Remove legacy/redundant GPO settings

Hi folks!
Is there any way to automatically remove legacy or redundant settings from a GPO.
For example (specifically in fact) remove the IE settings, that up until IE8 were rolled out via Policies > Windows Settings > IE Maintenance. I have other settings as well, Admin Templates for Outlook 2002 that are showing and I want them gone too.
I'm just doing basic housekeeping, and the OCD in me doesn't want two places where the settings show in the GPO settings tab in the GPMC. I am also just trying to make it easier for the IT dept to be able to manage on their own, if I am out of the office
for any reason.
Apologies if this is an easy one, but I can't find anywhere that actually allows me to remove settings from a GPO following a domain upgrade (2003 to 2012), only to remove entire GPOs.
Cheers!
Andy

Hi Andy,
>>For example (specifically in fact) remove the IE settings, that up until IE8 were rolled out via Policies > Windows Settings > IE Maintenance.
Regarding this point, the following KB article can be referred to as reference.
Policy reporting tools indicate empty Internet Explorer Maintenance policy as winning
http://support.microsoft.com/kb/2722241/en-us
>> I have other settings as well, Admin Templates for Outlook 2002 that are showing and I want them gone too.
To remove these settings, you can import the administrative template files for Outlook 2002 in GPMC, and un-configure the previous configured settings.
To obtain the policy template files for Outlook 2002, you can use the version of the resource kit from the Office XP or Outlook 2002 enterprise CD-ROM, or you can download Office XP orktools.exe from the following location.
Office XP Resource Kit
http://www.microsoft.com/office/orkarchive/XPddl.htm
Regarding how to add administrative template, the following article can be referred to for more information.
Add or remove an Administrative Template (.adm file)
http://technet.microsoft.com/en-in/library/cc739134(v=ws.10).aspx
TechNet Subscriber Support
If you are TechNet Subscription user and have any feedback on our support quality, please send your feedback here.
Best regards,
Frank Shen

Similar Messages

  • What should happen after removing restricted group GPO settings

    I created and applied restricted group settings in GPO 
    Computer Configuration -> Policies -> Windows Settgins -> Secuirty settings -> Restricted Groups
    which is linked to all production servers OU. I set up members of local administrators group to include only domain admins. This lead to removing all another accounts from local administrators group on all server. I was quite scared about this, I realize my
    mistake. So I remove this restricted groups settings from this GPO. Then on all servers previous configuration came back, all previously configured accounts are back in local administrator group. Is it normal behavior? I thought that these previously configured
    accounts will not back automatically

    This is the expected behavior since Windows XP/Windows Server 2003.
    Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

  • Unable to remove the redundant group header from the bottom of page

    Hi,
    In one of my projects in I am facing a problem.
    I need to display the details of all available products of the company. While displaying the details, I need to group the products based on some criteria (like type of product, release date) and the grouping is upto 4 level grouping. Grouping criteria can se said as, I need to firstly group all the products based on the type, then on the Release Date and then on two of the client specific values on the Product.
    Along with this, the view of product details is a thumbnail view (Image on top with all details below that line after line) due to which I need to display multiple (5) products in one row.
    The problem which I am facing is:
    The most important criterion for the customer is that there should not be any wastage of space.
    Secondly, they also donu2019t want to see partial data like only the header data in one page and the Product related Data (Image and Info) on the next page.
    In my case, when first page has insufficient space for the next grouped products, it simply displays the group header on the first page. On the second page, it again displays the group header along with the data.
    For reference, images are available at:
    Image1: http://farm4.static.flickr.com/3454/3224626688_aa3cfb8236_m.jpg
    Image2: http://farm4.static.flickr.com/3373/3224626782_0501cf566f_m.jpg
    My requirement is to remove the redundant group header from the first page as it does not make sense without having any data below it.
    I have tried the following options:
    1. I tried to apply setting "Keep Group Together" on the group and "Repeat Group Header On Each Page". But when I apply this, when my second group has more than 5 products (two rows of data) and space on first page can accommodate only 1 row of data, it moves the data on to the second page instead of keeping the 1st row on first page and 2nd on second page. This solution is not acceptable to the customer as it wastes space.
    2. If I remove setting "Keep Group Together" on all the groups, but keep the "Repeat Group Header On Each Page" and remove the "Keep Object Together" in the details section, I can save space. But this is not acceptable to the user as it leaves dangling headers (Orphaned Header Information).
    Need some pointers to overcome this issue as it is very critical for me.
    Thanks in advance,
    Vibhav Agrawal

    Thanks Raghavendra for your reply.
    These solutions provided on the link are not useful for me because of the peculiar layout of my report.
    In my report I am supposed to show details of multiple items (upto 5/6) in a single row.
    All solutions suggest about adding additional header (below group header) and use the formula to use that header to put the data for initial first object and details section for the subsequent objects.
    But, since i need to display multiple items in same row...and data cannot be set as 'format with multiple columns' in the header, hence this solution does not work for me
    Thanks,
    Vibhav Agrawal

  • How do I remove the Notification under settings after updating IOS 8.1 ?

    How do I remove the Notification under settings as I have the latest IOS 8.1 on an ipad mini retina display?

    System requirements for Continuity on iPhone, iPad, iPod touch, and Mac - Apple Support

  • Within Pro 9, how do I remove/delete default security settings?

    All,
    As a learning excercise, I recently password protected a document so that PRINT was disabled. However everytime I render a PDF, this security policy is applied by default requiring me to go the Security tab under Properties and select "No Security."
    How can I permanently deleted this policy so that it is no long applied to newly rendered PDFs by default?
    Thanks in advance!
    David

    I'm OK with how to remove the security settings from a document:  Documents > Properties (security tab; "No Security").
    What I'm looking for is the path to removing the security settings such that they are NOT applied when I convert a document to PDF. What is happening now is that when I convert a MS Word doc to PDF, the security settings are applied by default, which means I have to go the process, albeit a short one, of removing the security settings from the document - as referenced above.
    So again, if I simply launch Acorbat Pro 9 (without opening of a document), what is the correct path to removing (permenently) the security settings so that they are no longer applied to a converted document by default?
    Thanks in advance.

  • Internet Options greyed out in Internet Explorer 9 because of GPO settings in Windows 2008 AD

    Internet Options greyed out in Internet Explorer 9 because of GPO settings in Windows 2008 AD.
    I am trying to find out what GPO setting is causing this so I can change I.E. settings at a desktop running Windows 7.
    A GPO has I.E. locked down so settings are greyed out for Intranet settings so I can't change Intranet settings.
    How do I enable so I can save changes with a GPO?

    Classic GPO using Administrative Templates, is designed to do exactly that (disable the UI).
    Previously, you could use IEM in preference mode.
    Now, you'll need to use GPP, but there are a couple of limitations.
    Check the IE10 IEAK documentation (it's useful for understanding what you can do with GPP)
    http://technet.microsoft.com/en-us/library/jj890998.aspx
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • GPO settings are not applied

    Hi everyone
    I am using WSUS in my internal network.
    When i am trying to deploy GPO, The GPO seems to be applying on the computer but the 
    GPO settings are not being applied.
    I am getting error An error occured while checking for updates for your computer
    and in Windows update change settings, i can see it is grayed out with the option
    Download updates but let me choose wheter to install them(some settings are managed by your system administrator)
    I have disabled windows firewall when i was using Windows XP computers, Is any settings of windows firewall creating issues?
    I have created a computer group in WSUS say TESTGroup
    In GPO I have assigned the following settings(Please correct me if i am going wrong with the settings)
    Configure Automatic updates : 3-Auto download and notify for install
    Specify Intranet microsoft update service location: http://mywsus (here should it be mywsus or mywsus:8530)
    Enable Client Side targeting : TestGroup ( I have OU in active directory with Computers)
    Do not display install updates and shutdown option : Enabled
    Automatic Updates detection frequency : 2 hours
    Allow Non administrators to receive update notification : Enabled
    Allow Automatic updates immedidate installation : Enabled
    Turn of recommended updates via automatic updates : Enabled
    Reschedule automatic udpates scheduled installation : 10 min
    I have approved few updats in WSUS console to install on TestGroup
    On Client Computer ihave used the command 
    wuauclt /detectnow and wuauclt /reportnow
    Please guide me

    I have installed the updates KB2720211 KB2530678 KB2530709 KB2734608 on WSUS Server
    My GPO settings are 
    Configure Automatic updates : 3-Auto download and notify for install
    Allow signed updates from an intranet microsoft update service location : Enabled(i am using internal WSUS server exporting updates from internet connected WSUS to internal WSUS)
    GPO is applying but settings are not being applied.
    please do refer the client logs & attachment.
    Triggering AU detection through DetectNow API
    START ##  AU: Search for updates
    <<## SUBMITTED ## AU: Search for updates [CallId = {A52428A8-E7EC-4CAB-9842-0B66F6969382}]
    ** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    Agent *********
    * Online = Yes; Ignore download priority = No
    * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    Agent   * Search Scope = {Machine}
    Setup Checking for agent SelfUpdate
    Setup Client version: Core: 7.6.7600.320  Aux: 7.6.7600.320
    Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab with dwProvFlags 0x00000080:
    Microsoft signed: NA
    Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\TMP8FF3.tmp with dwProvFlags 0x00000080:
    Triggering AU detection through DetectNow API
    Piggybacking on an AU detection already in progress
    Microsoft signed: NA
    Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab with dwProvFlags 0x00000080:
    Microsoft signed: NA
    Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab with dwProvFlags 0x00000080:
    Microsoft signed: NA
    Setup Determining whether a new setup handler needs to be downloaded
    Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\Handler\WuSetupV.exe with dwProvFlags 0x00000080:
    Microsoft signed: NA
    Setup SelfUpdate handler update NOT required: Current version: 7.6.7600.320, required version: 7.6.7600.320
    Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.6.7600.320"
    Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.6.7600.320" is already installed.
    Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.320"
    Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.320" is already installed.
    Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~x86~~7.6.7600.320"
    Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~x86~~7.6.7600.320" is already installed.
    SelfUpdate check completed.  SelfUpdate is NOT required.
    +++++++++++  PT: Synchronizing server updates  +++++++++++
    + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://MYWSUSServer/ClientWebService/client.asmx
    WARNING: GetConfig failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404
    WARNING: PTError: 0x80244019
    WARNING: GetConfig_WithRecovery failed: 0x80244019
    WARNING: RefreshConfig failed: 0x80244019
    WARNING: RefreshPTState failed: 0x80244019
    WARNING: Sync of Updates: 0x80244019
    WARNING: SyncServerUpdatesInternal failed: 0x80244019
     * WARNING: Failed to synchronize, error = 0x80244019
    * WARNING: Exit code = 0x80244019
    **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    Agent *************
    WARNING: WU client failed Searching for update with error 0x80244019
    >>##  RESUMED  ## AU: Search for updates [CallId = {A52428A8-E7EC-4CAB-9842-0B66F6969382}]
    # WARNING: Search callback failed, result = 0x80244019
    # WARNING: Failed to find updates with error code 80244019
    ##  END  ##  AU: Search for updates [CallId = {A52428A8-E7EC-4CAB-9842-0B66F6969382}]
    Need to show Unable to Detect notification
    Successfully wrote event for AU health state:1
    AU setting next detection timeout to 2015-03-20 20:18:22
    Successfully wrote event for AU health state:1
    Successfully wrote event for AU health state:1
    Report REPORT EVENT: {5BCEA64A-0FEB-4B01-9509-CE94AFE0D04A}
    2015-03-20 21:19:59:003+0300 1
    148 101
    {00000000-0000-AutomaticUpdates Failure
    Software Synchronization Windows Update Client failed to detect with error 0x80244019.
    CWERReporter::HandleEvents - WER report upload completed with status 0x8
    WER Report sent: 7.6.7600.320 0x80244019 00000000-0000-0000-0000-000000000000 Scan 101 Managed
    Report CWERReporter finishing event handling. (00000000)
    WARNING: GetConfig failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404
    WARNING: PTError: 0x80244019
    WARNING: GetConfig_WithRecovery failed: 0x80244019
    WARNING: RefreshConfig failed: 0x80244019
    WARNING: RefreshPTState failed: 0x80244019
    WARNING: PTError: 0x80244019
    WARNING: Reporter failed to upload events with hr = 80244019.
    WARNING: GetConfig failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404
    WARNING: PTError: 0x80244019
    WARNING: GetConfig_WithRecovery failed: 0x80244019
    WARNING: RefreshConfig failed: 0x80244019
    WARNING: RefreshPTState failed: 0x80244019
    WARNING: PTError: 0x80244019
    WARNING: Reporter failed to upload events with hr = 80244019.

  • How to remove the redundant input English (United States) in the Language Control Panel on Windows 8?

    I have English (Australia) and English (United States) in the same order installed in the Language panel.
    I try to remove the redundant English (United States).  I click Options to open it.  I found the option Remove for the Input method is dimmed out and disabled.

    Hi,
    To uninstall language package try following steps:
    Type lpksetup.exe in search charm.
    Press enter to open Install and uninstall display languages wizard.
    Try to uninstall it.
    If there is any error happened, post back here.  
    Kate Li
    TechNet Community Support

  • How to remove legacy exchange servers. exchange 2013

    hello I recently tried to create a DAG and it failed so i decided to remove the DAG and also the new server i created for it. 
    however now on my main production exchange server i still have legacy things left over from the server i deleted.
    for instance Get-ExchangeServer command will bring up my current server and the old ones as well.
    what i want to know is how do i clear our out all traces of the older servers?
    many thanks

    Here's a good article to refer to remove Exchange 2013:
    http://blog.dargel.at/2012/11/20/complete-remove-exchange-2013-using-adsiedit/
    for 2007 and 2010:
    http://thlnk3r.wordpress.com/2013/04/17/how-to-remove-legacy-exchange-servers-using-adsiedit-tool/
    Thanks, MikeV MCSE 2012

  • Removing the initial Import Settings Dialog

    i want Removing the initial Import Settings Dialog for all users and any new profils

    See https://bugzilla.mozilla.org/show_bug.cgi?id=286557#c38 (comments 38 and 39)

  • Programatic access to GPO settings

    I would like to programmatically read/write several GPO settings (ideally in c#). This include few rules related to Firewall, enabling Remote Desktop/Remote assistance. What could be best way of accomplishing it?

    > I would like to programmatically read/write several GPO settings
    > (ideally in c#). This include few rules related to Firewall, enabling
    > Remote Desktop/Remote assistance. What could be best way of
    > accomplishing it?
    Have a look at
    http://technet.microsoft.com/library/ee461034.aspx
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • Need GPO settings for firefox to have similar settings as IE

    ''locking this thread as duplicate, please continue at [https://support.mozilla.org/en-US/questions/1042786 /questions/1042786]''
    The firefox gpo adm files are not pushing the gpo settings to firefox, please help

    hello,
    searching on the internet I found the name of the APN : orangenet.com.do
    I don't know if they require credentials.
    The search box on top-right of this page is your true friend, and the public Knowledge Base too:

  • Can't get display settings / destop tab back after removing it with GPO

    I'm running ZEN32SP3. I'm just getting started with GPO in WinXP. I
    inadvertently removed the desktop tab in the display settings and can't seem
    to get it back. Can anyone help me out?
    Thanks,
    brad

    Thanks.
    "Rolf Lidvall" <[email protected]> wrote in message
    news:AIVEc.1848$[email protected]..
    > > I'm running ZEN32SP3. I'm just getting started with GPO in WinXP. I
    > > inadvertently removed the desktop tab in the display settings and can't
    > seem
    > > to get it back. Can anyone help me out?
    >
    > The setting is here:
    > User Configuration -> Administrative Templates
    > -> Control Panel -> Display
    > -> Hide Desktop tab
    >
    > The setting goes here:
    >
    > [HKEY_CURRENT_USER\Software\Microsoft\Windows
    > \CurrentVersion\Policies\System]
    > Value Name: NoDispBackgroundPage
    > Data Type: REG_DWORD
    > Value Data: 0 = disabled, 1 = enabled
    >
    > If you would like to start from square one
    > on the WS, this TID explains how to clean:
    > http://support.novell.com/cgi-bin/se...?/10059171.htm
    > Follow 1-5, skip 6 (unnecessary)
    >
    > Regards
    > Rolf Lidvall
    > Swedish Radio (Ltd)
    >
    >

  • Issues with Server 2008 R2 GPO Settings Being Applied To Internet Explorer 11 on Windows 7

    We are working on a new domain and I'm trying to figure out how to populate the default Home page, Trusted Sites and the Proxy now that Microsoft has removed the IEM from the GPO's.
    I have created a standalone policy that only has these items set in the User Configuration Preferences and the settings are not updating for my test user account on the test system.  I see the policy is being applied without any errors.  The only
    other GPO that is being applied to this system is the Default Domain Policy and it is at the default settings.
    Why would Microsoft take away such a basic and fundamental administrative function?  I'm trying to figure this out before all support ends for the older versions of IE in January, 2016.  I'd appreciate any suggestions on how to get this configured
    so I don't have to touch every system.
    Mark Gordon
    Systems Administrator

    Hi Karen and thanks for the reply.  I'm having to use my personal Microsoft account as I was unable to reconnect to this one.  The only settings in this group policy that is set are the 3 fields (Home page, Security level for Trusted Sites and
    Proxy script under the LAN Settings) under the User Configuration Preferences.   There is nothing configured under the Computer Configuration section.
    I have my test computer and user in a Test OU with this policy linked to it.  The only policy being applied to this system through inheritance, is the Default Domain Policy (all default settings).  Attached is the link to the gpreport.html that
    you requested.
    I am very aware of making sure there are no other settings in the same as well as other policies that can overwrite the desired settings.  This is why I have created a policy with only these few settings as a test to ensure that they work.  I'd
    be grateful if you would review the result file below and could come up with some suggestions that I could try.  Thanks a bunch.
    https://onedrive.live.com/redir?resid=7956C3A4AD84AA5E%21549
    Sincerely,
    Mark Gordon
    If you're using Group Policy Preferences (GPP), a common mistake for those new to using GPP, is to misunderstand the F5/F6/F7/F8 configuration step (particularly for the Internet Explorer settings):
    http://blogs.technet.com/b/grouppolicy/archive/2008/10/20/red-green-underlining-continued-using-preferences-to-set-ie-settings-like-preference-or-like-policy.aspx
    http://blogs.technet.com/b/grouppolicy/archive/2008/10/13/red-green-gp-preferences-doesn-t-work-even-though-the-policy-applied-and-after-gpupdate-force.aspx
    http://justworks.ca/blog/f5-f6-f7-f8-red-green
    https://4sysops.com/archives/internet-explorer-10-administration-part-3-group-policy-preferences/
    https://dirteam.com/sander/2013/09/16/knowledgebase-internet-explorer-10-security-settings-are-silently-applied-to-client-computers-when-you-use-gpmc-to-view-the-group-policy-preferences-settings/
    http://blog.thesysadmins.co.uk/group-policy-internet-explorer-10-death-iem.html
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • Unable to remove Mapped drives GPO

    Hello
    Windows Server 2008 R2
    I previously create some mapped drives for users in 2 cities (same lan different ips - 10.10.2.x and 192.168.0.x)
    Under each ou I have gone into the GPO preferences and created a "Delete" under map drives.  When rebooting the workstations, the drives are still there and mapped.  I deleted the GPO for them and still, they show up.  I also created
    a new mapped drive and is sporatic to users (some users it does show up, others it does not show up).
    I cannot figure out why they are still being mapped or why only some users see the new mapped drive and some don't.  Even those users that see the new mapped drive still see the old ones as well.
    Any suggestions?
    Thank you
    Terry

    Hi Terry,
    There may be few things which you check
    1. Run RSOP or GPresult on users system and confirm if the old / new groups are getting applied.
    2. Make sure that group policy objects are replicated all domains Controllers in domain so that there is replication issue which is causing this behavior
    3. As suggestion if you need map drives for these users then don't need create new delete map drive. You can remove the original map drive settings or filter out these set of users using item level targeting.
    Hope this helps to resolve the issues.
    Regards,
    Rajesh J S

Maybe you are looking for