Hi All,
I am using the Group Policy Management console to administer Group Policy in another domain. I am able to connect to and read all objects fine. I am able to create new objects, edit the objects I’ve just created, and link all objects.
The problem is that I cannot edit pre-existing individual GPOs–objects that were created from the local DC. Shouldn’t the permissions applied to the “Group Policy Objects” container (using the “delegation” tab) filter down to all individual objects?
I would prefer not to have to log into the local DC and grant myself permission on every single GPO created from there (x 20 locations/domains).
Thanks.