Solved

GPO problems with server after 2008 migration

Posted on 2010-11-11
5
1,213 Views
Last Modified: 2012-05-10
We've recently migrated from 2003 SBS to 2008 SBS.

All GPOs are working just fine on every client computer. There's this member server though which was ok until we demoted the 2003 server.  Folder redirection GPO is not applying on the server for no user (shows as Filtering:  Denied (Security) on gpresult)

Not only that, there's another GPO which is not even showing as applied nor filtered on gpresult.
Both GPOS apply correctly on any other machine on the domain. I just moved the server to the SBSservers OU without any result.

Another strange thing is on gprsult output information about the computer or user are not showing (name, ou, etc) . See bellow.

Have no clue why this is happening and would really appreciate any help.
Thanks a lot.

Diego

Heres the gpuresult output:


COMPUTER SETTINGS
--------------

    Last time Group Policy was applied: 11/10/2010 at 9:57:29 PM
    Group Policy was applied from:      CSA1.domain.local
    Group Policy slow link threshold:   500 kbps
    Domain Name:                        DOMAIN
    Domain Type:                        Windows 2000


    Applied Group Policy Objects
    -----------------------------
        Local Group Policy

    The computer is a part of the following security groups
    -------------------------------------------------------
        BUILTIN\Administrators
        Everyone
        NT AUTHORITY\Authenticated Users


USER SETTINGS
--------------

    Last time Group Policy was applied: 11/10/2010 at 9:57:29 PM
    Group Policy was applied from:      CSA1.domain.local
    Group Policy slow link threshold:   500 kbps
    Domain Name:                        DOMAIN
    Domain Type:                        Windows 2000

    Applied Group Policy Objects
    -----------------------------
        Windows SBS User Policy
        Windows SBS CSE Policy
        Default Domain Policy

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Small Business Server Folder Redirection Policy
            Filtering:  Denied (Security)

        Local Group Policy
            Filtering:  Not Applied (Empty)

        DISABLE WINDOWS FIREWALL
            Filtering:  Denied (WMI Filter)

        Update Services Common Settings Policy
            Filtering:  Not Applied (Empty)

    The user is a part of the following security groups
    ---------------------------------------------------
        Domain Users
        Everyone
        Remote Desktop Users
        BUILTIN\Users
        REMOTE INTERACTIVE LOGON
        NT AUTHORITY\INTERACTIVE
        NT AUTHORITY\Authenticated Users
        This Organization
        LOCAL
        Windows SBS Fax Users
        Windows SBS SharePoint_MembersGroup
        Windows SBS Link Users
        Windows SBS Remote Web Workplace Users

0
Comment
Question by:reliantcorp
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 
LVL 3

Expert Comment

by:eviljester
ID: 34117282
Hi,
I'm suprised that the member server is not a member of 'domain computers'. On the GP policy itself, what groups are set for the policy to apply to?
0
 

Author Comment

by:reliantcorp
ID: 34118147

Well, just checked on aduc an the server is member of domain computers. Doesnt show as a member of that group on gpresult output.

The GPOs scopes are "authenticated users" for the logon scripts GPO and "windows SBS Folder redirection Accounts" group for the folder redirection policy.

I disjoined the server from the domain, restarted a few times, rjoined and nothing happened.
Also deleted all the profiles.

Now I run gpresult and get "the user does not have RSOP data" ?!

Im totally out of ideas.

Please, help.
0
 

Author Comment

by:reliantcorp
ID: 34118162
No results with rsop.msc either. It says that the possible reason is because computer and user policies might have not been not processed, an thats absolutely whats happening and I dont know why.

So now no single GPO is being applied.
0
 

Accepted Solution

by:
reliantcorp earned 0 total points
ID: 34118303

Solved.

The old server was the only DNS server listed on this machine. Changed it to the new SBS and everythings now fine.
0
 

Author Closing Comment

by:reliantcorp
ID: 34143585
Cause Ive found the problem.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Issue: One Windows 2008 R2 64bit server on the network unable to connect to a buffalo Device (Linkstation) with firmware version 1.56. There are a total of four servers on the network this being one of them. Troubleshooting Steps: Connect via h…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question