<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Gpo on Nicola Suter</title><link>https://tech.nicolonsky.ch/tags/gpo/</link><description>Recent content in Gpo on Nicola Suter</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>© 2026 Nicola Suter</copyright><lastBuildDate>Thu, 19 Oct 2017 17:51:57 +0000</lastBuildDate><atom:link href="https://tech.nicolonsky.ch/tags/gpo/rss.xml" rel="self" type="application/rss+xml"/><item><title>Windows 10 1709 Cannot Access SMB2 Share Guest Access</title><link>https://tech.nicolonsky.ch/windows-10-1709-cannot-access-smb2-share-guest-access/</link><pubDate>Thu, 19 Oct 2017 17:51:57 +0000</pubDate><guid>https://tech.nicolonsky.ch/windows-10-1709-cannot-access-smb2-share-guest-access/</guid><description>&lt;p&gt;After Upgrading to Windows 10 1709 (Fall Creators Update) I couldn&amp;rsquo;t access my Synology NAS anymore. Therefore I started troubleshooting the Windows 10 1709 Cannot Access SMB2 Share Guest Access error:&lt;/p&gt;
&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Windows 10 1709 Cannot Access SMB2 Share Guest Access"
 src="https://tech.nicolonsky.ch/content/images/2017/10/2017-10-19_1725-300x171.png"
 &gt;&lt;/figure&gt;
&lt;blockquote&gt;&lt;p&gt;An error occurred while reconnecting X: to &lt;code&gt;\\nas\data&lt;/code&gt;
Microsoft Windows Network: You can&amp;rsquo;t access this shared folder because your organization&amp;rsquo;s security policies block unauthenticated guest access. These policies help protect your PC from unsafe or malicious devices on the network.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 class="relative group"&gt;Cause
 &lt;div id="cause" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cause" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;Starting with Windows 10 1709, Windows prevents you from accessing network shares with guest access enabled. Guest access means connecting to network shares without authentication, using the built-in &amp;ldquo;guest&amp;rdquo; account.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;This has no reference to the SMB1 protocol which was disabled in the latest Windows 10 release.&lt;/strong&gt;&lt;/p&gt;

&lt;h2 class="relative group"&gt;Resolution
 &lt;div id="resolution" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#resolution" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;To enable guest access again, configure the following GPO:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;Computer configuration &amp;gt; administrative templates &amp;gt; network &amp;gt; Lanman Workstation: &amp;quot;Enable insecure guest logons&amp;quot; = Enabled&lt;/code&gt;&lt;/p&gt;
&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Windows 10 1709 Cannot Access SMB2 Share Guest Access"
 src="https://tech.nicolonsky.ch/content/images/2017/10/2017-10-19_1740-1024x726.png"
 &gt;&lt;/figure&gt;

&lt;h3 class="relative group"&gt;Registry Key
 &lt;div id="registry-key" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#registry-key" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;The according registry key is located under:&lt;/p&gt;</description></item><item><title>Manage Local Administrator Rights Using Group Policy</title><link>https://tech.nicolonsky.ch/manage-local-administrator-rights-using-group-policy/</link><pubDate>Sat, 14 Oct 2017 13:37:49 +0000</pubDate><guid>https://tech.nicolonsky.ch/manage-local-administrator-rights-using-group-policy/</guid><description>&lt;p&gt;If you imagine that your users or administrators have uncontrolled local administrator rights it&amp;rsquo;s a nightmare. They have (certainly) full control over their computer, and could do a lot of harm. So managing local administrator rights is definitely a must.&lt;/p&gt;

&lt;h1 class="relative group"&gt;Manage Local Administrator Rights
 &lt;div id="manage-local-administrator-rights" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#manage-local-administrator-rights" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;The Active Directory Group Policies offer a great possibility to manage local groups on clients or servers. All the magic happens with &amp;ldquo;Restricted Groups&amp;rdquo;.&lt;/p&gt;

&lt;h3 class="relative group"&gt;Adding a group or users to a local group
 &lt;div id="adding-a-group-or-users-to-a-local-group" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#adding-a-group-or-users-to-a-local-group" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;If you want to add a certain group to a built-in group add the group to the restricted groups under the &amp;ldquo;This group is a member of&amp;rdquo; sections:&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Group Policy Restricted Groups"
 src="https://tech.nicolonsky.ch/content/images//2017/10/2017-10-13_2326.png"
 &gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;When the GPO is no longer applied, the restricted group is being removed from the clients.&lt;/p&gt;

&lt;h3 class="relative group"&gt;Overwrite local group members
 &lt;div id="overwrite-local-group-members" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#overwrite-local-group-members" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;When you wan&amp;rsquo;t take full control over a local group, you can choose the &amp;ldquo;Members of this group&amp;rdquo; option. Then all group members are replaced with the specified users or groups here, except the built-in local Administrator account.&lt;/p&gt;</description></item></channel></rss>