Solved

Group Policy doesn't refresh correctly after copying profile using Copy To

Posted on 2006-07-21
2
238 Views
Last Modified: 2010-04-18
So, recently I set up an OU at my company for the user accounts that log on to computers on the manufacturing floor.  The goal is that we don't want those accounts to have internet access.  So, I used a GPO to basically point their browsers to a bogus proxy server, thereby disabling their access -- I also disabled the ability to change the proxy server.  SO, yesterday I was told by one of the managers that one of the computers in the back was going to be used by an assistant manager and needed to have internet access.  Not only that, but the assistant manager basically needed to have all of the crud that was in the profile of the internet-disabled account.  I logged on as administrator on that computer, and using my computer>properties>advanced>profiles>copy to... I copied the internet-disabled account's profile to the new user's account.  The problem is that the internet-disabling GPO is still in force!  This is after several attempts to use gpupdate, log out/log in, restart the computer, etc.  Using the group policy management console to find group policy results on that account, it says that the policy is updated with the correct one, but the proxy server settings are still set and grayed-out.  I have even moved the user account to different ou's and refreshing... nothing...  Am I missing something?!?
0
Comment
Question by:Zach_Pearce
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 48

Assisted Solution

by:Jay_Jay70
Jay_Jay70 earned 125 total points
ID: 17159375
i dont think you are :) unfortunately this is something that i have battled with over the last little while, when you copy a profile that has settings enforced, group policy doesnt update from there on in...

eg i had a forced background, if i copy a profile over, i can no longer force the background with GPO unless i compltelely flush the registry of all old entries...

due to this downfall i now dont do profile copying on domain accounts
0
 
LVL 3

Accepted Solution

by:
artthegeek earned 125 total points
ID: 17160235
Some suggestions and questions:
1st, verify that the user has full permissions to the profile folder & force inheritance.

I assume that the GPO is attached to an OU containing the user, not the pc acount?
Do you think that the Group Policies have replicated to all DC's yet?  (check the GPO on the other Domain Controllers).  If not, there's some troubleshooting steps we can go through.


A quick check using the RSoP snap-in may help you to verify that the GPO is reaching the PC*,

Also - One quick test would be to give the user "deny" permissions to the GPO object itself (make sure the GPO permissions have replicated 1st).


*http://support.microsoft.com/default.aspx?scid=kb;en-us;323276

Let me know if any of this helps!
0

Featured Post

U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Finding and deleting duplicate (picture) files can be a time consuming task. My wife and I, our three kids and their families all share one dilemma: Managing our pictures. Between desktops, laptops, phones, tablets, and cameras; over the last decade…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question