" height="1"&gt;</description></item><item><title>re: Apply_LGPO_Delta 1.0:  utility to apply custom changes to Local Policy</title><link>http://blogs.technet.com/b/fdcc/archive/2008/05/07/apply-lgpo-delta-1-0.aspx#3119964</link><pubDate>Fri, 05 Sep 2008 21:04:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3119964</guid><dc:creator>tardboy21</dc:creator><description>&lt;p&gt;You could post it on another URL and then post the link here. I would be very interested in taking a look at and testing the files a little myself. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3119964" width="1" height="1"&gt;</description></item></channel></rss>