[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

GPO do not take precedence

Posted on 2016-09-14
17
Medium Priority
?
55 Views
Last Modified: 2016-09-14
I have the following GPO applied to the following OU's:

Workpace OU
Settings1 GPO
     Customer OU
      Settings 2 GPO

The problem is when I do run the GPO results wizard the "settings 2 GPO" do not take precendence over the "settings 1 GPO" (winning GPO). When I check the group policy inheritance of the  "Customer OU" then the "settings 2 GPO" is in the top of the list. Also Enforced is disabled. Any ideas?
0
Comment
Question by:emieldmz
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 8
  • 7
  • 2
17 Comments
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 41797702
Just to double check a few things.

1. You do not have enforced enabled on Settings 1 GPO?
2. Do you see settings 2 GPO listed in the list of processed GPOs on the client? GPresult or the Group Policy log in event viewer will show this information.
1
 

Author Comment

by:emieldmz
ID: 41797803
1. Yes that is correct. it is not enabled
2. When I check the GPresult the GPO isn't in the list of applied GPO's. But the settings 2 GPO is enabled and has the good scope.
0
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 41797833
If the GPO isn't listed, something is off in the scoping of the policy. Can you upload a gpresult and a screenshot of the scope of both GPOs?

Also - check out this guide on some common GP errors: https://deployhappiness.com/top-10-ways-to-troubleshoot-group-policy/
0
NFR key for Veeam Agent for Linux

Veeam is happy to provide a free NFR license for one year.  It allows for the non‑production use and valid for five workstations and two servers. Veeam Agent for Linux is a simple backup tool for your Linux installations, both on‑premises and in the public cloud.

 

Author Comment

by:emieldmz
ID: 41797920
I checked the guide first before I wrote this question unfortunately without any success.

See attachments for the report & screenshots

settings1 gpo = DMZ Profile user settings

settings 2 gpo = Customer - Paintcenter User settings
scope-Settings1.PNG
scope-settings-2.PNG
report.html
0
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 41797943
Ah dang!

Take a screenshot of the enter GPO scope tab for both GPOs please. Also - take a screenshot of both settings tab (with all settings expanded).
0
 
LVL 59

Accepted Solution

by:
Cliff Galiher earned 2000 total points
ID: 41797969
At first glance, I'm guessing you are getting bit by this change, based on the security group change you made in setting 2.

https://blogs.technet.microsoft.com/askpfeplat/2016/07/05/who-broke-my-user-gpos/
0
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 41797985
Thank you.

Are the objects in the paintcenter OU users?
0
 

Author Comment

by:emieldmz
ID: 41798002
Yep the user accounts. The group "Paincenter Users" (where the scope is pointing to) is in another OU.
0
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 41798006
Ok. If they were just added to the group, did you log off and log back on?

When logged in as a user in that group, launch command prompt. type net user /domain USERNAME

Under group memberships (at the bottom), do you see the paintcenter users group listed?
0
 

Author Comment

by:emieldmz
ID: 41798024
Yep!
0
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 41798034
Hmm... log in as one of those users. Run a gpresult /h report.htm command. Upload the report.htm file that is created.
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 41798079
Did you read the article I posted at all?
0
 

Author Closing Comment

by:emieldmz
ID: 41798088
The option from Cliff does the job. When I added domain computers everything worked fine.
0
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 41798104
Good catch Cliff! I completely overlooked that.
1
 

Author Comment

by:emieldmz
ID: 41798109
And thanks for the support Joseph!
0
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 41798117
No problem - I went back and added this solution to the group policy troubleshooting article from earlier.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question