Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Help with Group Policy and browsing

Posted on 2014-02-05
6
Medium Priority
?
421 Views
Last Modified: 2014-02-06
I need to find out why my users are getting a Proxy setting applied automatically in their browsers, applied by Group Policy? I need to find this IE Proxy setting in GPMC and disable it so that NO proxy is applied and all users with a proxy set manually have it overridden by group policy.

This is an ongoing problem... new users claim they "Can't get on the internet" until they uncheck the proxy from Tools > Internet Options > Connections LAN settings.
0
Comment
Question by:Elixir2
  • 4
6 Comments
 
LVL 9

Expert Comment

by:Lee Ingalls
ID: 39836693
REF: http://technet.microsoft.com/en-us/library/dd759258.aspx

See the screenshot for adding a GPO to clear IE Proxy Setting

To open or add and open a Group Policy object

On your domain controller running Windows Server 2008, click Start , point to Administrative Tools , and then click Group Policy Management . The Group Policy Management console opens.

In the left pane, double-click your forest. For example, double-click Forest: example.com .

In the left pane, double-click Domains , and then double-click the domain that contains the GPO you want to manage. For example, double-click example.com .

Do one of the following:

To open an existing domain-level GPO for editing , double click the domain that contains the GPO that you want to manage, right-click the domain policy you want to manage, and then click Edit .

To create a new Group Policy object and open for editing , right-click the domain for which you want to create a new GPO, and then click Create a GPO in this domain, and link it here .

In New GPO , in Name , type a name for the new GPO, and then click OK .

Right-click your new GPO, and then click Edit . Group Policy Management Editor opens.
GP-IE-Proxy-Off.jpg
0
 
LVL 1

Author Comment

by:Elixir2
ID: 39837261
I'm fairly familiar with GPMC adding/editing GPOs. I'm not so familiar with "linking" and "enforcing" GPOs.

I'm looking at your screenshot and I notice a significant difference. I don't have anything under User Configuration > Windows Settings > Internet...  It's just not there. The last entry is Policy-based...screenshot of my gpo I even tried creating a new GPO from scratch - same thing.
0
 
LVL 10

Accepted Solution

by:
Pramod Ubhe earned 2000 total points
ID: 39838187
On one one of the affected computers, you can run GPRESULT > R > result.txt command to see what GPOs are applied or RSOP.msc for GUI.
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 
LVL 1

Author Comment

by:Elixir2
ID: 39840391
GPRESULT /R > result.txt maybe?

Microsoft (R) Windows (R) Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001

Created On 2/6/2014 at 2:51:23 PM



RSOP data for DOMAIN\usernameDC02 : Logging Mode
--------------------------------------------------------

OS Configuration:            Primary Domain Controller
OS Version:                  6.1.7601
Site Name:                   N/A
Roaming Profile:             N/A
Local Profile:               C:\Users\username
Connected over a slow link?: No


USER SETTINGS
--------------
    CN=Lastname\, Firstname,OU=Admins,DC=domain,DC=pest1,DC=com
    Last time Group Policy was applied: 2/6/2014 at 2:39:11 PM
    Group Policy was applied from:      DC02.domain.pest1.com
    Group Policy slow link threshold:   500 kbps
    Domain Name:                        DOMAIN
    Domain Type:                        Windows 2000
    
    Applied Group Policy Objects
    -----------------------------
        Browser and Software Block
        Desktop Lock Policy
        Login
        logging
        Legal Logon
        Desktop Lock Policy
        Default Domain Policy
        DHR-LION

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Outlook Restrict PST
            Filtering:  Disabled (GPO)

        logging
            Filtering:  Not Applied (Empty)

        Local Group Policy
            Filtering:  Not Applied (Empty)

        Browser and Software Block
            Filtering:  Not Applied (Empty)

        ConfigMgr Client Install
            Filtering:  Not Applied (Empty)

    The user is a part of the following security groups
    ---------------------------------------------------
        Domain Users
        Everyone
        BUILTIN\Users
        BUILTIN\Pre-Windows 2000 Compatible Access
        BUILTIN\Administrators
        NT AUTHORITY\INTERACTIVE
        CONSOLE LOGON
        NT AUTHORITY\Authenticated Users
        This Organization
        LOCAL
        Domain Admins
        TSWeb Users
        TSWEB Admin
        VNC Users
        WSUS Administrators
        Denied RODC Password Replication Group
        High Mandatory Level
        

Open in new window

0
 
LVL 1

Author Comment

by:Elixir2
ID: 39840443
I used the /Z switch to get more information:
Found my proxy. Still can't tell what GPO is setting it. Still don't know why the Internet Explorer line is missing from my GPMC?
Well, there's this which explains it.
But I think I like this one better...
0
 
LVL 1

Author Closing Comment

by:Elixir2
ID: 39840468
Addressed the issue I asked for. If it was a partial answer, it was because my question was vague. Good enough to get me to the next step!
0

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question