Link to home
Start Free TrialLog in
Avatar of quickslvr
quickslvrFlag for Switzerland

asked on

GPO not working

i have created various GPO`s,but i have to admit not a single one is working.

a drive mapping GPO is set,not working.

two software GPO are set, not working either!

i tried with gpupdate /force, no way! this is going to freak me out.

any advice pls?
Avatar of Darius Ghassem
Darius Ghassem
Flag of United States of America image

How are you applying the GPOs? Are you applying them to the proper OU or container where the computer and user objects are located?

Run ROSP to view the GPO being applied
Can you run an RSoP report from GPMC and post the results here

User generated image
Thanks

Mike
Or, run

gpresult /h c:\results.html

Open in new window


on a computer in question. Check the results file to see if your computers even see the GPOs to be applied.
Are you blocking inheritance at any of your OUs?
Avatar of quickslvr

ASKER

the GPO are applying to a OU named clients.
So what settings are exactly being set on the GPOs

so for example if they are computer settings are the objects in that OU computers or users?

Just making sure the right settings are being applied

Thanks

Mike
Your policy is not even being applied at the OU. Do you have it link enabled?
Or where do you have it link too
it is linked to the OU clients
ok,i found the following:

 The following GPOs were not applied because they were filtered out:

Drive Mapping GPO
            Filtering:  Not Applied (Empty)

I assume that this is a user GPO and i have to bind this GPO to a user group to make it work. prior,i linked it to the clients OU

is that correct?
SOLUTION
Avatar of motnahp00
motnahp00
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
domain users then.right?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
pls check here: is this correct?
targetgr.png
if i do a RSOP, theres error. message is:

"the application was applied due to...it was in language neutral"

but nothing has been installed
Looks correct to me.
You are configuring item-level targeting.

Left click on your GPO from GPMC. Click the scope tab, at the bottom for security filtering, what do you see?
here we go:
scope.png
That looks like it's set up correctly to me. Though, since the link is in a computer group, it's not going to apply user settings. I think that's why you're getting the problem with it showing empty. You need to link it to a specific user group.
What is in Clients?
in the OU clients are all the computers of the domain.

so i link the GPO to the domain users (security) group?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
No, not a security group, an OU housing the users you would like to apply this GPO to.
look here, that GPO allows me only to choose computer or user groups: i dont really have a choice.
pol1.png
pol2.png
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
look here, i can apply it only to user or computer GROUPS NOT OUs.
drive1.png
drive2.png
drive3.png
Where are you linking this GPO is the question?
once again: the domain users group
You can NOT link to the domain users. You are giving permission to apply the policy to anyone that is the Domain User group but this does NOT link the policy to the Domain Container, Default Domain Controller Container, etc
yess,but it doesnt give me even the choice. it has to be either as user or computer group
Where? You are adding the Security Filtering which is GPO permissions. You aren't adding the GPO to a OU.
here,ps see attachment.

item-level targeting is set to a security group,in tis case the domain users
xxx.png
xxxx.png
ok,that one is working meantime.

i had to set some registry key which delays the net logon,that worked
Is things working now?
drive map GPO,yes

software GPO,no
Software GPO are you applying to a Computer Configuration or User Configuration? What OU are you linking too?
Computer Configuration AND linking to the OU clients.
OU clients hold computers?
YES
How did you get the drive mapping GPO to work?
user configuration,then item level targeting to domain computers. created an OU with the computers inside and then i linked it to that OU
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ok,from what i`ve found it looks like the MSI packages are not properly created.
those freeware tools do,for some reason,not properly convert. thats probably the "price" one pays by using freeware.

i tried with http://www.advancedinstaller.com/  and it works now