Cross Forest GPO Question...
hi all,
i ask question configuring cross forest gpos.
in summary. have environment 2 forests in it.
a resource domain/forest (pcresource.com) has ad computer objects in , computer based gpos.
and managed ad forest has user ad objects , user based gpos in (users.net)
there one-way trust (non transitive) pcresource.com users.net
cross forest gpo support has been enabled via 1 of computer based gpos in resource domain/forest.
when user01 logs onto pc-dev-01 (a windows 10 pc) the computer based gpos applying successfully. user based gpos not appear applying successfully.
running rsop gpo management console or gpresults locally on pc gives report seems indicate user based gpos applying successfully. when settings checked manually not set. or if setting changed not reapplied @ next logon.
most common examples of ie11 homepage, auto proxy script , shortcuts placed on desktop.
i'm rather confused this. because if user based policies not applying various reports should indicate this.
any assistance gratefully received,
hi iwebb,
>>because if user based policies not applying various reports should indicate this.
agree view.
besides, try to export gpos user.net , import pcresource.com workaround.
also, me check following location on user.net: computer configuration/administrative templates/system/group policy/allow cross- forest user policy(ensure enabled)
more detailed steps, please see kb below:
https://support.microsoft.com/en-sg/kb/823862
in addition, below kb helps troubleshooting issue:
how troubleshoot group policy object processing failures occur across multiple forests
see: scenario 2: cross-forest gpo application fails if icmp not enabled
https://support.microsoft.com/en-sg/kb/910206
symptoms
all user group policy, including have been security filtered on user accounts or security groups, or both, may fail apply on domain joined computers.see kb below:
https://support.microsoft.com/en-sg/kb/3163622
be sure current logon uses has appropriate read permission.
lastly, suppose following thread said right:
best regards,
please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.
Windows Server > Group Policy
Comments
Post a Comment