NetIQ Group Policy Administrator 4.5
NetIQ Group Policy Administrator 4.6
NetIQ Group Policy Administrator 5.0
All Repository users receive the the error 'Unable to create checkout version of GPO' when trying to check out any GPO from the Repository.
This can occur if the FullArmor container has been moved or deleted.
To verify the cause of the problem, first open up Active Directory Users and Computers as a Domain Admin and determine whether the FullArmor container is missing from the root. If it is missing, perform the following:
- Open the GPA Console with an account that is both a Domain Admin and has at a minimum the GPO Editor role in the Repository.
- Right click on any GPO and perform a Checkout.
Since the Domain Admin has rights to create containers in Active Directory, performing a checkout creates the FullArmor container and the structure underneath it. After performing this task, other Repository users should be able to checkout GPOs.
If other Repository users are still unable to check out GPOs, check the permissions on the FullArmor structure and verify the account has the permissions 'Create groupPolicyContainer Objects' and 'Delete groupPolicyContainer Objects' on the Policies container under the FullArmor structure.