Link to home
Create AccountLog in
Avatar of Jason210
Jason210Flag for Sweden

asked on

Active Directory Problem Windows Server 2008

A vague title for a vague problem.

We're having numerous issues with a group of accounts within specific OUs. The OUs within a parent OU and users accounts withn these are not working properly. There are no special group policies applied to the parent OU, but the OUs within it have two policies applied: a log on script and a folder redirection. These GPOs are almost identicial to GPOs used on other OUs throughout the organisation and have we had no problems with them.

Amongst the problems we are having with the accounts are:

No printer getting deployed (GPO higher in AD)
Roaming Profiles not getting updated properly (copying of profiles to server on log off breaks off part way through leaving only a few files on the server)
GPOs not working properly.
Third party software that retrieves information from AD not working properly

I've tried moving the accounts to a GPO free container and it didn't make any difference. The problem with this is that I don't know where to begin looking for problems, or what diagnostic tests I can do.

Any ideas?

Avatar of moon_blue69
moon_blue69

Hi

How about the Default domain policy? The GP are applied in SDOU, site, domain organisational unit  and if there is a conflict the closest one will win. Does the users/user group has read and apply permissions for the Group policy you want to get applied. Sounds like a permission problem.
ASKER CERTIFIED SOLUTION
Avatar of Renato Montenegro Rustici
Renato Montenegro Rustici
Flag of Brazil image

Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
See answer
SOLUTION
Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
make sure the GP is linked to the OU you are working on
Avatar of Jason210

ASKER

Thanks. It could be a logic issue, but I think the problem may related to the fact that I have recycled some user groups and accounts on AD, instead of deleting and creating from new. We have a high turnover of users, you see.

I'm going to test this next week.