Sheridan Posted February 11, 2014 Posted February 11, 2014 Some of our recently imaged PCs are logging an error (which relates to login scripts running) that seems to show that a group policy is preventing access to the cmd.exe: Access to C:\Windows\System32\cmd.exe has been restricted by your Administrator by location with policy rule {GUID} placed on path C:\Windows\system32\cmd.exe. Now, the weird thing is that GUID does not link to any Group Policy in our organisation, and I can't find a reference to it on the local machine! Its only on a certain batch of PCs which were created with the same image, but I can't find a trace of that phantom guid anywhere! Anyone got any ideas where this could be hiding?
Sheridan Posted February 11, 2014 Author Posted February 11, 2014 I can't see any local GPO's! The GroupPolicy folder is empty on the local machine as well.
3s-gtech Posted February 11, 2014 Posted February 11, 2014 Does the GUID still exist in the sysvol policies folder?
Sheridan Posted February 11, 2014 Author Posted February 11, 2014 No, its not a valid policy GUID as far as I can see on both the AD servers and the local clients themselves.
Cache Posted February 11, 2014 Posted February 11, 2014 rsop.msc run as administrator should give you a list of all the policies and their linked OU's/locations and you might be able to work it out from there? I had a few machines, not newly built mind you, which were pulling an old GPO I removed a month or 2 earlier at one point for some unknown reason. Runnning gpupdate /force fixed that though.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now