Hello Van Fifty,
Using secedit to export, modify, and reimport security policy settings is a valid approach, and reimporting only a specific section (like [System Access]) generally does not cause negative consequences as long as the required [Version] header is present. Windows expects that section for consistency, which is why you saw errors without it. The partial import simply overwrites the targeted settings, leaving other areas of the policy untouched.
That said, it’s important to be cautious: if the configuration file is incomplete or malformed, you could unintentionally reset or clear other policy areas. To minimize risk, always keep a full backup of the original exported configuration before applying changes. This way, you can restore quickly if something doesn’t behave as expected.
Regarding the comment you read about exporting “violating system security,” you’re correct in your assumption. The concern is mainly about exporting the entire policy and leaving the file accessible, since it exposes sensitive configuration details. As long as you handle the file securely, store it in a protected location and delete it when finished, the risk is minimal.
In practice, your approach of importing only the relevant section is fine, and many administrators use it to streamline changes. Just remember to validate the applied settings with secedit /analyze or by checking secpol.msc afterward, which you’ve already done successfully.
I hope the response provided some helpful insight. If you find this answer useful, please hit “accept answer” so I know it addressed your concern.
Jason