Solved

Group Policies Not Applying

Posted on 2004-03-30
7
620 Views
Last Modified: 2010-03-18
All Clients are W2k professional. All fresh installs, no upgrades.
All DC's are W2k Server in native mode. Many of these servers were upgraded a while back from Windows NT.
I just want to get a GPO to apply to a set of users to remove buttons from the toolbar in Internet Explorer.
USER CONFIG/ADMIN TEMP/WINDOWS COMP/I EXPLORER/TOOLBARS
I have an OU that includes the users I need the policy applied to and I have created the GPO called toolbar in that OU.
I have checked the security tab on the group policy, both authenticated users and the specific domain users that need this policy applied have read and apply group policy checked
We really don't have a lot of GPOS on our network so I don't thing this is being overwritten
I've run GPresult on a machine where I am logged in as that user. The only other GPO that is included in that OU shoes up as being applied.
0
Comment
Question by:Brian_Blair
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 3

Expert Comment

by:following
ID: 10718107
Do you have any errors in the Application Log in Event Viewer that indicate that this policy is failing when it attempts to apply it?  So you don't even see this new GPO listed when you run GPresult, but you do see another GPO that is linked to the same OU?

-jdm
0
 

Author Comment

by:Brian_Blair
ID: 10720380
I will check event log 3/31.

That is correct, the policy is not even listed in the output of gpresult. However, the default domain policy, another gpo called "roaming" that is linked to the OU, and the local policy are showing up as affecting the user.
0
 
LVL 3

Expert Comment

by:following
ID: 10723090
This could possibly be a result of a replication problem between DCs.  If you configured the GPO on one DC and it is not replicating to another DC, then perhaps the client machine is getting its list of policies to apply from the second DC.

To check on this, look in the event viewer on your DCs under the File Replication Service logs and Directory Service logs (especially for NTDS KCC entries).  Also try the replmon and netdiag tools in the Windows 2000 Support Tools (if not already installed, these are on the W2K Server CD).

-jdm
0
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

 

Author Comment

by:Brian_Blair
ID: 10724427
Chacked that yesterday. Policies are replicating successfully.
Also checked event viewer. No errors in event viewer indicating policy failure.

We are a 1 domain shop with 11 dc's all W2K server.  When I create a gpo I do it through Active Directory Users and Computers. I'm a little confused when I see it suggested that the GPO may have been configured on one DC. I configure them right on my pc and link it to an OU. They seem to apply OK except this one.

Thanks for your help to this point though.
0
 
LVL 3

Expert Comment

by:following
ID: 10724832
If I understand it correctly, when you use Active Directory Users and Computers, it connects to the "closest" DC.  Whatever changes you make while connected to this DC are then replicated to the rest of the DCs at the next replication cycle.  So if you have replication problems on any particular DC and a client connects to that DC while logging on, it may not get the policy.  Does that make sense?

Are you using the Group Policy Management Console?  This is the new way of managing group policy that is downloadable from MS.  I have found it to very valuable for troubleshooting the organization of GPOs in our network.  It is a little more visual than the old way of doing it -- might help to pinpoint where it's failing.

http://www.microsoft.com/downloads/details.aspx?FamilyId=C355B04F-50CE-42C7-A401-30BE1EF647EA&displaylang=en

I see that all your clients are w2k.  The GPMC may only be installed on XP Pro or W2K3 Server; however, it will manage W2K servers as well as W2K3 servers.  Perhaps you won't be able to use this tool if you have no XP clients.

-jdm
0
 

Author Comment

by:Brian_Blair
ID: 10726144
No I haven't tried that yet. If I load XP on a machine and then download it, will I be able to look and see how policies are being applied on specific PC's in my networK?
0
 
LVL 3

Accepted Solution

by:
following earned 250 total points
ID: 10726321
You will be able to run very informative reports that are similar to GPResult, except you can run them against a remote machine for any user that has previously logged onto that machine.  You can also see exactly which GPOs are linked to which objects and whether any GPOs at a specific OU level are set to "Block Inheritance" or "Enforce" -- right click on the OU.  You can quickly see if the User or Computer portion of a GPO has been disabled (usually for performance reasons) -- right click on the GPO and click GPO Status.  You can see if the link to a GPO has been enabled for the OU -- right click on the GPO under the OU and see if "Link Enabled" is checked.  You can see at a glance a summary of all settings that are configured in a particular GPO.

In short, it is a wonderful tool to manage, troubleshoot, and organize most all aspects of Group Policy.

-jdm
0

Featured Post

PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Enterprise networks where VoIP phones have been deployed frequently use port configurations that allow both a computer and an IP phone to be plugged into the same switch port but use different VLANs. On Cisco equipment I'm referring to the "native V…
This article is in response to a question (http://www.experts-exchange.com/Networking/Network_Management/Network_Analysis/Q_28230497.html) here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Add bar graphs to Access queries using Unicode block characters. Graphs appear on every record in the color you want. Give life to numbers. Hopes this gives you ideas on visualizing your data in new ways ~ Create a calculated field in a query: …

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question