Tech or Treat! Write an article about your scariest tech disaster to win gadgets!Learn more


Group policy not being accepted on XP Clients

Posted on 2003-12-10
Medium Priority
Last Modified: 2010-05-18
I have 2 Windows 2000 Domain controllers.  Recently I have added 5 new Dell dimension 2350 desktop computers with XP Pro to the domain.  For some reason, they are not accepting some group policy updates.  I have a policy set to install pc anywhere from a network share, this policy works for all other computers in the company, which include windows2000 and xp pro clients.  
I have run GPRESULT from the win2k resource kit on the client boxes in question, and they are getting some policy changes from the domain controller that is assigning them but not others.  The credentials appear the be identical to other computers in the domain, so I have ruled out access rights as a possible reason.  The only difference I have found is that the boxes in question are Dells that came with the OS pre installed, they are the only ones with this problem.  I have deleted networking completely and reinstalled it, I removed them from the domain, renamed them and rejoined them to the domain.  I have run gptool on the dcs to validate the policies, which returns no errors.  Everything else on the client boxes seems to be working normally, DNS, they are accepting their DHCP assignments, and connecting to the network with no other issues.  I have also uninstalled ALL dells preinstalled software.  If anyone has any other solutions on this - HELP!  Its driving me insane, I cannot alter the clients SUS settings via group policy, and therefore have to install updates and patches manually.  Granted its only on 5 boxes, but something has gone wrong.  I dont want to have to reinstall the os, but Im getting desparate.
Question by:Col_Beckwith
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 11

Expert Comment

ID: 9914042
on the client machine.. see if there is a security policy(local group policy object) in place and if there is a setting.. that is configured not to inherit the policy from the domain..

Expert Comment

ID: 9914166
Use the following command:
gpupdate /sync
gpupdate /force
then restart PC.

After that Start "Help and support", Click "tools" in the rightside of the window.
Choose "Special system information" then Results of Group policy (I have a Hungarian XP, so I have to translate menus back, sorry)
You can find useful information here.
Finally, check GPO permission. Is it permitted to apply policy to these machenes?

Tamás Lepenye
from Hungary
(Sorry for grammar)

Author Comment

ID: 9920741
Ok, adonis1976 - I couldnt find anything in local gp on the client boxes that would deny group policy updates.

lepenyet, I tried your suggestion and noticed that USER group policies are being accepted on any given box, but COMPUTER policies, which is the case here in this problem are NOT being updated on the client box.  Again, this is only happening on these Dells.  One other thing worth mentioning is that if I try a net send command to any of these computers, using fqdn or their netbios names, they are not found in the attempt, the "message alias could not be found on the network", and if I run nbtstat -a against the netbios name of the boxes, the current logged on user <03> unique doesnt appear in the in the results even though a current use is logged on.  Dunno if this is related.  One other thing I noticed using the Help and Support to view GP results on the clients boxes, is that the Site information is blank for the client box, ie what site it belongs to, all the other computers have this info, however, the domain it belongs to is correctly listed.  Something is not updating.  By the way, thanks for the help and support gp view, I didnt know XP had that, I was used to using GPRESULT on win2k boxes.
Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

LVL 15

Expert Comment

by:Rob Stone
ID: 9920812

Is it worth trying SECEDIT /REFRESHPOLICY on the XP Clients?

It does sound a bit strange with these clients.  Are they showing up in the DNS Snap in on the server?  I presume they ping OK?

Are you using WINS as well as DNS?  Are these clients  using the same settings under IPCONFIG /ALL?  LMHOSTS lookup enabled on the clients?

Author Comment

ID: 9920918
all the networking settings are indentical.  Ive use secedit /refreshpolicy from the server - machine_policy, I used GPUPDATE as per lepenyets comments to no avail.  I assume they do the same thing on the client machines.  The client boxes ping fine, the log on to the domain with no problems.  They are showing up in the dns snap in on the servers with the correct ip address as assigned by dhcp server.

Author Comment

ID: 9931323
I solved the riddle.  Issue was the network adapter - a broadcom 440.  I used a registry hack to modify dhcp media sense in hkey_local_machine, system, current control set, services, tcpip, parameters.  I added a DWORD value "DisableDHCPMediaSense" and set its value to one.  Apparently there is a bug on some adapters where group policies for machines assigned by the DC will not be propagated because of the media sense parameter.  Upon reboot, the client boxes accepted the install for the local machine and bingo it all started working.

Accepted Solution

GhostMod earned 0 total points
ID: 11330225
PAQed, with points refunded (125)

Community Support Moderator

Expert Comment

ID: 23464261
4/5 Years later and the Dell Vostro 220s still has the same problem

The registry hack worked....I will send an email to Dell and request them to pre-hack the registry on all computers with the Broadcom LAN Card.

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
One of the most important things in an application is the query performance. This article intends to give you good tips to improve the performance of your queries.
This course is ideal for IT System Administrators working with VMware vSphere and its associated products in their company infrastructure. This course teaches you how to install and maintain this virtualization technology to store data, prevent vuln…
Add bar graphs to Access queries using Unicode block characters. Graphs appear on every record in the color you want. Give life to numbers. Hopes this gives you ideas on visualizing your data in new ways ~ Create a calculated field in a query: …

647 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question