Solved

GPO problems with server after 2008 migration

Posted on 2010-11-11
5
1,206 Views
Last Modified: 2012-05-10
We've recently migrated from 2003 SBS to 2008 SBS.

All GPOs are working just fine on every client computer. There's this member server though which was ok until we demoted the 2003 server.  Folder redirection GPO is not applying on the server for no user (shows as Filtering:  Denied (Security) on gpresult)

Not only that, there's another GPO which is not even showing as applied nor filtered on gpresult.
Both GPOS apply correctly on any other machine on the domain. I just moved the server to the SBSservers OU without any result.

Another strange thing is on gprsult output information about the computer or user are not showing (name, ou, etc) . See bellow.

Have no clue why this is happening and would really appreciate any help.
Thanks a lot.

Diego

Heres the gpuresult output:


COMPUTER SETTINGS
--------------

    Last time Group Policy was applied: 11/10/2010 at 9:57:29 PM
    Group Policy was applied from:      CSA1.domain.local
    Group Policy slow link threshold:   500 kbps
    Domain Name:                        DOMAIN
    Domain Type:                        Windows 2000


    Applied Group Policy Objects
    -----------------------------
        Local Group Policy

    The computer is a part of the following security groups
    -------------------------------------------------------
        BUILTIN\Administrators
        Everyone
        NT AUTHORITY\Authenticated Users


USER SETTINGS
--------------

    Last time Group Policy was applied: 11/10/2010 at 9:57:29 PM
    Group Policy was applied from:      CSA1.domain.local
    Group Policy slow link threshold:   500 kbps
    Domain Name:                        DOMAIN
    Domain Type:                        Windows 2000

    Applied Group Policy Objects
    -----------------------------
        Windows SBS User Policy
        Windows SBS CSE Policy
        Default Domain Policy

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Small Business Server Folder Redirection Policy
            Filtering:  Denied (Security)

        Local Group Policy
            Filtering:  Not Applied (Empty)

        DISABLE WINDOWS FIREWALL
            Filtering:  Denied (WMI Filter)

        Update Services Common Settings Policy
            Filtering:  Not Applied (Empty)

    The user is a part of the following security groups
    ---------------------------------------------------
        Domain Users
        Everyone
        Remote Desktop Users
        BUILTIN\Users
        REMOTE INTERACTIVE LOGON
        NT AUTHORITY\INTERACTIVE
        NT AUTHORITY\Authenticated Users
        This Organization
        LOCAL
        Windows SBS Fax Users
        Windows SBS SharePoint_MembersGroup
        Windows SBS Link Users
        Windows SBS Remote Web Workplace Users

0
Comment
Question by:reliantcorp
  • 4
5 Comments
 
LVL 3

Expert Comment

by:eviljester
ID: 34117282
Hi,
I'm suprised that the member server is not a member of 'domain computers'. On the GP policy itself, what groups are set for the policy to apply to?
0
 

Author Comment

by:reliantcorp
ID: 34118147

Well, just checked on aduc an the server is member of domain computers. Doesnt show as a member of that group on gpresult output.

The GPOs scopes are "authenticated users" for the logon scripts GPO and "windows SBS Folder redirection Accounts" group for the folder redirection policy.

I disjoined the server from the domain, restarted a few times, rjoined and nothing happened.
Also deleted all the profiles.

Now I run gpresult and get "the user does not have RSOP data" ?!

Im totally out of ideas.

Please, help.
0
 

Author Comment

by:reliantcorp
ID: 34118162
No results with rsop.msc either. It says that the possible reason is because computer and user policies might have not been not processed, an thats absolutely whats happening and I dont know why.

So now no single GPO is being applied.
0
 

Accepted Solution

by:
reliantcorp earned 0 total points
ID: 34118303

Solved.

The old server was the only DNS server listed on this machine. Changed it to the new SBS and everythings now fine.
0
 

Author Closing Comment

by:reliantcorp
ID: 34143585
Cause Ive found the problem.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I’m often asked about newer and larger USB drives connected to SBS2008 and 2011 failing Windows Server Backup vs the older USB drives not failing. As disk space continues to grow and drive technology change SBS2008 and some SBS2011 end up with the f…
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now