Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Struggling with GPOs

Posted on 2016-07-31
7
Medium Priority
?
85 Views
1 Endorsement
Last Modified: 2016-08-01
I have just started playing with GPOs. Trying to deploy a couple printers. I linked the Policies to the Computers OU but for some reason it isn't being applied. The two policies are Production LaserJet Pro and Lab LaserJet Pro.

I made up a Security Group for each and added the computers that I wanted to install the printers on to that Group. Then applied the policy to those security groups yet according to GPRESULT they aren't being applied. Screen shot attached. Thanks!
Capture.PNG
Capture.PNG
Capture.PNG
1
Comment
Question by:LockDown32
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
  • +1
7 Comments
 
LVL 79

Accepted Solution

by:
arnold earned 1000 total points
ID: 41736997
Do you have a status script that has pushprinterconnections.exe
You needs this application to run to map/setup the printers/drivers.

Your three images are of the same display if tge GPO, but includes mo info on the GPO settings.

Hp printers are usually included with the...

Server is version, printer manager configured to deploy the printers to the gpo?

Step one create GPO that has the pushprinterconnections.com as the startup script (note if you have a mixed environment, make sure the push is the 32bit version.

On the print manager, under sharing make sure you have drivers to meet your environment's need I.e. 32/64 bit ..
Then within print manager, deploy the printer as computer, to referencing the GPO that applies.

Working for memory, you placed the GPO in the sbscomputer OU ...

run
gpupdate /force

This will force the computer to refresh the GPOs and will require the reboot of the system.

If you followed a specific guide to set this up, please post so that we can discuss this from the same vantage point.
0
 
LVL 79

Expert Comment

by:arnold
ID: 41737000
He is the link reference to the mentioned pushprinterconnection.exe utility in the earlier comment.

https://technet.microsoft.com/en-us/library/cc772505(v=ws.10).aspx
0
 
LVL 20

Assisted Solution

by:Peter Hutchison
Peter Hutchison earned 1000 total points
ID: 41737058
There are or four places you can assign printers using GPOs/GPPs.

If you Group Policy, you can deploy printers:
a) Computer Configuration, Policies, Windows Settings, Deployed Printers
b) User Configuration, Policies, Windows Settings, Deployed Printers
c) Computer Configuration, Preferences, Control Panel Settings, Printers
d) User Configuration, Preferences, Control Panel Settings, Printers

Which of these areas did you use to deploy printers?
What OS version do you clients have?

You only need pushprinterconnections.exe for Windows 2000,XP,2003 machines.

If using GPPs, on Windows XP, you also need Group Policy Preferences client-side extensions for XP, 2003 and Vista (see https://www.microsoft.com/en-us/search/result.aspx?q=Preferences+client-side+extension&form=dlc)
0
Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

 
LVL 15

Author Comment

by:LockDown32
ID: 41737274
It is a Server 2012 Standard, The way I have been doing it is to first create and share the printer with both x86 and x64 drivers. Create the GPO and then going in to Control Panel and Print Manager to deploy via GPO. I did it that way for one printer and deployed it in the Default Domain Policy and it deployed fine. Then I was told not to use the Default Domain Policy so I tried a separate GPO linked to the Computers OU and haven't been able to get it to work.

When I run Group Policy Results from the Server it tells me that both polices are "Access Denied (Security Filtering)" when I apply it on one computer yet when I apply it to another computer in the same scope it deploys.

I made up a group (Security Group) and added three computers to it. That is the scope of the GPO. On two of the three computers it applies. On the third it is "Access Denied (Security Filtering)"
1
 
LVL 20

Expert Comment

by:Peter Hutchison
ID: 41737328
I think some more screen shots of the GPOs themselves would be helpful incl group, group membership, GPO scope and delegation and policy settings may help and a full output of gpresults command.
0
 
LVL 15

Author Comment

by:LockDown32
ID: 41737338
Thanks Peter but I found the problem. Kind of two fold. I had to run gpupdate /force on this problem workstation at which point the GPO took effect. I wasn't aware that when you ran gpresult on the server that it actually queried the workstation and if the workstation needed a gpupdate the server would not reflect that but simply show the gpo as denied and....

gpresult on a Windows 10 workstation doesn't work... even now that the GPO is working it does not show up as either applied or denied on this WIndows 10 workstation with a gpresult /h.
0
 
LVL 23

Expert Comment

by:yo_bee
ID: 41737750
Not sure if this will help, but I have a article that was published on EE on How to Push Printers using Group Policy Preferences.

https://www.experts-exchange.com/articles/11321/Deploying-Printers-using-Group-Policy-Preferences.html

If may help or may not.
Please let me know
0

Featured Post

Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question