WmHenryH
asked on
Proxy setting in group policy
We're running Windows 2K server as the domain controller and we're having a problem with the proxy settings getting set (occassioaly) by a group policy but I can't locate the correct GP setting. If I go to any or all the group policies and look under User configuration, windows settings, Internet explorer maintenance, connections proxy settings I see the proxy settings we don't want to use (we don't want any) but it's grayed out and I don't know where it's being ingerited from. How do I resolve this issue?
ASKER
SkyKing,
Thanks I will try this and get back to you.
Thanks I will try this and get back to you.
ASKER
Thanks, I ran GPRESULT /z and got the following which shows the HTTP Prox Server, IP address and some ports. It doesn't say where it's getting this informaion except that the default domain policy and the DST Registry Update and Refresh are the applied group policy objects. I looked through both these policies and the deault domain policy under user settings and internet connections proxy server has these addresses that are grayed out and I can't find where they are coming from. The DST registry Update policy has no addresses under the proxy settings (not even grayed out ones) What don't I understand here? If I look at a user's control panel, internet settings, connection lan settings, there is a yellow band saying some settings are managed by your system administrator.
Thanks again for your help
Thanks again for your help
Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001
Created On 7/22/2009 at 11:22:55 AM
RSOP results for LCS\RAnsel on LAB-19 : Logging Mode
-----------------------------------------------------
OS Type: Microsoft Windows XP Professional
OS Configuration: Member Workstation
OS Version: 5.1.2600
Domain Name: LCS
Domain Type: Windows 2000
Site Name: Default-First-Site-Name
Roaming Profile:
Local Profile: C:\Documents and Settings\RAnsel
Connected over a slow link?: No
COMPUTER SETTINGS
------------------
CN=LAB-19,CN=Computers,DC=lancasterchristian,DC=com
Last time Group Policy was applied: 7/22/2009 at 10:38:26 AM
Group Policy was applied from: LCS-Server.lancasterchristian.com
Group Policy slow link threshold: 500 kbps
Applied Group Policy Objects
-----------------------------
Default Domain Policy
DST Registry Update and Refresh
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Staff Group Policy Object
Filtering: Not Applied (Empty)
Faculty Group Policy Object
Filtering: Not Applied (Empty)
test
Filtering: Not Applied (Empty)
Local Group Policy
Filtering: Not Applied (Empty)
Student Group Policy Object
Filtering: Not Applied (Empty)
The computer is a part of the following security groups:
--------------------------------------------------------
BUILTIN\Administrators
Everyone
Debugger Users
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
LAB-19$
Domain Computers
Resultant Set Of Policies for Computer:
----------------------------------------
Software Installations
----------------------
N/A
Startup Scripts
---------------
GPO: DST Registry Update and Refresh
Name: DST2007Update_Win2k.cmd
Parameters:
LastExecuted: 7:19:42 AM
Shutdown Scripts
----------------
N/A
Account Policies
----------------
GPO: Default Domain Policy
Policy: MinimumPasswordAge
Computer Setting: N/A
GPO: Default Domain Policy
Policy: PasswordHistorySize
Computer Setting: 1
GPO: Default Domain Policy
Policy: MinimumPasswordLength
Computer Setting: N/A
GPO: Default Domain Policy
Policy: LockoutBadCount
Computer Setting: N/A
GPO: Default Domain Policy
Policy: MaximumPasswordAge
Computer Setting: 42
Audit Policy
------------
N/A
User Rights
-----------
N/A
Security Options
----------------
GPO: Default Domain Policy
Policy: RequireLogonToChangePassword
Computer Setting: Not Enabled
GPO: Default Domain Policy
Policy: PasswordComplexity
Computer Setting: Not Enabled
GPO: Default Domain Policy
Policy: ForceLogoffWhenHourExpire
Computer Setting: Not Enabled
GPO: Default Domain Policy
Policy: ClearTextPassword
Computer Setting: Not Enabled
Event Log Settings
------------------
N/A
Restricted Groups
-----------------
N/A
System Services
---------------
N/A
Registry Settings
-----------------
N/A
File System Settings
--------------------
N/A
Public Key Policies
-------------------
N/A
Administrative Templates
------------------------
GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
State: Enabled
USER SETTINGS
--------------
CN=Reagan J. Ansel,CN=Users,DC=lancasterchristian,DC=com
Last time Group Policy was applied: 7/22/2009 at 11:21:32 AM
Group Policy was applied from: LCS-Server.lancasterchristian.com
Group Policy slow link threshold: 500 kbps
Applied Group Policy Objects
-----------------------------
Student Group Policy Object
Default Domain Policy
DST Registry Update and Refresh
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Local Group Policy
Filtering: Not Applied (Empty)
The user is a part of the following security groups:
----------------------------------------------------
Domain Users
Everyone
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
LOCAL
Students
Resultant Set Of Policies for User:
------------------------------------
Software Installations
----------------------
N/A
Public Key Policies
-------------------
N/A
Administrative Templates
------------------------
N/A
Folder Redirection
------------------
N/A
Internet Explorer Browser User Interface
----------------------------------------
GPO: Default Domain Policy
Large Animated Bitmap Name: N/A
Large Custom Logo Bitmap Name: N/A
Title BarText: N/A
UserAgent Text: N/A
Delete existing toolbar buttons: No
GPO: Student Group Policy Object
Large Animated Bitmap Name: N/A
Large Custom Logo Bitmap Name: N/A
Title BarText: N/A
UserAgent Text: N/A
Delete existing toolbar buttons: No
Internet Explorer Connection
----------------------------
HTTP Proxy Server: 10.1.3.6:14446
Secure Proxy Server: 10.1.3.6:14446
FTP Proxy Server: 10.1.3.6:14446
Gopher Proxy Server: 10.1.3.6:14446
Socks Proxy Server: 10.1.3.6:14446
Auto Config Enable: No
Enable Proxy: No
Use same Proxy: Yes
HTTP Proxy Server: 10.1.3.6:14444
Secure Proxy Server: 10.1.3.6:14444
FTP Proxy Server: 10.1.3.6:14444
Gopher Proxy Server: 10.1.3.6:14444
Socks Proxy Server: 10.1.3.6:14444
Auto Config Enable: No
Enable Proxy: No
Use same Proxy: Yes
Internet Explorer URLs
----------------------
GPO: Default Domain Policy
Home page URL: N/A
Search page URL: N/A
Online support page URL: N/A
GPO: Student Group Policy Object
Home page URL: N/A
Search page URL: N/A
Online support page URL: N/A
Internet Explorer Security
--------------------------
Always Viewable Sites: N/A
Password Override Enabled: False
Always Viewable Sites: N/A
Password Override Enabled: False
GPO: Default Domain Policy
Import the current Content Ratings Settings: No
Import the current Security Zones Settings: No
Import current Authenticode Security Information: No
Enable trusted publisher lockdown: No
GPO: Student Group Policy Object
Import the current Content Ratings Settings: No
Import the current Security Zones Settings: No
Import current Authenticode Security Information: No
Enable trusted publisher lockdown: No
Internet Explorer Programs
--------------------------
GPO: Default Domain Policy
Import the current Program Settings: No
GPO: Student Group Policy Object
Import the current Program Settings: No
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thank you for your offer, I can't find the source and I appreciate your help. Here's a copy of the file and the snippet copied
Bill
Bill
Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001
Created On 7/23/2009 at 10:42:29 AM
RSOP results for LCS\SRule on RM302-WINXP : Logging Mode
---------------------------------------------------------
OS Type: Microsoft Windows XP Professional
OS Configuration: Member Workstation
OS Version: 5.1.2600
Domain Name: LCS
Domain Type: Windows 2000
Site Name: Default-First-Site-Name
Roaming Profile:
Local Profile: C:\Documents and Settings\SRule
Connected over a slow link?: No
COMPUTER SETTINGS
------------------
CN=RM302-WINXP,CN=Computers,DC=lancasterchristian,DC=com
Last time Group Policy was applied: 7/23/2009 at 10:36:33 AM
Group Policy was applied from: LCS-Server.lancasterchristian.com
Group Policy slow link threshold: 500 kbps
Applied Group Policy Objects
-----------------------------
Default Domain Policy
DST Registry Update and Refresh
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Staff Group Policy Object
Filtering: Not Applied (Empty)
Faculty Group Policy Object
Filtering: Not Applied (Empty)
test
Filtering: Not Applied (Empty)
Local Group Policy
Filtering: Not Applied (Empty)
Student Group Policy Object
Filtering: Not Applied (Empty)
The computer is a part of the following security groups:
--------------------------------------------------------
BUILTIN\Administrators
Everyone
Debugger Users
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
RM302-WINXP$
Domain Computers
Resultant Set Of Policies for Computer:
----------------------------------------
Software Installations
----------------------
N/A
Startup Scripts
---------------
GPO: DST Registry Update and Refresh
Name: DST2007Update_Win2k.cmd
Parameters:
LastExecuted: 5:46:45 PM
Shutdown Scripts
----------------
N/A
Account Policies
----------------
GPO: Default Domain Policy
Policy: MinimumPasswordAge
Computer Setting: N/A
GPO: Default Domain Policy
Policy: PasswordHistorySize
Computer Setting: 1
GPO: Default Domain Policy
Policy: MinimumPasswordLength
Computer Setting: N/A
GPO: Default Domain Policy
Policy: LockoutBadCount
Computer Setting: N/A
GPO: Default Domain Policy
Policy: MaximumPasswordAge
Computer Setting: 42
Audit Policy
------------
N/A
User Rights
-----------
N/A
Security Options
----------------
GPO: Default Domain Policy
Policy: RequireLogonToChangePassword
Computer Setting: Not Enabled
GPO: Default Domain Policy
Policy: PasswordComplexity
Computer Setting: Not Enabled
GPO: Default Domain Policy
Policy: ForceLogoffWhenHourExpire
Computer Setting: Not Enabled
GPO: Default Domain Policy
Policy: ClearTextPassword
Computer Setting: Not Enabled
Event Log Settings
------------------
N/A
Restricted Groups
-----------------
N/A
System Services
---------------
N/A
Registry Settings
-----------------
N/A
File System Settings
--------------------
N/A
Public Key Policies
-------------------
N/A
Administrative Templates
------------------------
GPO: Default Domain Policy
Setting: Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
State: Enabled
USER SETTINGS
--------------
CN=SRule,CN=Users,DC=lancasterchristian,DC=com
Last time Group Policy was applied: 7/23/2009 at 10:08:16 AM
Group Policy was applied from: LCS-Server.lancasterchristian.com
Group Policy slow link threshold: 500 kbps
Applied Group Policy Objects
-----------------------------
Default Domain Policy
DST Registry Update and Refresh
Local Group Policy
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Staff Group Policy Object
Filtering: Denied (Security)
Student Group Policy Object
Filtering: Denied (Security)
Faculty Group Policy Object
Filtering: Denied (Security)
The user is a part of the following security groups:
----------------------------------------------------
Domain Users
Everyone
Debugger Users
BUILTIN\Administrators
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
LOCAL
teststudentgroup
Group Policy Creator Owners
Domain Admins
Schema Admins
Enterprise Admins
Resultant Set Of Policies for User:
------------------------------------
Software Installations
----------------------
N/A
Public Key Policies
-------------------
N/A
Administrative Templates
------------------------
N/A
Folder Redirection
------------------
N/A
Internet Explorer Browser User Interface
----------------------------------------
GPO: Default Domain Policy
Large Animated Bitmap Name: N/A
Large Custom Logo Bitmap Name: N/A
Title BarText: N/A
UserAgent Text: N/A
Delete existing toolbar buttons: No
Internet Explorer Connection
----------------------------
HTTP Proxy Server: 10.1.3.6:14446
Secure Proxy Server: N/A
FTP Proxy Server: N/A
Gopher Proxy Server: N/A
Socks Proxy Server: N/A
Auto Config Enable: No
Enable Proxy: Yes
Use same Proxy: Yes
HTTP Proxy Server: 10.1.3.6:14446
Secure Proxy Server: 10.1.3.6:14446
FTP Proxy Server: 10.1.3.6:14446
Gopher Proxy Server: 10.1.3.6:14446
Socks Proxy Server: 10.1.3.6:14446
Auto Config Enable: No
Enable Proxy: No
Use same Proxy: Yes
Internet Explorer URLs
----------------------
GPO: Default Domain Policy
Home page URL: N/A
Search page URL: N/A
Online support page URL: N/A
Internet Explorer Security
--------------------------
Always Viewable Sites: N/A
Password Override Enabled: False
Always Viewable Sites: N/A
Password Override Enabled: False
GPO: Default Domain Policy
Import the current Content Ratings Settings: No
Import the current Security Zones Settings: No
Import current Authenticode Security Information: No
Enable trusted publisher lockdown: No
Internet Explorer Programs
--------------------------
GPO: Default Domain Policy
Import the current Program Settings: No
GP.txt
ASKER
After editing all the policy files that contained connection settings of the IP address and ports for Proxy server the situation has improved in that sometimes the yellow band stating some setting are controlled by the administrator and sometimes the Proxy settings and IP address shows up on the control panel but is grayed out. I have no idea where these grayed out settings are coming from.
ASKER
No solution was ever found
It sounds like you may have a domain controller that is not getting replication updates from the active directory. If you are on a small network or only have a single domain controller this is unlikley, so I will assume that replication is working.
You have two options.
1. Find out where it is inheriting from and get rid of the settings. You can do this by getting a Resultant Set of Policy report using GPRESULT.
http://www.windowsnetworking.com/articles_tutorials/Resultant-Set-Policy-Queries-GPRESULT.html
This will tell you where policies are being set.
2. If you don't need to inherit any settings from the parent GPOs you could set the Block Inheritance option on the OU containing the affected machines. This would block all policies not just the proxy settings from being inherited so this option is most likley not a good idea.