Unable to set up synchronization of the default domain policy. (NETIQKB52867)

  • 7752867
  • 02-Feb-2007
  • 18-Jul-2007

Resolution

fact
NetIQ Group Policy Administrator 5.0

symptom

Unable to set up synchronization of the default domain policy.



symptom

Unable to set up synchronization of the default domain controllers policy.



symptom

Error: 'Default domain policy is already a master GPO and could not be added as a controlled GPO for this master GPO.'



cause

All of the 'default domain policy' GPOs have the same GUID, as do all of the 'default domain controllers policy' GPOs. For this reason, Group Policy Administrator does not allow you to set up synchronization of these GPOs with each other.



fix

As a workaround, you can migrate the default domain policy from one domain in the repository to another and then set up the migrated GPO as a controlled GPO, to be synchronized with the master.

Because it may be confusing to have another GPO called 'Default Domain Policy,' consider creating a new GPO with a different name such as 'My Domain Policy' and linking it to the domain. If you already have a number of settings in your default domain policy, you can simply copy and paste from the default domain policy and rename the copy. Then, migrate the new GPO and set it up as a controlled GPO, to be synchronized with the master.

Note: Whichever method you choose, ensure the link to the domain gets mapped correctly during migration.



Additional Information

Formerly known as NETIQKB52867