Active Directory Problem Windows Server 2008

Posted on 2011-10-03
Last Modified: 2012-05-12
A vague title for a vague problem.

We're having numerous issues with a group of accounts within specific OUs. The OUs within a parent OU and users accounts withn these are not working properly. There are no special group policies applied to the parent OU, but the OUs within it have two policies applied: a log on script and a folder redirection. These GPOs are almost identicial to GPOs used on other OUs throughout the organisation and have we had no problems with them.

Amongst the problems we are having with the accounts are:

No printer getting deployed (GPO higher in AD)
Roaming Profiles not getting updated properly (copying of profiles to server on log off breaks off part way through leaving only a few files on the server)
GPOs not working properly.
Third party software that retrieves information from AD not working properly

I've tried moving the accounts to a GPO free container and it didn't make any difference. The problem with this is that I don't know where to begin looking for problems, or what diagnostic tests I can do.

Any ideas?

Question by:Jason210
    LVL 10

    Expert Comment


    How about the Default domain policy? The GP are applied in SDOU, site, domain organisational unit  and if there is a conflict the closest one will win. Does the users/user group has read and apply permissions for the Group policy you want to get applied. Sounds like a permission problem.
    LVL 11

    Accepted Solution

    Use this tools:

    1) Group Policy Management console /  Group Policy Results
    2) Event Viewer / Application Log (where the gpo is to be applied)
    3) gpupdate or gpupdate /force (run where the gpo is to be applied)

    You can debug most GPO issue using this tools.
    LVL 11

    Assisted Solution

    by:Renato Montenegro Rustice
    I would follow this script:

    1) Run the gpupdate /force in the target machine
    2) Check for erros in the Event Viewer (Source=SceCli)
    3) If you found errors, fix them.
    4) If no errors, probably you have a logic issue. Use GPMC to run remote queries to the target and see in what order the GPOs are being consumed and what are the resultant settings.
    5) If you change anything in any policy, force a gpupdate and evaluate the results again.
    LVL 1

    Expert Comment

    make sure the GP is linked to the OU you are working on
    LVL 11

    Author Closing Comment

    Thanks. It could be a logic issue, but I think the problem may related to the fact that I have recycled some user groups and accounts on AD, instead of deleting and creating from new. We have a high turnover of users, you see.

    I'm going to test this next week.

    Featured Post

    What Should I Do With This Threat Intelligence?

    Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

    Join & Write a Comment

    So many times I have seen the words written in a question "if only I could show you" or " I know how hard it is for you since you can't see it" in any zone. That has inspired me to write about this tool in windows 7 called "Problem Steps Recorder…
    If you get continual lockouts after changing your Active Directory password, there are several possible reasons.  Two of the most common are using other devices to access your email and stored passwords in the credential manager of windows.
    This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
    This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum editing capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now