GPO problem

Posted on 2007-11-27
Last Modified: 2010-03-17
In my active directory, I have setup an OU called Information Systems
Under Information System, I have an OU called Terminal Servers

I put one of my terminal servers in teh Terminal Servers OU and setup a group policy for that OU to "Hide these specified drives in My Computer"  
 -   User Configuration, Administrative Templates, Windows Explorer

When I log on to the terminal server in the Terminal Servers OU, the drives are not hidden.
If I move the Terminal Servers OU directly under the domain and login, the drives are hidden.

Any ideas why I can't leave the OU as shown below
          Information System
                      Terminal Servers

To make the GPO work, I currently have the OUs set like this..
          Terminal Servers

Question by:Die-Tech
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1
LVL 38

Accepted Solution

Hypercat (Deb) earned 500 total points
ID: 20361067
It sounds like it's probably some kind of inheritance issue with other group policies connected to the Information System OU.  The easiest way to figure out what's going on would be to put the Terminal Servers OU back in the Information Systems OU, then open the GPMC and look at the settings for the TS OU - i.e., from the Settings tab in GPMC rather than by opening the group policy console as though you were going to edit the policy.  This will tell you what setting is being applied and where it's coming from.
LVL 12

Expert Comment

ID: 20361140
Did you link the GPO to that OU? You can also create another GPO and place it in side the OU.
LVL 12

Expert Comment

ID: 20361143
Also might have to use loopback processing.
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

LVL 12

Expert Comment

ID: 20361164
Sorry about the multiple posts, ideas keep comming in. I have spent alot of time with issues like this. We have a kind of complex TS enviorment here. The GPO management tools are a god send. Use the report tool to see what Policys are applied and which one are not. It will also tell you why.

Expert Comment

ID: 20361653
Keep in mind that Group Policy objects are processed according to the following order:

The local Group Policy object (LPGO) is applied.
GPOs linked to sites.
GPOs linked to domains
GPOs linked to organizational units. In the case of nested organizational units, GPOs associated with parent organizational units are processed prior to GPOs associated with child organizational units.

GPO links to a specific site, domain, or organizational unit are applied in reverse sequence based on link order. For example, a GPO with Link Order 1 has highest precedence over other GPOs linked to that container.

In general, the last policy to be applied wins if different GPOs attempt to apply conflicting values.

Using the Group Policy Management console, review the list of GPOs that are applied to each OU, paying close attention to any differences in the "Information System" and "Terminal Servers" OUs.  I would look for any GPOs linked to the "Information System" OU that are set as "enforced", meaning they cannot be overrode by a later GPO.


Author Comment

ID: 20368416
Thanks everyone who posted...
I have to give the points to hypercat... he answered first.

After I moved the Terminal Servers OU back under the Information Systems OU, the policy started working... I'm guessing it was the inheritance issue hypercat mentioned... Moving the OU out and back fixed it.

BTW... I love the GPMC... thanks again hypercat for that suggestion.
LVL 38

Expert Comment

by:Hypercat (Deb)
ID: 20368470
Thanks for the points, and you're welcome - I love it too.  They should've had it back when they first designed GPOs as an upgrade from the old NT group policy way...bit I guess better late than never. And, just a friendly reminder - there are those of us out here (me) who are she's, not he's, regardless of the gender-free online naming.

Author Comment

ID: 20368501
Sorry for showing my inner caveman.... :)
It's nice to see she's who know what they're talking about !!

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question