Solved

GPO not being applied

Posted on 2011-03-01
2
341 Views
Last Modified: 2012-05-11
I used to use a GPO to add a security group of users to IIS_WPG local group in windows server 2003. Now I have 2008 and this group changed to the name of IIS_IUSRS. I have 4 new servers builded and joined to the domain (2008) all 4 are in the same OU and the GPO is being applied to this OU.
The problem is that just 1 server out of 4 is getting this group of users being added to the IIS_IUSRS group, and the other 3 not.

What could be the problem?

I rejoined the machines to the domain, group policies are being applied no correctly as per event viewer on all the machines.

Can you please point me in the right direction on where the problem can be?

Thanks a mil,
0
Comment
Question by:M7K
2 Comments
 
LVL 20

Expert Comment

by:woolnoir
Comment Utility
Any event log entries which could highlight a problem in the machines not receiving the policy ? have you tried forcing policy application with the GPUPDATE ?
0
 
LVL 11

Accepted Solution

by:
Tasmant earned 500 total points
Comment Utility
I don't really understand your need. IIS_IUSRS is a built-in group for IIS to be executed. What is the interest to add some groups or users to this special group?

Any way, to troubleshoot Group Policy issues on 2008, you can activate logging in the event viewer for the service log/Microsoft/Windows/Group Policy: activate logging.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

My last post dealt with using group policy preferences to set file associations, a very handy usage for a GPP. Today I am going to share another cool GPP trick, this may be a specific scenario but I run into these situations frequently in my activit…
Do you have users whose passwords are expiring and they are constantly calling you?  Well I sure did and needed a way to put an end to this.  We have a lot of remote users which would not be notified that their passwords were expiring since they wer…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now