troubleshooting Question

Problem with GPO / GPP (drive mapping) when L2 authentication is in place

Avatar of Logica01
Logica01Flag for Czechia asked on
Active DirectoryWindows Server 2008Windows 7
2 Comments1 Solution1607 ViewsLast Modified:
Issue:
We have problem with Drive Mapping (Group Policy Preference, Item level targetting). Drives are not mapped to users after restart of computer.
Tests proved:
- this problem occurs only on ports where L2 authentication (computer certificate) is enabled
- if user login immediately (if there is 10+s delay with logon then disks are mapped properly)
- from GPO logs (compared logs with and without L2auth) is obvious that when computer is connected to switch with L2 auth then, due to delays, user's GPO is applied BEFORE computer GPO ... this I do not understand at all

Details:
If mapped drives are set to Update ... they are in disconnected state after restart (red X) ... but after 20-30s it is possible to see the content (but red X remain)
If mapped drives are set to Replace ... they are not visible after restart

... if user does Logoff/Logon disks are properly mapped

Settings of drive mapping (example of user policy):
Action: Update
Location: DFS folder
Reconnect: Enable
Use first Available: Disabled
Run in logged on user's security context: Yes
Item level targetting: Security Group

(Computer policy)
Always wait for the network at computer startup and logon: Enabled

Here is description of our environment:
DC: W2k8 R2
Clients: Windows 7 x86
L2 Auth: Computer Authentication, MS Supplicant set in computer policy

Any idea how to solve this issue??? And how user's GPO could be applied before computer GPO??

Thank you.

Michal
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 2 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 2 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros