Jump to content

Recommended Posts

Posted

Was asked to ban one child from t'internet, apparently he gets over-stimulated (not like that!).

 

Tried fake proxy, which didn't work, and then banning iexplore and chrome.exe - which also didn't work. Unless I put the GPO at the root of the domain.

 

AD structure is:

 

AD.PNG

 

The GPO is User/Policies/Administrative Templates/System/Don't run specified Windows applications and only the student is in the security filtering. I tried placing it in his Intake OU (2012) and moving it up through Students, Users and Curriculum, but it would only apply if I put it right at the top. (Didn't even register in modelling).

 

Whilst it's working, I'm a bit unhappy with leaving it there and wondered if anyone can shed any light or offer any suggestions as to how to move it "down". Having checked, it looks like a few other GPOs (but not all of them) have the same problem.

Posted
Can you set it there but use security filtering so it only takes affect on his account?

 

There at the top? That's what I've done and it works and doesn't seem to affect anyone else (so far!). But surely it should work in the appropriate OU?

Posted

The only time I've seen this was when using Enforced on group policies - where normally a more specific GPO takes precedence over a more general GPO (e.g. 2012 OU GPO wins out over Student GPO), this is reversed when using Enforced. So if your normal proxy GPO is Enforced at a general level, your new Enforced GPO has to be at a more general level in order to take precedence.

 

It's like the rules processing bounces back up the tree. Normal GPOs at root are applied first, so overwritten by more specific downtree GPOs as they're processed next, then the system works back up the tree checking for Enforced GPOs, reaching those general level Enforced GPOs last and thus resulting in their settings being applied. If that makes sense.

  • Thanks 1
Posted
Do you not have a ban option on your firewall/ filtering system, may be an easier way?

 

'Fraid not. LEA firewall/filtering.

 

The only time I've seen this was when using Enforced on group policies - where normally a more specific GPO takes precedence over a more general GPO (e.g. 2012 OU GPO wins out over Student GPO), this is reversed when using Enforced. So if your normal proxy GPO is Enforced at a general level, your new Enforced GPO has to be at a more general level in order to take precedence.

 

It's like the rules processing bounces back up the tree. Normal GPOs at root are applied first, so overwritten by more specific downtree GPOs as they're processed next, then the system works back up the tree checking for Enforced GPOs, reaching those general level Enforced GPOs last and thus resulting in their settings being applied. If that makes sense.

 

That does make sense, and answers some of my un-asked questions about processing order. I don't think that's the case here as I can only find one enforced policy (in Curriculum-Computers-Area) that allows the library machine to have a custom wallpaper and screensaver.

Posted
That does make sense, and answers some of my un-asked questions about processing order. I don't think that's the case here as I can only find one enforced policy (in Curriculum-Computers-Area) that allows the library machine to have a custom wallpaper and screensaver.

 

Have you tried enforcing this one?

 

As a complete cop-out-and-workaround, you could also use a startup script to set the proxy instead, if it's the particular setting that's being a pain.

 

What does the Group Policy Modelling Wizard say? Or GPRESULT?

Posted

Wait, another thought - you're using security group filtering, right, to target only this student? Have you added Domain Computers to the security filtering as well? Else the PC can't read the GPO to process it.

 

Might be easier to create a sub-OU in the relevant OU, shunt this student down into there and tie the GPO to that new OU without any filtering. Bit messier AD wise, but faster client processing, FWIW.

  • Thanks 1
Posted
Wait, another thought - you're using security group filtering, right, to target only this student? Have you added Domain Computers to the security filtering as well? Else the PC can't read the GPO to process it.

 

Might be easier to create a sub-OU in the relevant OU, shunt this student down into there and tie the GPO to that new OU without any filtering. Bit messier AD wise, but faster client processing, FWIW.

 

it dosent need to if its a user policy or you wouldn't be able to run policies with the disable user/computer configuration applied

  • Thanks 1
Posted
its not the order its applying in is it some other policy that because of the order is overwriting it?

 

Don't think so - especially after reading @sonofsanta's explanation.

 

Have you tried enforcing this one?

 

As a complete cop-out-and-workaround, you could also use a startup script to set the proxy instead, if it's the particular setting that's being a pain.

 

What does the Group Policy Modelling Wizard say? Or GPRESULT?

 

Tried enforcing; didn't work. Modelling and Result didn't show any sign of the policy until I moved it up.

 

Wait, another thought - you're using security group filtering, right, to target only this student? Have you added Domain Computers to the security filtering as well? Else the PC can't read the GPO to process it.

 

Might be easier to create a sub-OU in the relevant OU, shunt this student down into there and tie the GPO to that new OU without any filtering. Bit messier AD wise, but faster client processing, FWIW.

 

I did add Domain Computers (it didn't make any difference) though it's currently running without them in the security filtering. I did try a new sub-OU, but still left the security filtering set to that particular student (rather than authenticated users). Off to give it a try.

Posted
it dosent need to if its a user policy or you wouldn't be able to run policies with the disable user/computer configuration applied

 

Er, yeah. That. I was thinking of our background GPOs, when I want to apply them to a specific person - but they're loopback policies so they do need both.

 

Ignore me. Carry on.

Posted
if you log in as said user on a pc what does gpresult/rsop show on that pc rather than running modelling etc it may give you more info like showing it as a guid rather than a named policy and saying not applied
Posted
I did try a new sub-OU, but still left the security filtering set to that particular student (rather than authenticated users). Off to give it a try.

 

Didn't work :(.

 

If nothing else, at least I've been able to work out a fix for some of the other policies that I could never get to apply but were "nice tweaks" rather than "critical". (Like auto-filling the name on first use of Office or disabling the Action Centre because it doesn't seem to recognise McAfee as valid).

Posted
if you log in as said user on a pc what does gpresult/rsop show on that pc rather than running modelling etc it may give you more info like showing it as a guid rather than a named policy and saying not applied

 

Didn't show the policy in the list at all (assuming thats the same as GPRESULT /H .html).

Posted

This is really odd.

 

Tried making a new GPO on that sub-OU and seeing if that one applies? Maybe it's something daft specific to this policy and the quickest thing to do is make a new policy.

Posted
This is really odd.

 

Tried making a new GPO on that sub-OU and seeing if that one applies? Maybe it's something daft specific to this policy and the quickest thing to do is make a new policy.

 

I thought of that too, and tried a "Test" policy that made a piffling change - same result.

 

AFAIK my 2008 school doesn't have this problem (will check tomorrow) and I will take a look at my other 2012 school on Monday, as I've been unable to get my "automatically add wireless network credentials" to work there - might be a similar thing.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...