Solved

GPUdate /force

Posted on 2013-06-14
11
635 Views
Last Modified: 2013-07-15
I have about 50 machines so far (actually over 1200 in total) in an OU.  I need a way to run gpupdate /force remotely so I can refresh the policy.  I tried Psexec and although it looks like it works, when I run Group Policy Results the new policy isn't showing up.
0
Comment
Question by:WellingtonIS
  • 3
  • 2
  • 2
  • +3
11 Comments
 
LVL 23

Expert Comment

by:ComputerTechie
ID: 39249642
0
 
LVL 16

Expert Comment

by:cantoris
ID: 39250044
Bear in mind that Gpupdate only reapplies any group policy objects and ensures they're up to date.  It does not check to see if the computer account or user account have recently moved and therefore now come under the influence of a different set of group policies.  Don't let this catch you out!
I'm not sure which OS process governs the workstation discovering the GPO list.  I imagine it's the initial Logon process itself.

PSExec ought to work if you're expecting existing GPOs to have their newest settings deployed to PCs.  What syntax did you use?  The assumption of course is that your AD replication infrastructure is healthy and therefore all the DCs have copies of the updated GPOs.  MS have an excellent new AD Replication Status Tool you can download.

There's also the issue of parts of policy not applying over slow links to think about and whether you've taken into account your security and WMI filtering config, blocked inheritance, loopback processing etc etc!
0
 
LVL 10

Expert Comment

by:Tony Barkdull
ID: 39250472
There should be 2 logins until a new Group Policy is applied, after first, policy is downloaded (after login) and applied after second login. Both can be just a logoff and login again or reboots.
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 4

Expert Comment

by:TechOps07
ID: 39250780
You can use PowerShell to Invoke the Gpupdate command.

Invoke-Command -ComputerName "ComputerName" {gpupdate /force}

You obviously want to create it as a script for the numerous machines.
0
 
LVL 52

Expert Comment

by:Manpreet SIngh Khatra
ID: 39251482
In a way if all machines are restarted they would automatically at next user login GroupPolicy will be updated

- Rancy
0
 

Author Comment

by:WellingtonIS
ID: 39271609
1st:
Bear in mind that Gpupdate only reapplies any group policy objects and ensures they're up to date.  It does not check to see if the computer account or user account have recently moved and therefore now come under the influence of a different set of group policies.  Don't let this catch you out!
I'm not sure which OS process governs the workstation discovering the GPO list.  I imagine it's the initial Logon process itself.

Usually when I do a GPupdate /force via the machine it does fill in the new gpo's I'm seen this myself.
I tried the powershell but that's doesn't seem to be working.
Here's the error
PS C:\> Invoke-Command-wrmdegy01 "wrmdegy01" {gpupdate /force}
The term 'Invoke-Command-wrmdegy01' is not recognized as the name of a cmdlet, function, script file, or operable progr
am. Check the spelling of the name, or if a path was included, verify that the path is correct and try again.
At line:1 char:25
+ Invoke-Command-computername <<<<  "comutername" {gpupdate /force}
    + CategoryInfo          : ObjectNotFound: (Invoke-Command-wrmdegy01:String) [], CommandNotFoundException
    + FullyQualifiedErrorId : CommandNotFoundException
0
 
LVL 23

Expert Comment

by:ComputerTechie
ID: 39271642
I update our machines as needed by using psexec and the following command. Psexec -i -s \\* gpupdate.exe / force

 This works well and when I need one machine I just change the * as needed.

You can get psexec from Microsoft download site.

CT
0
 

Author Comment

by:WellingtonIS
ID: 39271657
Psexec -i -s \\*?  does the star represent everyone on the domain? I can't do that since I'm part of an OU in a bigger domain.  Unless there's someway of designating the OU only.
0
 
LVL 10

Expert Comment

by:Tony Barkdull
ID: 39288359
Check in the Event log for any WMI errors. If you do find them, you will need to run a repair on the WMI subsystem. I'd use option 3 on this page. You will need a CD or an accessible network location with the Install files.
0
 
LVL 16

Accepted Solution

by:
cantoris earned 500 total points
ID: 39288672
Filling in some gaps from above:

Your PowerShell didn't work as you missed a space.  I'll add extras here for clarity:
Invoke-Command   -ComputerName   wrmdegy01   -ScriptBlock   {gpupdate}

BUT, the above will only work if all your PCs have PowerShell 2 or above and are enabled for PSremoting.  If you do have this sort of infrastructure, then there is more PowerShell stuff you can use to get the computers in an OU and pass them all to Invoke-Command.

Server 2012 lets you force a policy refresh against an entire OU natively within GUI tools.

With PSExec, "*" does indeed mean all computers in the domain!
0
 

Author Closing Comment

by:WellingtonIS
ID: 39327466
this worked thanks
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
When you try to extract and to view the contents of a Microsoft Update Standalone Package (MSU) for Windows Vista, you cannot extract the files from the MSU. Here we are going to explain how to extract those hotfix details without using any third pa…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question