[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Windows 2008 AD & GPO Issues

Posted on 2012-09-05
9
Medium Priority
?
417 Views
Last Modified: 2012-09-19
I am putting the following down to our upgrade from 2003 AD to 2008 AD, which i am surprised at....  I am trying to import the new 2010 exchange certs.

So, we have an OU with 'block policy inheritance' set but this policy (when running the GPO wizard) is clearly picking up policies from the Domain root (+ others).  
I do not have any results from the wizard when on 2003 to prove....

I also have another GPO for an RDS that has 'replace' set on loopback processing.  This option is importing the certificates fine but also picking up the root GPO.

Ideas?  Is there major differences with 2008 AD?
How best to import the exch certs?
Does block inheritance work?

Thanks
0
Comment
Question by:CHI-LTD
  • 4
  • 4
9 Comments
 
LVL 22

Assisted Solution

by:Joseph Moody
Joseph Moody earned 1600 total points
ID: 38367483
Are the GPOS being processed enforced? Block inheritance will not block an enforced GPO.
0
 
LVL 1

Author Comment

by:CHI-LTD
ID: 38367518
none of any gpo's are enforced.
0
 
LVL 22

Assisted Solution

by:Joseph Moody
Joseph Moody earned 1600 total points
ID: 38367545
Also. Blocked inheritance only blocks processing for the specific objects in the OU. For example, if you have a computer in an OU and you set blocked inheritance, the user side GPOs will still process.
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 1

Author Comment

by:CHI-LTD
ID: 38367568
I thought it blocked all GPO's under the OU in question?
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 400 total points
ID: 38367649
Login to the machine in question and run rsop.msc. From there you will be able to see exactly what is process on thsi machine based on computer settings and also user settings. This will assist to see what is exactly being applied.

FRom there you can take a look at the GPO's and where they live in the processing.
0
 
LVL 22

Assisted Solution

by:Joseph Moody
Joseph Moody earned 1600 total points
ID: 38367813
Blocked inheritance does block all GPOS from above the OU. If that OU contains computer objects, it will block any computer side configurations from processing.

If a user is in another OU, that user will still receive their policies.
0
 
LVL 1

Author Comment

by:CHI-LTD
ID: 38367910
yes, i have ran the GPO wizard which is showing that the root domain gpo is winning for the computer side of things.   the user settings are being applied as required.
0
 
LVL 22

Assisted Solution

by:Joseph Moody
Joseph Moody earned 1600 total points
ID: 38368402
Can you run "gpresult /h report.htm /f" from a machine and upload the report.htm file?
0
 
LVL 1

Author Comment

by:CHI-LTD
ID: 38368427
I can.

I have a workaround, which was to untick the block inheritance option, which enabled the certificates to be installed and re-blocked.
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here in this article, you will get a step by step guidance on how to restore an Exchange database to a recovery database. Get a brief on Recovery Database and how it can be used to restore Exchange database in this section!
If something goes wrong with Exchange, your IT resources are in trouble.All Exchange server migration processes are not designed to be identical and though migrating email from on-premises Exchange mailbox to Cloud’s Office 365 is relatively simple…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Suggested Courses

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question