?
Solved

group policy

Posted on 2011-02-16
17
Medium Priority
?
309 Views
Last Modified: 2012-05-11
i just made a new group policy for using the wsus server from microsoft.

but the thing is i cannot see those computer in wsus interface.

how do i know if the policy has been applied to the computer
0
Comment
Question by:GCI_SUPPORT
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
17 Comments
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 34911429
Start with from command prompt on a client pc


 Reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
0
 
LVL 11

Expert Comment

by:yelbaglf
ID: 34911464
On a computer set to receive the gpo, run this from cmd prompt:
gpresult /scope computer /r

In the results, verify you see the WSUS GPO under 'Computer Settings' > Applied Group Policy Objects.
0
 

Author Comment

by:GCI_SUPPORT
ID: 34911465
cannot find the key
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 47

Expert Comment

by:Donald Stewart
ID: 34911487
Does clientdiag pass on the clients?

http://download.microsoft.com/download/9/7/6/976d1084-d2fd-45a1-8c27-a467c768d8ef/WSUS%20Client%20Diagnostic%20Tool.EXE


Have you ran gpupdate ?

wuauclt /detectnow on clients to initiate
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 34911497
"cannot find the key "

means that the computer did not yet get the GPO
0
 

Author Comment

by:GCI_SUPPORT
ID: 34911775
i cannot see the policy how can i solve it
0
 
LVL 11

Expert Comment

by:Venugopal N
ID: 34913916
At the client run the GPResult at the command promt and check if the GPO which you assisnged as been reflected there.

Also put the result here for our analys.
0
 

Author Comment

by:GCI_SUPPORT
ID: 34915212
just for information when i put a new policy what i have to do to make it effective

i make client reboot

it is enought
0
 

Author Comment

by:GCI_SUPPORT
ID: 34915572
onfiguration du systŠme d'exploitation : Station de travail membre
Version du systŠme d'exploitation...... : 6.0.6001
Nom du site............................ : Laval
Profil itin‚rant :             N/A
Profil local........................... : C:\Users\dionr.GCINETWORK
Connexion via une liaison lente ? : Non


ParamŠtre de l'ordinateur
--------------------------
    CN=CA-WS12-VST,CN=Computers,DC=GCINETWORK,DC=LOCAL
    Heure de la derniŠre application de la strat‚gie de groupe : 2011-02-17 … 06:41:54
    Strat‚gie de groupe appliqu‚e depuis :      CA-DC1-2K8.GCINETWORK.LOCAL
    Seuil de liaison lente dans la strat‚gie de groupe :   500 kbps
    Nom du domaine.........................ÿ: GCINETWORK
    Type de domaine........................ : Windows 2000

    Objets Strat‚gie de groupe appliqu‚s
    -------------------------------------
        Default Domain Policy
        ACTIVATION SERVICE POUR SOPHOS

    Les objets strat‚gie de groupe n'ont pas ‚t‚ appliqu‚s
    car ils ont ‚t‚ refus‚s
    -----------------------------------------------------------------------------------
        Map Drive
          Filtrage :  Non appliqu‚ (vide)

        Strat‚gie de groupe locale
          Filtrage :  Non appliqu‚ (vide)

    L'ordinateur fait partie des groupes de s‚curit‚ suivants
    ---------------------------------------------------------
        Administrateurs
        Tout le monde
        SophosAdministrator
        SQLServerMSSQLServerADHelperUser$CA-WS12-VST
        SophosUser
        Utilisateurs
        RESEAU
        Utilisateurs authentifi‚s
        Cette organisation
        CA-WS12-VST$
        Ordinateurs du domaine
        Niveau obligatoire systŠme
       

PARAMÔTRES UTILISATEURS
------------------------
    CN=Robert Dion,OU=GLOBAL NETWORK IT,DC=GCINETWORK,DC=LOCAL
    Heure de la derniŠre application de la strat‚gie de groupe : 2011-02-17 … 06:46:11
    Strat‚gie de groupe appliqu‚e depuis :      CA-DC1-2K8.GCINETWORK.LOCAL
    Seuil de liaison lente dans la strat‚gie de groupe :   500 kbps
    Nom du domaineÿ:                        GCINETWORK
    Type de domaine :                        Windows 2000
   
    Objets Strat‚gie de groupe appliqu‚s
    -------------------------------------
        Map Drive

    Les objets strat‚gie de groupe n'ont pas ‚t‚ appliqu‚s
    car ils ont ‚t‚ refus‚s
    -----------------------------------------------------------------------------------
        Default Domain Policy
          Filtrage :  Non appliqu‚ (vide)

        Strat‚gie de groupe locale
          Filtrage :  Non appliqu‚ (vide)

        ACTIVATION SERVICE POUR SOPHOS
          Filtrage :  Non appliqu‚ (vide)

    L'utilisateur fait partie des groupes de s‚curit‚ suivants
    ----------------------------------------------------------
        Utilisateurs du domaine
        Tout le monde
        SophosUser
        Sophos Console Administrators
        Sophos DB Admins
        Sophos Full Administrators
        SophosAdministrator
        Utilisateurs
        Administrateurs
        INTERACTIF
        Utilisateurs authentifi‚s
        Cette organisation
        LOCAL
        VPN SUPPORT GROUP
        Admins du domaine
        GOUDREAU CARGO INTL USER
        SophosAdministrator
        Groupe de r‚plication dont le mot de passe RODC est refus‚
        SophosUser
        Niveau obligatoire ‚lev‚
       
0
 

Author Comment

by:GCI_SUPPORT
ID: 34915655
ok i found what is going wrong

if i put my policy at the bottom of my domain name it works
but if i put it inside a organisonial unit it doesnt work

it is possible to put it in a ou if yes what i have to do
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 34916657
Dont you want your WSUS policy to apply to all your workstations?
0
 

Author Comment

by:GCI_SUPPORT
ID: 34917772
yes
0
 
LVL 47

Accepted Solution

by:
Donald Stewart earned 2000 total points
ID: 34917830
Then why not leave the policy where it was working ? :)
0
 

Author Comment

by:GCI_SUPPORT
ID: 34918464
its what i will do, its working for some computer and some not why
how can i know why some gpo are rejected
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 34918575
Are all your Pc's/Workstations located in the same OU???
0
 

Author Comment

by:GCI_SUPPORT
ID: 34943010
yes
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 34943714
What security filtering is being used on this GPO ?

Normally "Authenticated Users" is all you need
0

Featured Post

NFR key for Veeam Agent for Linux

Veeam is happy to provide a free NFR license for one year.  It allows for the non‑production use and valid for five workstations and two servers. Veeam Agent for Linux is a simple backup tool for your Linux installations, both on‑premises and in the public cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses
Course of the Month12 days, 16 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question