I have just completed the migration of my NT4 domain to Windows2003/Active Directory.
I have created new logical OU's that make sense to our company and moved all computers, users and groups to appropriate OU structures.
My Group Policies are not working on any new OU that I create.
If I right click on mydomain.com, and go to the policies tab, I can edit the policies and those get pushed down fine. It only works at this level.
Here is what I have tried...
Made a new OU on the root of mydomain.com called TESTOU
I moved the computer that I want to push policies to into this OU.
I then created a group in this OU called MYPOLICYGROUP
Then I created a new policy and applied that policy to the group "MYPOLICYGROUP"
Edit the policy and took away the start/run.
Replicated Active Directory. (no errors)
Ran gpupdate /force from the client.
Rebooted the client.
I "DO NOT" get the new policy....ugh!
I then ran GPRESULT, it never shows the policy being applied or denied for any reason.
I can get this to work only if I put the user and computer into the same OU.
For many reasons this is not a viable solution.
Does anyone have any ideas why this may be doing this?
Thanks
DK
Also, make sure that the GPO's security permissions are set correctly.. The READ and Apply must be set...
FE