Avatar of Logica01
Logica01Flag for Czechia asked on

Problem with GPO / GPP (drive mapping) when L2 authentication is in place

Issue:
We have problem with Drive Mapping (Group Policy Preference, Item level targetting). Drives are not mapped to users after restart of computer.
Tests proved:
- this problem occurs only on ports where L2 authentication (computer certificate) is enabled
- if user login immediately (if there is 10+s delay with logon then disks are mapped properly)
- from GPO logs (compared logs with and without L2auth) is obvious that when computer is connected to switch with L2 auth then, due to delays, user's GPO is applied BEFORE computer GPO ... this I do not understand at all

Details:
If mapped drives are set to Update ... they are in disconnected state after restart (red X) ... but after 20-30s it is possible to see the content (but red X remain)
If mapped drives are set to Replace ... they are not visible after restart

... if user does Logoff/Logon disks are properly mapped

Settings of drive mapping (example of user policy):
Action: Update
Location: DFS folder
Reconnect: Enable
Use first Available: Disabled
Run in logged on user's security context: Yes
Item level targetting: Security Group

(Computer policy)
Always wait for the network at computer startup and logon: Enabled

Here is description of our environment:
DC: W2k8 R2
Clients: Windows 7 x86
L2 Auth: Computer Authentication, MS Supplicant set in computer policy

Any idea how to solve this issue??? And how user's GPO could be applied before computer GPO??

Thank you.

Michal
Active DirectoryWindows Server 2008Windows 7

Avatar of undefined
Last Comment
Logica01

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
Raj-GT

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
ASKER
Logica01

Thank you. Startup policy was the one :).
Default value of Amount of time to wait is 30s.
When I increased it to 150s the problem was solved.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes