Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Warning in gpresult after installation of IE11 (Internet Explorer Branding)

Posted on 2015-01-21
3
Medium Priority
?
747 Views
Last Modified: 2015-02-26
Hi experts,

I´m facing a small problem while testing my Internet Explorer 11 deployment.
I created a new GPO for the IE11 clients, but have also some old GPOs, which have IEM settings activated.
I know, that those setting won`t work on new IE-versions, so in the new GPO I made those settings using a mix of Registry-Entries and GPPs.
That`s all working fine, as far as I can see.

I now only have the problem that gpresult on clients shows of a failure with "Internet Explorer Branding" as soon as IE 11 is installed.
It is a warning-sign on User-Configuration telling me that Internet Explorer Branding could not be processed. Ok, that`s true, but my clients get configured correctly.

I want to get those warnings away and took a look at following article:
http://support.microsoft.com/kb/2813272/en-us

The solution given by microsoft is to install a patch (which in fact is not available) or to rename registry-keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}

Open in new window


Deleting the key would be fine, would this key not be owned by "TrustedInstaller" only. That means that only this group is allowed to change those keys. Because of that it is not possible to change the keys centrally with my software deployment tool "opsi" (User for opsi is not member od TrustedInstaller).

So now I have two questions:

1. Is it a problem to have those warning in gpresult?
2. Doens anybody have an idea how I can get rid of those warnings in a centralized way?

Did anybody have the same problem?
Many thanks in advance!
0
Comment
Question by:Systemadministration
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 24

Expert Comment

by:VB ITS
ID: 40563443
You can just delete the GPExtensions and ProcessGroupPolicyEx registry keys (mentioned in KB2813272) through Group Policy Preferences if they're not needed.

Should be as simple as creating a new policy in the OU containing the PCs you want this policy to apply to, then configuring the below settings in the policy:
- Go to Computer Configuration\Preferences\Registry
- Right click on empty space on the right then click NewRegistry Item
- Configure the key with the following settings:
- Action: Delete
- Hive: HKEY_LOCAL_MACHINE
- Key Path: click on the ... button and browse to the key mentioned in the KB article
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}

Open in new window



Unfortunately you can't rename keys through Group Policy though so you'll need to rely on scripts to achieve this if you want to go down this path.
0
 

Author Comment

by:Systemadministration
ID: 40563894
I tried that, but the problem is, that the key "{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}" ist owned by "TrustedInstaller" and even the user "SYSTEM" has not rights to change entries under this key.

If I take ownership and change the permissions, that "SYSTEM" is allowed to change, the registry-change via GPO works fine.

 Strange bug...
0
 
LVL 24

Accepted Solution

by:
VB ITS earned 2000 total points
ID: 40563918
In that case you can also configure Group Policy to grant Users/Administrators/whatever full access to the key so it can be deleted.

In GPMC:
- Go to Computer Policies\Policies\Windows Settings\Security Settings\Registry
- Right click on empty space > Add Key
- Copy and paste the path to the key in the Selected Key field at the bottom of the Select Registry Key window that appears, but remove "HKEY_LOCAL_" from the beginning so it looks like this:
MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}

Open in new window

- Left click on Users in the access list and tick the Full Control box, then click OK
- In the Add Object window that appears select the Replace existing permissions on all subkeys with inheritable permissions option then click OK
- Force AD replication if you don't want to wait, then run the gpupdate /force command on a workstation and reboot it
- Log in once the machine is up, hopefully the ProcessGroupPolicy and ProcessGroupPolicyEx registry entries will have deleted themselves
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question