Server 2008 STD, Group Policy, ODDNESS

The environment is Server 2008 STD domain, windows 7 PCs and a group policy to add several sites to the trusted sites tab section of IE 8!  We have to use IE8 to access a US Govt wed site that only supports IE8.

There is a group policy applied to an OU and under Computer Config-Policies-Admin Templates- Windows Components/IE/IE Control Panel/Security page we have all of our sites listed.  This policy does not show as applied in the gpresults report.

Down under User Config, there IS a policy applied and it is the one that is working.  It shows under User Config-Policies-Windows Settings-IE Maintenance-Security/Security Zones and Content Ratings.  THAT policy is not applying either.

Two policies, neither applying.

Now, of course, when I open RSAT on my Win 7 box, or my Win 8 box, I DO NOT see the IE Maintenance as it was deprecated.  

When I log into the server and look in GP Mgt, I DO see the IE Maintenance option, but the settings are blank.

So, where are my PCs getting this setting if it's blank?  The gpreport shows that the GP I am working with is the source GP, but the source GP is blank under those settings when I look from the server.  

I am baffled as to how this GP is still getting pushed to the machines and I still need to push a list of trusted sites to my PCs and I'm pretty sure I'm going to do that with a Preferences policy.

Thoughts on this?

Thanks

Cliff
crp0499CEOAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Manikandan NarayanswamySecurity Specialist & IBM Security GuardiumCommented:
Hi,

So you mean to say both the policies are not applying on the windows 7 systems. Did all the computer accounts are on the OU where policy is linked. Did you tried enforce in group policy management console.  Send the screenshot of the policy which you have set in group policy. Also check the scope if authenticated users are added in the group policy management console

Thanks
Manikandan
0
crp0499CEOAuthor Commented:
There is a computer policy written and it doesn't show as applied OR failed.  OTHER settings in the same GP ARE applied though so I know the GP is applying.

There is NO setting in the user config of the GP, but that's where the gpreport shows the policy is applied and it's applied under the Internet Explorer Maintenance option, which is now deprecated.
0
Manikandan NarayanswamySecurity Specialist & IBM Security GuardiumCommented:
Hi,

Try to apply the Policy under Computer Configuration mentioned below in the screenshot. After modifying the policy run gpupdate /sync and see if it works.

Thanks
Manikandan
Capture.PNG
Capture1.PNG
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.