?
Solved

Issues with a new GPO

Posted on 2015-01-23
10
Medium Priority
?
120 Views
Last Modified: 2015-01-26
Hello,
I created a simple GPO to enforce a screen saver of type X and activate within 1800 seconds. The policy is under the Users Configuration. I then went to the Scope and made sure Auth users and Domain users are in the security filtering, and it is linked to the domain XXXXX.local.

I went to a Windows 7 end PC which is on the domain, did several gpupdate/force and ran gpresult /r but keep getting N/A under applied GPO under the User Settings.... what am I missing here.

It is a new Windows 2012 R2 domain which I migrated from Windows 2003 server. The migration went pretty smooth, but maybe I missed something.

Do I need to enable loopback maybe?
0
Comment
Question by:SpiderPig
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
  • 2
  • +1
10 Comments
 
LVL 59

Accepted Solution

by:
Cliff Galiher earned 1000 total points
ID: 40567104
If you do a verbose output, or run the results wizard in the GPMC GUI, you can see every applied *AND* denied GPO. And why a GPO was denied. Start there.
0
 
LVL 22

Assisted Solution

by:Joseph Moody
Joseph Moody earned 1000 total points
ID: 40567184
You also don't need domain user and auth users. Auth users contains domain users.

You don't need loopback if the policy is linked at the domain and contains auth users.
0
 

Author Comment

by:SpiderPig
ID: 40567375
OK so I made some progress and was able to make all the User Config GPOs work. From some reason I cannot seems to get the GPOs with the Computer Config policies to work. For example password policies... I have Auth users in the security filtering, I assume thats why and I need to add computers there, but its a pain in the bXXX to manually add PCs. Is there away to tell it to implement for all hardware or computers in the office? I dont want to maintain security groups for computers... Any ideas?
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 40567391
Password policies are unique in that they can normally only be implemented at the domain level. The authenticated users group includes all computers. If you want more granular policies, you have to implement Fine Grained Password Policies and that is not a trivial undertaking. TechNet thoroughly documents all of this.
0
 

Author Comment

by:SpiderPig
ID: 40567403
Oh you are right it is working. I tried "Don not require ALT CTRL Del" And the PC I am working on actually got the policy even though when you type GPresult it does not show anything under computer only user policies....
0
 

Author Closing Comment

by:SpiderPig
ID: 40568409
Thank you all. Got it sorted out. It was also something weird with MS Bing Desktop which caused the screen saver to operate outside of the GPO scope. Very strange.
0
 
LVL 37

Expert Comment

by:Mahesh
ID: 40568418
Whenever you create new Policy, run gpupdate /force on domain controller 1st
Then run gpupdate /force on client computers
Also some computer configuration policies in order to get applied you must reboot the client computer, by simply running gpupdate /force won't help
All user policies will get applied after gpupdate /force on client machines, however some policies do need logoff and logon again in order to get applied

As stated earlier all users and computers \ servers are member of authenticated users group
If you don't want to apply policy only to users or computers, then remove authenticated users from security filtering and add either domain users or domain computers group
OR
more specifically you can create security groups and add required users \ computers in that group
Example:
U might have OU containing all computers, but you wanted to apply GPO to specific computers only within that OU, in that case you can create new security group and add required computers in that group and add that group on security filtering tab, remove authenticated users

U cannot disable default password policy for any domain user unless you create Fine Grained Password Policy
FGPP will override default domain password policy
0
 

Author Comment

by:SpiderPig
ID: 40568792
By the way, if I dont enable the policy by right clicking it, will it still take effect? I noticed that some PCs got the policy even though it was not enabled.
0
 
LVL 37

Expert Comment

by:Mahesh
ID: 40568905
By default any group policy is enabled only even if its not linked to anywhere (domain level, OU level), you may disable all setting if wanted to, this will prevent GPO setting to be pushed to workstations \ users
Even if GPO is enabled, it will not effect unless you link it to any OU \ domain
Instead of disabling GPO, just unlink it from respective OU \ domain.

The problem here is once GPO is applied on workstation, in reality the changes will get written in computers registry, hence even if you remove \ unlink \ disable policy, registry changes will not get reverted automatically
Either you need to reverse policy setting or push another GPO with reverse setting to revert.
0
 

Author Comment

by:SpiderPig
ID: 40571389
Awesome, thank you. Much appreciated.
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Here's a look at newsworthy articles and community happenings during the last month.
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum editing capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question