GPO not applying
i have strange issue gpo not applying pc's in ou.
 
have made gpo computer enabled not user since gpo settings affects computer configuration.
in organization, have many departments computers exist in own "computer" ou.
example: main department ou "accounting", have sub ou called "computers".
in ou, computers in accounting departament exist.
 
trying link new gpo "computers" ou in accounting ou. when link gpo "computers" ou, not apply. logged in client pc, did gpupdate gpresult , not see gpo there. however, when add individual pc's new gpo, appreas while doing gpupdate gpresult on client. have tried enforcing gpo while applying accounting computers ou, did not work. works when specify individual pc's in gpo.
thing have noticed that, when apply individual accounting comptuers gpo leaving gpo link accounting computers ou on, gpresult shows gpo applied twice. when remove accounting computers ou gpo , leave individual pc's there, lists 1 time.
 
linking ou gpo work if it's done users? not pcs?
 
input on this.
thanks,
 have made gpo computer enabled not user since gpo settings affects computer configuration.
in organization, have many departments computers exist in own "computer" ou.
example: main department ou "accounting", have sub ou called "computers".
in ou, computers in accounting departament exist.
trying link new gpo "computers" ou in accounting ou. when link gpo "computers" ou, not apply. logged in client pc, did gpupdate gpresult , not see gpo there. however, when add individual pc's new gpo, appreas while doing gpupdate gpresult on client. have tried enforcing gpo while applying accounting computers ou, did not work. works when specify individual pc's in gpo.
thing have noticed that, when apply individual accounting comptuers gpo leaving gpo link accounting computers ou on, gpresult shows gpo applied twice. when remove accounting computers ou gpo , leave individual pc's there, lists 1 time.
linking ou gpo work if it's done users? not pcs?
input on this.
thanks,
if understood scenraio correct looks security group issue.
but first answering last question:
it work linking gpo ou computer accounts when gpo has computer configuration based settings in it.
in case far ok.
to gpo applied, besides linking security filters must enable target objects read , apply gpo.
by default, authenticates users have apply permission (this group includes users , computers of domain).
probably default group missing... please check this.
if want have computers of ou affected, add authenticates users again (scope pane).
if want affected computers only, add self created security group apply permission , and specific accounts group.
some helpful links:
http://technet.microsoft.com/en-us/library/cc779291(ws.10).aspx
http://technet.microsoft.com/en-us/library/cc781988(ws.10).aspx
hope helps. if yes, feel free mark post answer.
patrick
but first answering last question:
it work linking gpo ou computer accounts when gpo has computer configuration based settings in it.
in case far ok.
to gpo applied, besides linking security filters must enable target objects read , apply gpo.
by default, authenticates users have apply permission (this group includes users , computers of domain).
probably default group missing... please check this.
if want have computers of ou affected, add authenticates users again (scope pane).
if want affected computers only, add self created security group apply permission , and specific accounts group.
some helpful links:
http://technet.microsoft.com/en-us/library/cc779291(ws.10).aspx
http://technet.microsoft.com/en-us/library/cc781988(ws.10).aspx
hope helps. if yes, feel free mark post answer.
patrick
                                                                          Windows Server                                                     >                                                                 Group Policy                                                                           
 
 
  
 
Comments
Post a Comment