Solved

Group Policy Not getting aplied

Posted on 2004-09-23
9
219 Views
Last Modified: 2012-05-05
Hi All,

Here is my situation:

We have a Group Policy applied Domain-Wide (ie applied to our domain in AD Users & Comp). Recently we made changes to it to fix the wallpaper to a specific bmp. It worked a treat - no probs.

What I wanted to do was exclude a group from getting that Group Policy (and therefore that wallpaper change), so I decided to try and exclude me first, then when I worked that out I could exclude particular groups from getting the policy - but something has gone awry! It isn't working! I'm sure it is an easy solution, I am missing something simple... Here is what I did to try and exclude me:

1. Under 'Groups' in AD Users & Computers I created a new group called 'No Group Policy', and added myself to it.
2. Then I right clicked on the 'Groups' Folder (which is a built-in Organisational Unit?) containing the new group (and of course all other groups in our domain) and created a new Group Policy. In this new policy I first tried leaving the default settings (ie 'not configured' for the wallpaper changes), then I tried using the same settings as the domain policy (above it) but changing the actual wallpaper bmp so I could tell which GP was being applied.
3. I then changed the permissions of the policy to allow the 'No Group Policy' group (of which I was a member) 'read' and 'apply group policy' permissions, and removed the 'apply group policy' permission to the Authenticated Users Group (note - after trying it and it not working, I changed this back to default but it still made no difference)
4. Then I ticked 'Block Policy Inheritence'
5. Then I refreshed the GP (start > run > cmd > secedit /refreshpolicy user_policy)
6. Ten I logged off and back on (to my laptop) but still got the domain-wide policy wallpaper...

What am I doing wrong?

From my understanding, the following is true:
- GP's are only applied to Sites, Domains and OU's (Which is why I applied the GP to the 'Groups' folder but only gave the 'No Group Policy' group access to it)
- GP's are applied in that order: Sites > Domains > OU's (which is why I created the new GP in the 'Groups' folder, which is UNDER the Domain GP isn't it? So it should have been applied last...

Is there perhaps an issue that I am a member of multiple groups? I also tried taking the new group ('No Group Policy') out of the equation and just gave myself explicit permissions on the GP but still didn't work.. I also tried explicity denying myself from the DOMAIN level GP, but the lower-level GP still didn't work (it just went back to my old wallpaper)

...?



0
Comment
Question by:alsace
9 Comments
 
LVL 19

Expert Comment

by:Zaheer Iqbal
Comment Utility
Are you sure the domain wide policy has not been applied to the OU container also???
0
 

Author Comment

by:alsace
Comment Utility
Yeah it is being applied (because I am getting the standard wallpaper specified in the domain-wide GP), but I thought if I created a GP on that new OU it would override the domain-wide policy because (a) it was more specific (GP's are applied on the site, then the domain, then any OU's - in that order) and (b) I ticked the 'no-override' option in the new GP (which I thought was supposed to force it's application...)

Alsace.
0
 
LVL 15

Expert Comment

by:harleyjd
Comment Utility
Enable loopback processing on the new GP. Because the users are not in a branch of the tree that the GP is attached to, the GP will not be applied to the users.

Loopback is enabled in Computer Configuration, Admin Templates, System, Group Policy.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:alsace
Comment Utility
Hi harleyjd, thanks for the suggestion - but I wanted to avoid computer policies if I could and wanted to make it a user policy - a lot easier. Also the users are in a branch that the GP applies, as I have set the new GP on the Groups container...

I have found a solution - I just gave the 'no group policy' group (of which I am a member) explicit 'deny' access to the default domain policy - so it wasn't applied.

It works, but I still can't see why the original one didn't apply...

Thanks all for your help.
0
 
LVL 15

Expert Comment

by:harleyjd
Comment Utility
PAQ/Refund
0
 

Author Comment

by:alsace
Comment Utility
Yeah I am happy for a PAQ/Refund, do I need to formally request it in another thread?
0
 

Accepted Solution

by:
modulo earned 0 total points
Comment Utility
PAQed with points refunded (200)

modulo
Community Support Moderator
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Describes a method of obtaining an object variable to an already running instance of Microsoft Access so that it can be controlled via automation.
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now