Active Directory
--
Questions
--
Followers
Top Experts
When creating a new installation policy on an Active Directory Domain and applying the policy to a specific Organizational Unit, a computer that is not a member of the domain is joined to the Domain and then moved to the specific Organizational Unit that has the policy attached to it. In this scenario, installation is achieved fine.
If existing Active Directory Domain computers needing the same installation and are moved to the Organizational Unit containing the same installation, installation doesn't occur unless the Active Directory Domain computer is removed from the Domain and rejoined to the Domain.
How do you accomplish group policy installation of software on existing Domain computers without first having to take them off the Domain and rejoin them to the Domain.
It makes no difference whether I run gpupdate /force or not or restart the computer. How do you install a new application to computers that are already joined to the Domain and are in the OU where the installation policy has already been attached?
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Some people have problems with PCs that boot very fast since those are not network-ready at the point in time when they should start installing.
Provide the application log entries that accompany the installation failures, please.
You could solve it quickly using scheduled tasks. Tasks can be deployed by GPO and simply install the MSI during normal operation. That works as long as the application is not in use.
Make it an "immediate task (at least windows 7)", which implies that it runs once, only (and not installs again and again).
As executor, use "system".
As task action, use
msiexec.exe /i \\server\share\some.msi /quiet /norestart
That task will apply at the next GPO background refresh which occurs about every 90 minutes plus/minus 20 minutes randomization (can of course be sped up by using
gpupdate /target:computer
on an elevated command prompt).
It will install the sofgtware quietly (invisible for the user)






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
When the computer gets moved into the requisite OU make sure to run:
GPUpdate /ForceOnce that's complete, reboot the computer and the software should install.If it doesn't, check that computer's Event Logs under Administration and there should be a specific error listed for the "why" it doesn't install.
Open regedit and browse to HKLM\Software\Microsoft\Wi
check each entry under here and view the Deployment name for the GPO
you require.
Delete the relevant entry under HKLM\Software\Microsoft\Wi
force a gpupdate (gpupdate /force) and reboot. it should then redeploy the software
Provided the entry under HKLM\Software\Microsoft\Wi

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Are you able to show the settings in the GPO for the software install so we can check that it looks ok?






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Active Directory
--
Questions
--
Followers
Top Experts
Active Directory (AD) is a Microsoft brand for identity-related capabilities. In the on-premises world, Windows Server AD provides a set of identity capabilities and services, and is hugely popular (88% of Fortune 1000 and 95% of enterprises use AD). This topic includes all things Active Directory including DNS, Group Policy, DFS, troubleshooting, ADFS, and all other topics under the Microsoft AD and identity umbrella.