Use a domain-wide policy

This is the recommended option to enable remote access for Windows 2000 style domains.

This option is only available to Windows 2000-style domains that support ACL-level control through domain-wide registry policies.

  1. Log in to the Domain Controller as Administrator.
  2. Open the Active Directory Users and Computers MMC snap-in.
  3. Create a new Global group called CA_scanners by selecting New and then Group from the User folder in the Tree tab.
  4. Open the properties dialog box for the group.
  5. Select the Members Of tab.
  6. Remove the Everyone group by selecting Remove. The Members Of section should be empty.
  7. Create a new user account called CA_account by selecting New and then User from User folder in the Tree section.
  8. Add the new user account to the "CA_scanners" group.
  9. Confirm that the user has no unintended permissions on the domain. For example, check the "Member of" section to confirm that it only has the "CA_scanners" group listed.
  10. Open the "Domain Security Policy" MMC snap-in, and add the remote access key:
    1. Go to the "Registry" section.
    2. Select "Add Key".
    3. Add the following key:

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg

  11. Select the new registry key by selecting Windows Setting and then Registry from the Tree tab.
  12. Add the CA_scanners group, and set "Read" and "Execute" permissions only by selecting the read and execute checkbox.
  13. Open the Set the Template Security Policy Setting dialog box to configure this key.
  14. Select the Propagate inheritable permissions to subkeys option.
  15. Select OK. The new registry-key ACL policy is propagated to all Windows endpoints participating in the domain (standalone endpoints are not affected in any way). The time it takes for this configuration to be propagated to endpoints may vary, depending on network configuration and traffic. To set the registry processing options:
  16. Open the Group Policy MMC.
  17. Select the Default Domain Policy, and then go the Group Policy section.
  18. Select Default Domain Policy and then Computer Configuration, Administrative Templates, then System, Group Policy.
  19. Set options in Registry Policy Processing Properties dialog box and the Group Policy Refresh Interval for Computers Properties dialog box. Be sure to select the Process even if Group Policy objects have not changed in the Registry Policy Processing Properties dialog box.