Link to home
Start Free TrialLog in
Avatar of psueoc
psueocFlag for United States of America

asked on

Windows Server 2003 GPO Software deploy

I'm having a problem installing software via GPO's

I've created a separate OU just for testing purposes, and moved 1 computer into that OU.  I created a "new" group policy, and "assigned" a softare package under the "computer configuration" section.  I've also made sure the "authenticated users" has "full control" over the location where the package is located. (even though they probably only needed read and execute).   I'm able to manually install this MSI file just fine.  But for some reason I keep getting the following errors in the event viewer.

EVENT ID 1085   "The Group Policy client-side extension Software Installation failed to execute. Please look for any errors reported earlier by that extension.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp."

and

EVENT ID 108  "Failed to apply changes to software installation settings.  Software changes could not be applied.  A previous log entry with details should exist.  The error was : There is no software installation data object in the Active Directory.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp."


Anybody have any ideas

Avatar of DaMaestro
DaMaestro
Flag of United States of America image

When you added software object to AD, did you only select assigned or did u customize? Have you deleted it and reassigned it?
When it prompted for the location of the .msi did you enter it as a UNC path?
Pls check to see if:

1) you have check the permission on the file to allow full access to the file
2) check in your domain controller security policy if there are any policies defined that state that you cannot install .msi files across the network

Btw, any chance if you can map the shared folder, and install it through a drive letter instead of UNC?
Avatar of psueoc

ASKER

right now the GPO is set to "assign".  I have deleted and re-assigned it a few times now.

"authenticated" users have full control over the location of the .msi file

the installation location is referred to in the GPO by it's full UNC path

previous GPO software deploys worked, so I don't think I'm restricting them elsewhere in the default domain policy.

One thing I did do a long long time ago, before I knew what the heck I was doing with GPO's, was assign a software deploy withing the "default domain policy" (a big no no, but lesson learned).  Ever since this mistake, I've have occasionally been seeing the above mentioned EVENT ID's on ALL client systems.  Usually after a reboot (but no every time), not just a log off and back on.  Don't know if this helps at all, just another piece of information I thought of.


Is the authenticated users a file level permission or share level permission? Is there a matching permission at both share and file level or is one of them more restrictive? Have you done effective permissions on the share location and/or resultant set of policy (group policy results) on the target machine? What are the the builtin\system and domain computers account permissions?
Avatar of psueoc

ASKER

both the share permissions and the NTFS file permissions are set to "authenticated users" full control
Avatar of psueoc

ASKER

*****APPMGMT.LOG******

09-22 11:34:47:896
Software installation extension has been called for asynchronous policy refresh
The following policies are to be applied, flags are 1011.
    Default Domain Policy (unique identifier {31B2F340-016D-11D2-945F-00C04FB984F9})
        System volume path = \\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine
        Active Directory path = LDAP://CN=Machine,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu
    Install Mozilla Firefox (unique identifier {EBCDD3AA-BE77-47F5-8133-5ABE631297CE})
        System volume path = \\eoc.psu.edu\SysVol\eoc.psu.edu\Policies\{EBCDD3AA-BE77-47F5-8133-5ABE631297CE}\Machine
        Active Directory path = LDAP://CN=Machine,CN={EBCDD3AA-BE77-47F5-8133-5ABE631297CE},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu
Set the Active Directory path to LDAP://CN=Class Store,CN=Machine,CN={EBCDD3AA-BE77-47F5-8133-5ABE631297CE},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu;LDAP://CN=Class Store,CN=Machine,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu;.
Enumerating applications in the Active Directory for computer EOC1144 with flags 5.
Cannot bind to the Active Directory to enumerate applications, error code 80040169.
Failed to apply changes to software installation settings.  Software changes could not be applied.  A previous log entry with details should exist.  The error was : %2147746153

Software installation extension returning with final error code 2147746153.
09-22 11:34:50:851
Software installation extension has been called for foreground synchronous policy refresh.
The following policies are to be removed, flags are 0.
    Default Domain Policy (unique identifier {31B2F340-016D-11D2-945F-00C04FB984F9})
        System volume path = \\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\User
        Active Directory path = LDAP://CN=User,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu
Enumerating the managed applications which are currently applied to this user.
No managed applications are currently applied to this user.
Policy Default Domain Policy has been removed.  All applications will be made unmanaged or removed.
No Active Directory path.
Software installation extension returning with final error code 0.
09-22 11:48:58:044
Software installation extension has been called for asynchronous policy refresh
The following policies are to be applied, flags are 1011.
    Default Domain Policy (unique identifier {31B2F340-016D-11D2-945F-00C04FB984F9})
        System volume path = \\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine
        Active Directory path = LDAP://CN=Machine,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu
    Install Mozilla Firefox (unique identifier {EBCDD3AA-BE77-47F5-8133-5ABE631297CE})
        System volume path = \\eoc.psu.edu\SysVol\eoc.psu.edu\Policies\{EBCDD3AA-BE77-47F5-8133-5ABE631297CE}\Machine
        Active Directory path = LDAP://CN=Machine,CN={EBCDD3AA-BE77-47F5-8133-5ABE631297CE},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu
Set the Active Directory path to LDAP://CN=Class Store,CN=Machine,CN={EBCDD3AA-BE77-47F5-8133-5ABE631297CE},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu;LDAP://CN=Class Store,CN=Machine,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu;.
Enumerating applications in the Active Directory for computer EOC1144 with flags 5.
Cannot bind to the Active Directory to enumerate applications, error code 80040169.
Failed to apply changes to software installation settings.  Software changes could not be applied.  A previous log entry with details should exist.  The error was : %2147746153

Software installation extension returning with final error code 2147746153.
09-22 11:54:01:055
Software installation extension has been called for asynchronous policy refresh
The following policies are to be applied, flags are 1011.
    Default Domain Policy (unique identifier {31B2F340-016D-11D2-945F-00C04FB984F9})
        System volume path = \\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine
        Active Directory path = LDAP://CN=Machine,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu
Set the Active Directory path to LDAP://CN=Class Store,CN=Machine,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu;.
Enumerating applications in the Active Directory for computer EOC1144 with flags 5.
Cannot bind to the Active Directory to enumerate applications, error code 80040169.
Failed to apply changes to software installation settings.  Software changes could not be applied.  A previous log entry with details should exist.  The error was : %2147746153

Software installation extension returning with final error code 2147746153.
09-22 11:58:09:024
Software installation extension has been called for asynchronous policy refresh
The following policies are to be applied, flags are 1011.
    Default Domain Policy (unique identifier {31B2F340-016D-11D2-945F-00C04FB984F9})
        System volume path = \\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine
        Active Directory path = LDAP://CN=Machine,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu
Set the Active Directory path to LDAP://CN=Class Store,CN=Machine,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu;.
Enumerating applications in the Active Directory for computer EOC1144 with flags 5.
Cannot bind to the Active Directory to enumerate applications, error code 80040169.
Failed to apply changes to software installation settings.  Software changes could not be applied.  A previous log entry with details should exist.  The error was : %2147746153

Software installation extension returning with final error code 2147746153.
09-22 12:57:06:207
Software installation extension has been called for asynchronous policy refresh
The following policies are to be applied, flags are 1011.
    Default Domain Policy (unique identifier {31B2F340-016D-11D2-945F-00C04FB984F9})
        System volume path = \\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine
        Active Directory path = LDAP://CN=Machine,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu
Set the Active Directory path to LDAP://CN=Class Store,CN=Machine,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=eoc,DC=psu,DC=edu;.
Enumerating applications in the Active Directory for computer EOC1144 with flags 5.
Cannot bind to the Active Directory to enumerate applications, error code 80040169.
Failed to apply changes to software installation settings.  Software changes could not be applied.  A previous log entry with details should exist.  The error was : %2147746153

Software installation extension returning with final error code 2147746153.


******USERENV.LOG*******
USERENV(2ec.2f0) 09:23:34:407 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.2f0) 09:23:34:437 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.2f0) 09:23:34:447 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.520) 09:24:12:411 ProcessGPO:  Couldn't find the group policy template file <\\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>, error = 0x3.
USERENV(2ec.520) 09:24:12:411 EvalList:  ProcessGPO failed
USERENV(2ec.520) 09:24:12:411 GetGPOInfo:  EvaluateDeferredGPOs failed. Exiting
USERENV(2ec.520) 09:24:12:421 ProcessGPOs: GetGPOInfo failed.
USERENV(2ec.140) 09:24:12:592 ProcessGPO:  Couldn't find the group policy template file <\\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>, error = 0x3.
USERENV(2ec.140) 09:24:12:592 EvalList:  ProcessGPO failed
USERENV(2ec.140) 09:24:12:602 GetGPOInfo:  EvaluateDeferredGPOs failed. Exiting
USERENV(2ec.140) 09:24:12:602 ProcessGPOs: GetGPOInfo failed.
USERENV(2ec.6a0) 10:58:08:100 ProcessGPO:  Couldn't find the group policy template file <\\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>, error = 0x3.
USERENV(2ec.6a0) 10:58:08:100 EvalList:  ProcessGPO failed
USERENV(2ec.6a0) 10:58:08:110 GetGPOInfo:  EvaluateDeferredGPOs failed. Exiting
USERENV(2ec.6a0) 10:58:08:110 ProcessGPOs: GetGPOInfo failed.
USERENV(2ec.2f0) 11:02:56:122 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.2f0) 11:02:56:142 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.2f0) 11:02:56:152 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.508) 11:03:37:692 ProcessGPO:  Couldn't find the group policy template file <\\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>, error = 0x3.
USERENV(2ec.508) 11:03:37:702 EvalList:  ProcessGPO failed
USERENV(2ec.508) 11:03:37:702 GetGPOInfo:  EvaluateDeferredGPOs failed. Exiting
USERENV(2ec.508) 11:03:37:702 ProcessGPOs: GetGPOInfo failed.
USERENV(2ec.130) 11:03:37:962 ProcessGPO:  Couldn't find the group policy template file <\\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>, error = 0x3.
USERENV(2ec.130) 11:03:37:962 EvalList:  ProcessGPO failed
USERENV(2ec.130) 11:03:37:962 GetGPOInfo:  EvaluateDeferredGPOs failed. Exiting
USERENV(2ec.130) 11:03:37:972 ProcessGPOs: GetGPOInfo failed.
USERENV(2e8.2ec) 11:05:50:982 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2e8.2ec) 11:05:51:012 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2e8.2ec) 11:05:51:012 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2e8.504) 11:06:32:341 ProcessGPO:  Couldn't find the group policy template file <\\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>, error = 0x3.
USERENV(2e8.504) 11:06:32:341 EvalList:  ProcessGPO failed
USERENV(2e8.504) 11:06:32:351 GetGPOInfo:  EvaluateDeferredGPOs failed. Exiting
USERENV(2e8.504) 11:06:32:351 ProcessGPOs: GetGPOInfo failed.
USERENV(2e8.164) 11:06:34:945 ProcessGPO:  Couldn't find the group policy template file <\\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>, error = 0x3.
USERENV(2e8.164) 11:06:34:945 EvalList:  ProcessGPO failed
USERENV(2e8.164) 11:06:34:945 GetGPOInfo:  EvaluateDeferredGPOs failed. Exiting
USERENV(2e8.164) 11:06:34:955 ProcessGPOs: GetGPOInfo failed.
USERENV(2ec.2f0) 11:10:37:587 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.2f0) 11:10:37:617 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.2f0) 11:10:37:617 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.4f8) 11:11:17:715 ProcessGPO:  Couldn't find the group policy template file <\\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>, error = 0x3.
USERENV(2ec.4f8) 11:11:17:725 EvalList:  ProcessGPO failed
USERENV(2ec.4f8) 11:11:17:725 GetGPOInfo:  EvaluateDeferredGPOs failed. Exiting
USERENV(2ec.4f8) 11:11:17:745 ProcessGPOs: GetGPOInfo failed.
USERENV(2ec.444) 11:11:17:995 ProcessGPO:  Couldn't find the group policy template file <\\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>, error = 0x3.
USERENV(2ec.444) 11:11:17:995 EvalList:  ProcessGPO failed
USERENV(2ec.444) 11:11:18:005 GetGPOInfo:  EvaluateDeferredGPOs failed. Exiting
USERENV(2ec.444) 11:11:18:005 ProcessGPOs: GetGPOInfo failed.
USERENV(2ec.2f0) 11:34:03:082 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.2f0) 11:34:03:122 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.2f0) 11:34:03:122 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2ec.560) 11:34:47:756 GetGPOInfo:  Local GPO's gpt.ini is not accessible, assuming default state.
USERENV(2ec.560) 11:34:48:347 ProcessGPOs: Extension Software Installation ProcessGroupPolicy failed, status 0x80040169.
USERENV(2ec.108) 11:34:50:540 GetGPOInfo:  Local GPO's gpt.ini is not accessible, assuming default state.
USERENV(304.308) 11:48:18:617 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(304.308) 11:48:18:647 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(304.308) 11:48:18:657 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(304.524) 11:48:57:843 GetGPOInfo:  Local GPO's gpt.ini is not accessible, assuming default state.
USERENV(304.524) 11:49:00:347 ProcessGPOs: Extension Software Installation ProcessGroupPolicy failed, status 0x80040169.
USERENV(304.1fc) 11:49:00:597 GetGPOInfo:  Local GPO's gpt.ini is not accessible, assuming default state.
USERENV(2e8.2ec) 11:53:17:042 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2e8.2ec) 11:53:17:082 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2e8.2ec) 11:53:17:082 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(2e8.4f8) 11:54:00:574 GetGPOInfo:  Local GPO's gpt.ini is not accessible, assuming default state.
USERENV(2e8.4f8) 11:54:01:195 ProcessGPOs: Extension Software Installation ProcessGroupPolicy failed, status 0x80040169.
USERENV(2e8.130) 11:54:01:376 GetGPOInfo:  Local GPO's gpt.ini is not accessible, assuming default state.
USERENV(304.308) 11:57:30:038 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(304.308) 11:57:30:098 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(304.308) 11:57:30:098 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(304.520) 11:58:08:903 GetGPOInfo:  Local GPO's gpt.ini is not accessible, assuming default state.
USERENV(304.520) 11:58:09:124 ProcessGPOs: Extension Software Installation ProcessGroupPolicy failed, status 0x80040169.
USERENV(304.200) 11:58:09:304 GetGPOInfo:  Local GPO's gpt.ini is not accessible, assuming default state.
USERENV(300.304) 12:56:24:827 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(300.304) 12:56:24:877 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(300.304) 12:56:24:887 CUserProfile::CleanupUserProfile: Ref Count is not 0
USERENV(300.508) 12:57:06:027 GetGPOInfo:  Local GPO's gpt.ini is not accessible, assuming default state.
USERENV(300.508) 12:57:06:307 ProcessGPOs: Extension Software Installation ProcessGroupPolicy failed, status 0x80040169.
USERENV(300.2b4) 12:57:06:447 GetGPOInfo:  Local GPO's gpt.ini is not accessible, assuming default state.
Is DFS running?
Is the file \\eoc.psu.edu\sysvol\eoc.psu.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini there with the correct permissions set?
Avatar of psueoc

ASKER

DFS is not running

GPT.INI is there and does seem to have appropriate permissions
ASKER CERTIFIED SOLUTION
Avatar of Shift-3
Shift-3
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of psueoc

ASKER

dcgpofix did the trick.

it was bit of a pain going back through and making all the changes again, but it worked

thanks
When you ran the dcgpo fix did it touch anything in AD or just the default domain GPO?
Avatar of psueoc

ASKER

wow, that was quite some time ago.  But if I remember correctly, the only thing i had to redo was all the changes made to the "default domain policy"