I’ve got a (WS2012-R2) domain controller and a set of (WS2012-R2) servers that are member of the domain.
I accidentally added a group all administrators are member of to the Group Policy “Deny logon access locally”, “Deny logon as service”, “Deny remote access” and “Deny network access”.
This resulted in me and all other administrators (even the built-in account) being locked out of the domain controller.
Is there a way to regain access to the server by removing the GPO or by removing an admin account from the group that has been denied?