Applying a security template: one setting not saved to secedit.sdb

Applying a security template: one setting not saved to secedit.sdb

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Applying a security template: one setting not saved to secedit.sdb void.no.spam.com@gmail.com 06-06-2007
Posted by void.no.spam.com@gmail.com on June 6, 2007, 2:01 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I'm running Windows 2000 w/SP4 and I recently used the Security
Configuration and Analysis tool to apply a security template. This
security template changed a bunch of values, and I rebooted after it
was applied. Then I checked my Security Settings in gpedit.msc, and
it showed all of the new values, except for those in the Local Policies
\Security Options section. That section still showed all of the old
values for some reason.

Then I came across this article: http://support.microsoft.com/kb/827664

It says that if you use the SCaA tool to apply a template, the values
in the Security Options section may not be updated in the secedit.sdb
database until 16 hours later. I tried the workaround of double-
clicking one of the security options in gpedit.msc and hitting OK, and
then rebooted. This caused gpedit.msc to display all of the new
Security Options values, except for one of them. The "Disable CTRL+ALT
+DEL requirement for logon" policy still displayed the old value of
"Not Defined" (the template sets it to "Disabled").

If I use the SCaA tool and analyze my computer against the security
database that I created with my template, it says that the Database
Setting and Computer Setting are both "Disabled" for the "Disable CTRL
+ALT+DEL requirement for logon" policy. But if I analyze my computer
against my secedit.sdb file, then it says the Database Setting is "Not
Defined" and the Computer Setting is "Disabled" for that policy. So
the setting for that policy got updated in the registry, but it did
not get updated in the secedit.sdb file for some reason.

Any idea why that one policy didn't get updated in the secedit.sdb
file, but all the others did?


Similar ThreadsPosted
Applying security templates June 12, 2007, 6:01 pm
Saved pc from Malicious BHO’s October 4, 2008, 3:19 pm
%windir%\security \database\secedit.sdb ) was. The parameter is in June 12, 2007, 4:56 am
Security Setting May 12, 2007, 2:07 am
security template unreadable November 11, 2006, 8:50 am
Customzing Security Template Files December 7, 2005, 11:25 am
How to remove an applied security template on XP SP2 August 23, 2006, 11:55 am
Security Setting on Domain Controllers November 3, 2008, 3:56 pm
Security Template does not apply folder permissions January 2, 2007, 11:00 am
File System Security Setting Causes Slow Logon November 15, 2005, 7:21 pm

The site map in XML format XML site map

Contact Us | Privacy Policy