Solved

Group Policy Not getting aplied

Posted on 2004-09-23
9
222 Views
Last Modified: 2012-05-05
Hi All,

Here is my situation:

We have a Group Policy applied Domain-Wide (ie applied to our domain in AD Users & Comp). Recently we made changes to it to fix the wallpaper to a specific bmp. It worked a treat - no probs.

What I wanted to do was exclude a group from getting that Group Policy (and therefore that wallpaper change), so I decided to try and exclude me first, then when I worked that out I could exclude particular groups from getting the policy - but something has gone awry! It isn't working! I'm sure it is an easy solution, I am missing something simple... Here is what I did to try and exclude me:

1. Under 'Groups' in AD Users & Computers I created a new group called 'No Group Policy', and added myself to it.
2. Then I right clicked on the 'Groups' Folder (which is a built-in Organisational Unit?) containing the new group (and of course all other groups in our domain) and created a new Group Policy. In this new policy I first tried leaving the default settings (ie 'not configured' for the wallpaper changes), then I tried using the same settings as the domain policy (above it) but changing the actual wallpaper bmp so I could tell which GP was being applied.
3. I then changed the permissions of the policy to allow the 'No Group Policy' group (of which I was a member) 'read' and 'apply group policy' permissions, and removed the 'apply group policy' permission to the Authenticated Users Group (note - after trying it and it not working, I changed this back to default but it still made no difference)
4. Then I ticked 'Block Policy Inheritence'
5. Then I refreshed the GP (start > run > cmd > secedit /refreshpolicy user_policy)
6. Ten I logged off and back on (to my laptop) but still got the domain-wide policy wallpaper...

What am I doing wrong?

From my understanding, the following is true:
- GP's are only applied to Sites, Domains and OU's (Which is why I applied the GP to the 'Groups' folder but only gave the 'No Group Policy' group access to it)
- GP's are applied in that order: Sites > Domains > OU's (which is why I created the new GP in the 'Groups' folder, which is UNDER the Domain GP isn't it? So it should have been applied last...

Is there perhaps an issue that I am a member of multiple groups? I also tried taking the new group ('No Group Policy') out of the equation and just gave myself explicit permissions on the GP but still didn't work.. I also tried explicity denying myself from the DOMAIN level GP, but the lower-level GP still didn't work (it just went back to my old wallpaper)

...?



0
Comment
Question by:alsace
9 Comments
 
LVL 19

Expert Comment

by:Zaheer Iqbal
ID: 12140747
Are you sure the domain wide policy has not been applied to the OU container also???
0
 

Author Comment

by:alsace
ID: 12141926
Yeah it is being applied (because I am getting the standard wallpaper specified in the domain-wide GP), but I thought if I created a GP on that new OU it would override the domain-wide policy because (a) it was more specific (GP's are applied on the site, then the domain, then any OU's - in that order) and (b) I ticked the 'no-override' option in the new GP (which I thought was supposed to force it's application...)

Alsace.
0
 
LVL 15

Expert Comment

by:harleyjd
ID: 12142066
Enable loopback processing on the new GP. Because the users are not in a branch of the tree that the GP is attached to, the GP will not be applied to the users.

Loopback is enabled in Computer Configuration, Admin Templates, System, Group Policy.
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 

Author Comment

by:alsace
ID: 12157173
Hi harleyjd, thanks for the suggestion - but I wanted to avoid computer policies if I could and wanted to make it a user policy - a lot easier. Also the users are in a branch that the GP applies, as I have set the new GP on the Groups container...

I have found a solution - I just gave the 'no group policy' group (of which I am a member) explicit 'deny' access to the default domain policy - so it wasn't applied.

It works, but I still can't see why the original one didn't apply...

Thanks all for your help.
0
 
LVL 15

Expert Comment

by:harleyjd
ID: 14237898
PAQ/Refund
0
 

Author Comment

by:alsace
ID: 14253763
Yeah I am happy for a PAQ/Refund, do I need to formally request it in another thread?
0
 

Accepted Solution

by:
modulo earned 0 total points
ID: 14363963
PAQed with points refunded (200)

modulo
Community Support Moderator
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
The Nano Server Image Builder helps you create a custom Nano Server image and bootable USB media with the aid of a graphical interface. Based on the inputs you provide, it generates images for deployment and creates reusable PowerShell scripts that …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question