Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 58
  • Last Modified:

GPO do not take precedence

I have the following GPO applied to the following OU's:

Workpace OU
Settings1 GPO
     Customer OU
      Settings 2 GPO

The problem is when I do run the GPO results wizard the "settings 2 GPO" do not take precendence over the "settings 1 GPO" (winning GPO). When I check the group policy inheritance of the  "Customer OU" then the "settings 2 GPO" is in the top of the list. Also Enforced is disabled. Any ideas?
0
emieldmz
Asked:
emieldmz
  • 8
  • 7
  • 2
1 Solution
 
Joseph MoodyBlogger and wearer of all hats.Commented:
Just to double check a few things.

1. You do not have enforced enabled on Settings 1 GPO?
2. Do you see settings 2 GPO listed in the list of processed GPOs on the client? GPresult or the Group Policy log in event viewer will show this information.
1
 
emieldmzAuthor Commented:
1. Yes that is correct. it is not enabled
2. When I check the GPresult the GPO isn't in the list of applied GPO's. But the settings 2 GPO is enabled and has the good scope.
0
 
Joseph MoodyBlogger and wearer of all hats.Commented:
If the GPO isn't listed, something is off in the scoping of the policy. Can you upload a gpresult and a screenshot of the scope of both GPOs?

Also - check out this guide on some common GP errors: https://deployhappiness.com/top-10-ways-to-troubleshoot-group-policy/
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 
emieldmzAuthor Commented:
I checked the guide first before I wrote this question unfortunately without any success.

See attachments for the report & screenshots

settings1 gpo = DMZ Profile user settings

settings 2 gpo = Customer - Paintcenter User settings
scope-Settings1.PNG
scope-settings-2.PNG
report.html
0
 
Joseph MoodyBlogger and wearer of all hats.Commented:
Ah dang!

Take a screenshot of the enter GPO scope tab for both GPOs please. Also - take a screenshot of both settings tab (with all settings expanded).
0
 
Cliff GaliherCommented:
At first glance, I'm guessing you are getting bit by this change, based on the security group change you made in setting 2.

https://blogs.technet.microsoft.com/askpfeplat/2016/07/05/who-broke-my-user-gpos/
0
 
Joseph MoodyBlogger and wearer of all hats.Commented:
Thank you.

Are the objects in the paintcenter OU users?
0
 
emieldmzAuthor Commented:
Yep the user accounts. The group "Paincenter Users" (where the scope is pointing to) is in another OU.
0
 
Joseph MoodyBlogger and wearer of all hats.Commented:
Ok. If they were just added to the group, did you log off and log back on?

When logged in as a user in that group, launch command prompt. type net user /domain USERNAME

Under group memberships (at the bottom), do you see the paintcenter users group listed?
0
 
emieldmzAuthor Commented:
Yep!
0
 
Joseph MoodyBlogger and wearer of all hats.Commented:
Hmm... log in as one of those users. Run a gpresult /h report.htm command. Upload the report.htm file that is created.
0
 
Cliff GaliherCommented:
Did you read the article I posted at all?
0
 
emieldmzAuthor Commented:
The option from Cliff does the job. When I added domain computers everything worked fine.
0
 
Joseph MoodyBlogger and wearer of all hats.Commented:
Good catch Cliff! I completely overlooked that.
1
 
emieldmzAuthor Commented:
And thanks for the support Joseph!
0
 
Joseph MoodyBlogger and wearer of all hats.Commented:
No problem - I went back and added this solution to the group policy troubleshooting article from earlier.
0

Featured Post

Transaction-level recovery for Oracle database

Veeam Explore for Oracle delivers low RTOs and RPOs with agentless transaction log backup and transaction-level recovery of Oracle databases. You can restore the database to a precise point in time, even to a specific transaction.

  • 8
  • 7
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now