Solved

GPO is not working after upgrading Active Directory to Windows 2008 R2

Posted on 2010-11-09
2
866 Views
Last Modified: 2012-05-10
Dear All,

I upgrade my Active Directory from windows 2003 to windows 2008 R2, now I have two domain controllers, windows 2008 and windows 2003. The windows 2008 DC have all FSMO roles now.

Almost, everything is working fine except some group policy which they are not applied now.
So I need your help to upgrade the GPO to windows 2008 R2.

Thanks
0
Comment
Question by:Arabsoft_Security
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 27

Expert Comment

by:KenMcF
ID: 34098901
Are you getting any errors?
When you updated the schema did you run adprep /gpprep?

Is it all computers that the GPOs do not work on or just the new 2008 servers?

http://www.petri.co.il/windows-server-2008-adprep.htm
0
 
LVL 24

Accepted Solution

by:
Awinish earned 500 total points
ID: 34099492
Have you run adprep /domainprep /gpprep command while upgrading domain controller to 2k8.

This cmd is required to update permission on GPO,sometime adprep /domainprep is enough but this command requires to be run while upgrading or you can run now.

You can run gpotool.exe & can see the health of GPO's & then you can track with the error in event log.

You can use userenv logging the best way to find the cause for GPO not getting applied.

http://social.technet.microsoft.com/Forums/en/winservergen/thread/224c95bc-e6b3-4b66-82e1-22de625b7dc6

http://blogs.technet.com/b/askds/archive/2008/11/11/understanding-how-to-read-a-userenv-log-part-1.aspx 
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question