?
Solved

Some Clients not picking up a Change in Group Policy

Posted on 2011-09-08
10
Medium Priority
?
1,375 Views
Last Modified: 2012-05-12
Hi,

I have made some changes to the Default Domain Group Policy and half of the Servers and Clients in the Domain have picked up the Changes but the other half are still using the previous settings. I have tried doing a Gpupdate /force on the machines but still not getting anywhere.

0
Comment
Question by:Contigo1
  • 6
  • 4
10 Comments
 
LVL 12

Expert Comment

by:josika
ID: 36502718
What policy setting did you change/configure?  Is the OS that the changes are not applying to common?  Meaning, are they all Windows 2003 that have not accepted the changes?
0
 
LVL 1

Author Comment

by:Contigo1
ID: 36502848
No they are a mixture of 2003 and 2008R2 and I have changed the Windows update settings to point to our new WSUS server. The Servers that are not picking up the changes are still pointing to the old WSUS server which is now offline.
0
 
LVL 12

Expert Comment

by:josika
ID: 36503154
Do you have group policy inheritance blocked on the OUs where the affected servers lie?  Have you set any security or WMI filtering on the Default Domain Policy?
0
Worried about phishing attacks?

90% of attacks start with a phish. It’s critical that IT admins and MSSPs have the right security in place to protect their end users from these phishing attacks. Check out our latest feature brief for tips and tricks to keep your employees off a hackers line!

 
LVL 1

Author Comment

by:Contigo1
ID: 36503408
There is no WMI Filtering and Inheritance is not blocked to theOU's. The Servers are all in the Computers OU in AD. I have not set any Security on the Domain Policy either
0
 
LVL 12

Expert Comment

by:josika
ID: 36503488
Anything in the Event Viewer on the affected computers after running 'gpupdate /force'?
0
 
LVL 1

Author Comment

by:Contigo1
ID: 36503533
Nope the only thing I found the refers to Group Policy is and event that says:

Security policy in the Group policy objects has been applied successfully.
0
 
LVL 12

Expert Comment

by:josika
ID: 36504386
I would run RSOP on the servers and make sure the servers are seeing the policies.

Is it possible the WSUS server configuration is set in the local group policy on the servers?

Also, I would move the servers out of the default Computers container and into another OU.
0
 
LVL 1

Author Comment

by:Contigo1
ID: 36508742
I have looked at the local policy and everything is set to not configured. I have also done an RSOP and it is saying it is picking up the old settings still. How do I check what Policy it is getting the settings from? Also Could it be a problem with the version number?
0
 
LVL 1

Accepted Solution

by:
Contigo1 earned 0 total points
ID: 36536140
The problem was that the File Replication Service was not working which was meaning the AD and the Sysvol where getting out of sync. So when I made changes to the group policy it was not being replicated throughout the Domain. I solved this by what is listed in this articlehttp://support.microsoft.com/kb/290762

I then left the FRS service to get back into Sync. When It was back in sync I still couldnt get it to make the changes I needed so I changed all the upodate settings back to not configured in the GPO and then left it to sync back up with all the machines. Once this was done I changed all the update settings back to the required settings.
0
 
LVL 1

Author Closing Comment

by:Contigo1
ID: 36558745
This is what solved my problem
0

Featured Post

NEW Internet Security Report Now Available!

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out this quarters report on the threats that shook the industry in Q4 2017.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Understanding the various editions available is vital when you decide to purchase Windows Server 2012. You need to have a basic understanding of the features and limitations in each edition in order to make a well-informed decision that best suits …
In this article, we will discuss how you can secure Active Directory using free tools, and how you can choose a safe and secure Active Directory security auditing tool.
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…

569 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question