Cross Forest GPO Question...


hi all,

i ask question configuring cross forest gpos.

in summary.  have environment 2 forests in it.

a resource domain/forest (pcresource.com) has ad computer objects in , computer based gpos. 

and managed ad forest has user ad objects , user based gpos in (users.net)

there one-way trust (non transitive) pcresource.com users.net

cross forest gpo support has been enabled via 1 of computer based gpos in resource domain/forest.

when user01 logs onto pc-dev-01 (a windows 10 pc) the computer based gpos applying successfully.  user based gpos not appear applying successfully.

running rsop gpo management console or gpresults locally on pc gives report seems indicate user based gpos applying successfully.  when settings checked manually not set.  or if setting changed not reapplied @ next logon.

most common examples of ie11 homepage, auto proxy script , shortcuts placed on desktop.

i'm rather confused this.  because if user based policies not applying various reports should indicate this.

any assistance gratefully received,

hi iwebb,

>>because if user based policies not applying various reports should indicate this.

agree view.

besides, try to export gpos user.net , import pcresource.com workaround.

also, me check following location on user.net: computer configuration/administrative templates/system/group policy/allow cross- forest user policy(ensure enabled)

more detailed steps, please see kb below:

https://support.microsoft.com/en-sg/kb/823862

in addition, below kb helps troubleshooting issue:

how troubleshoot group policy object processing failures occur across multiple forests

see: scenario 2: cross-forest gpo application fails if icmp  not enabled

https://support.microsoft.com/en-sg/kb/910206

symptoms

all user group policy, including have been security filtered on user accounts or security groups, or both, may fail apply on domain joined computers.

see kb below:

https://support.microsoft.com/en-sg/kb/3163622

be sure current logon uses has appropriate read permission.

lastly, suppose following thread said right:

https://social.technet.microsoft.com/forums/en-us/b6276c11-bcb6-4fae-ae6a-d01c8c596a42/cross-forest-user-policies?forum=winservergp

best regards,

andy


please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Group Policy



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client