In applying a group policy to a Windows 2003 Server domain, the policy was inadvertently applied to the Domain Admin account. It was a very restrictive policy … no access to My Computer, no access to command prompt, no access to control panel, to MMC panels etc. In essence, the admin account can do almost nothing. Is there any way to prevent the policy from applying to the domain admin account? Is there any way to override it? Is there any way to free the admin account so I can manage the GPO and delete the restrictive policy? That is, any way short of trashing the domain and starting over again from scratch?
TIA