Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Some Clients not picking up a Change in Group Policy

Posted on 2011-09-08
10
Medium Priority
?
1,305 Views
Last Modified: 2012-05-12
Hi,

I have made some changes to the Default Domain Group Policy and half of the Servers and Clients in the Domain have picked up the Changes but the other half are still using the previous settings. I have tried doing a Gpupdate /force on the machines but still not getting anywhere.

0
Comment
Question by:Contigo1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 4
10 Comments
 
LVL 12

Expert Comment

by:josika
ID: 36502718
What policy setting did you change/configure?  Is the OS that the changes are not applying to common?  Meaning, are they all Windows 2003 that have not accepted the changes?
0
 
LVL 1

Author Comment

by:Contigo1
ID: 36502848
No they are a mixture of 2003 and 2008R2 and I have changed the Windows update settings to point to our new WSUS server. The Servers that are not picking up the changes are still pointing to the old WSUS server which is now offline.
0
 
LVL 12

Expert Comment

by:josika
ID: 36503154
Do you have group policy inheritance blocked on the OUs where the affected servers lie?  Have you set any security or WMI filtering on the Default Domain Policy?
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 1

Author Comment

by:Contigo1
ID: 36503408
There is no WMI Filtering and Inheritance is not blocked to theOU's. The Servers are all in the Computers OU in AD. I have not set any Security on the Domain Policy either
0
 
LVL 12

Expert Comment

by:josika
ID: 36503488
Anything in the Event Viewer on the affected computers after running 'gpupdate /force'?
0
 
LVL 1

Author Comment

by:Contigo1
ID: 36503533
Nope the only thing I found the refers to Group Policy is and event that says:

Security policy in the Group policy objects has been applied successfully.
0
 
LVL 12

Expert Comment

by:josika
ID: 36504386
I would run RSOP on the servers and make sure the servers are seeing the policies.

Is it possible the WSUS server configuration is set in the local group policy on the servers?

Also, I would move the servers out of the default Computers container and into another OU.
0
 
LVL 1

Author Comment

by:Contigo1
ID: 36508742
I have looked at the local policy and everything is set to not configured. I have also done an RSOP and it is saying it is picking up the old settings still. How do I check what Policy it is getting the settings from? Also Could it be a problem with the version number?
0
 
LVL 1

Accepted Solution

by:
Contigo1 earned 0 total points
ID: 36536140
The problem was that the File Replication Service was not working which was meaning the AD and the Sysvol where getting out of sync. So when I made changes to the group policy it was not being replicated throughout the Domain. I solved this by what is listed in this articlehttp://support.microsoft.com/kb/290762

I then left the FRS service to get back into Sync. When It was back in sync I still couldnt get it to make the changes I needed so I changed all the upodate settings back to not configured in the GPO and then left it to sync back up with all the machines. Once this was done I changed all the update settings back to the required settings.
0
 
LVL 1

Author Closing Comment

by:Contigo1
ID: 36558745
This is what solved my problem
0

Featured Post

Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question