• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 188
  • Last Modified:

GPO for Computer Restriction Policy Stopped Working

I have a computer restriction policy defined to certain computers in an OU.  This policy has been working for months.  This policy is marked enforced.  The policy restricts these computers from using Internet Explorer (path rule C:\Program Files\Internet Explorer\IEXPLORE.EXE).  This week, the policy stopped working.  All of the computers in the OU can now use Internet Explorer.  I have verified that the policy has not changed and nothing on these computers looks any different (33 computers).

I deleted the current policy and recreated it; however this had no effect.
0
Deathblow
Asked:
Deathblow
1 Solution
 
mikeleebrlaCommented:
if the OS of the clients is XP run gpresult to see if the GPOs are even being pushed down to the clients
0
 
DeathblowAuthor Commented:
GPRESULT is showing that this policy is not getting pushed the clients.  We checked this; however, this was not the case as of last week.  This problem started this week.
0
 
mikeleebrlaCommented:
well if the policy isn't being pushed to the clients then that is where you need to start,,, of course the policy will not be in effect if its not even being applied
0
Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

 
DeathblowAuthor Commented:
That is why I asked my original question.  What may be causing this to happen?
0
 
mikeleebrlaCommented:
can you copy and paste the result of the gpresult??
0
 
wlandymoreCommented:
we had a problem like this on a DC, where something became corrupt with the OS on that machine and then the policies after that weren't applied in the right order, if at all. In this case, replication was also a problem spot.
0
 
kristinawCommented:
death,

check your perms on the group policy and make sure 'apply group policy' is checked as well as 'read'.

kris.
0
 
mikeleebrlaCommented:
kristinaw is right,, that is one of the most often overlooked things when setting up GPOs,,, why they aren't turned on by default ill never know
0
 
DeathblowAuthor Commented:
This wasn't overlooked orginally because it worked for months; however, it appears that the permissions had been removed from authenticated users to apply group policy.  I'll have to do some internal research to see how that happened.  I am testing this now to see if this resolves the problem.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

The 14th Annual Expert Award Winners

The results are in! Meet the top members of our 2017 Expert Awards. Congratulations to all who qualified!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now