Jump to content

Recommended Posts

Posted

I'm struggling to find an clear explanation of the difference between the two. I understand modelling can be used to simulate a situation that doesn't exist, but what if you use modeling for a set-up that does exist? Is it any different from results?

 

I ask because I have a GPO that isn't being applied to a subset of PCs. Modelling shows it being applied but results doesn't show it being applied or denied at all.

Posted

I removed the loopback and applied it to Users. I then added the setting to our Laptop policy which has merge loopback already set up. The setting still isn't applied but the GPO is.

The setting is the System/Logon/Run these programs at logon.

 

I'm at a complete loss, which means it's a really obvious mistake I've made.

Posted

Basically Modeling is the Theory, Results is the Practice.

 

With modeling you get pages of options to check over, such as WMI filters, which may have default options it assumes (i.e. all WMI filters are applied, which is why I never skip to the final page in modeling). Both are useful to debug, in modeling it can be handy to know what happens if a custom WMI filter is not actioned for example.

 

With regard to loopback settings they are set on the computer OU in the computer policy settings, then in the same group policy the user settings you wish to push out are set in the user policy section.

Posted

Is modelling with defaults the same as results? Same OUs, groups, WMI filters etc.

 

I now only have one GPO with only the 'run at logon' setting. This is applied to Users. Which the user account is a part of.

That wasn't being applied OR denied. This is what confuses me. Surely it has to be one or the other?

 

I only added the 'run at logon' setting to the Laptop looback policy because these laptops play by their own rules and I wanted to add it to a GPO that I know is definitely being applied. The GPO applies, all except the setting I've added.

Posted
Is modelling with defaults the same as results? Same OUs, groups, WMI filters etc.

 

Unfortunately not, the defaults assumes that certain conditions are true (such as assuming all the WMI filter critiera are met) as the modeling can not tell what settings the computer has and is designed to work when the machine if the machine is online or offline.

 

I now only have one GPO with only the 'run at logon' setting. This is applied to Users. Which the user account is a part of.

That wasn't being applied OR denied. This is what confuses me. Surely it has to be one or the other?

 

Have you got any details of the GPO to hand to see what could be up?

Posted

It's running an executable from a share at logon for PaperCut.

No WMI filters

It's linked to 4 OUs of user accounts

Applied to Authenticated Users.

Works fine around the school except some laptops.

Posted
I worked it out. I noticed none of the GPOs that are linked to the Users OU and below are applied when the users log on to their laptops. I found a policy with a replace loopback setting. So it was overwriting any and all of the user settings.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...