blocked som

I have an enforced group policy applied to a site.
Servers in an OU in that are in that site have blocked inheritance on.

When running GPRW for the server, it's not showing as an allowed GPO for computer configuration. It's showing in the denied section, reason "Blocked SOM"

What's going on?
antoniokingAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Nick RhodeIT DirectorCommented:
You wouldn't by chance have block policy inheritance checked would you?
1
antoniokingAuthor Commented:
Yes, but the policy is enforced.
Does policy enforcement not apply to sites?
0
Nick RhodeIT DirectorCommented:
Depends on how its configured.  It is probably being blocked on the domain level hence why you see denied.  Try and get the results of the GP to narrow down the issue.

Couple methods are here:  http://social.technet.microsoft.com/Forums/windowsserver/en-US/c8d89dfa-1138-4ebc-84af-bad1041dd984/default-domian-policy-is-not-getting-applied-getting-error-blocked-som

To get the results of the GP and possibly why or where the problem is.
1
The Ultimate Tool Kit for Technolgy Solution Provi

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy for valuable how-to assets including sample agreements, checklists, flowcharts, and more!

dlbenson1979Commented:
If you are unsure of the type of block you have up, just create another link to the GPO within the OU that has blocked inheritance. It will get blocked at site level, but pass through at OU level.
1

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
antoniokingAuthor Commented:
The server is in an OU with blocked inheritance switched on.

The GPO is enforced and is applied to the same site the server is in.

The denied reason is 'Blocked SOM'
0
antoniokingAuthor Commented:
The only OU in my infrastructure with blocked inheritance is the one the server is in
0
dlbenson1979Commented:
What happens to you put a gpo link of the enforced policy into the OU container with blocked inheritance. My guess is that it would work from there.
0
antoniokingAuthor Commented:
Yep, it works.

But I would like  to get to the bottom of why it's not applying from the site.
0
antoniokingAuthor Commented:
Ok, I don't know how. Bit after adding the gpo to the OU and removing it, it now shows up as an applied policy in GPRW!

Bizarre!
1
dlbenson1979Commented:
Active directory at it's finest ;)
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.