Ripleys Posted December 16, 2015 Posted December 16, 2015 Hello everyone, I am having issues with GPO User Drive Mappings. First off a little info on what we have now. We are currently using logon scripts to map 3-5 drives, depending on the level of user. I decided to remove the logon script from my own user account and try using GPO preferences. At the moment I have the GPO's OU set to Users>Staff>AdminStaff, which is me and several other members. I have the Security Filtering set to my individual account. From what I have been reading, Replace sounds like the best option to have, along with reconnect. This works, to my knowledge, perfectly. Now, what I tried to do was push back the OU to Users>Staff which has two more OUs inside (AdminStaff & TeachingStaff, both with users inside) and set the Security Filtering to AllStaff. AllStaff is just a test group that has another group inside it, AllIT, which has myself in it. However this does not seem to work. Essentially what I want to try out is, instead of having this GPO drilled right down to an individual, I would like scale it back to all staff but for testing reasons, still keep it working for just myself. I have tried Item-Level Targetting to say "only apply these to the AllIT group" (Me alone in the group) but still got no luck from it. Do these type of policies not cascade down Groups, like what happens to OUs. Am I just missing something small? Am I going around this the completely wrong way? Is what I am doing even possible? Any help would be much appreciated.
Michael Posted December 16, 2015 Posted December 16, 2015 You can specify specific Users or Security Groups when targeting, but remember it's part of a specific Group Policy, so it has to be linked within the correct place within your structure also.
Ripleys Posted December 17, 2015 Author Posted December 17, 2015 Could this not be working because I am setting the GPO to the Users>Staff OU and not the Groups>Staff OU
penfold Posted December 17, 2015 Posted December 17, 2015 The best thing to do would probably create a TestOU with the same structure as the one you are trying to apply it to. We do not use security filtering on the GPO but we do use Item Level Targeting on the drive maps. If you do this you can apply it to your account only and then change that to a group once you know it is working. Be aware though if you have a script running which also maps drives, this will replace your GPP as the script runs last. Easiest way to check is create a new GPO with only drive mapping GPP and see how it works. Check your preferences that you have got run in logged-on users context ticked also.
Ripleys Posted December 17, 2015 Author Posted December 17, 2015 When you say you don't use Security Filtering, do you mean you just leave it as default; Authenticated Users?
clareq Posted December 17, 2015 Posted December 17, 2015 Yes, use Item level targeting to determine who gets which drive, in conjunction with which OU you link it with.
penfold Posted December 17, 2015 Posted December 17, 2015 @Ripleys - We just use Item Level Targeting to set the drive maps based on user groups and leave the security of the GPO on the default settings. Edit: @clareq above
Ripleys Posted December 17, 2015 Author Posted December 17, 2015 I will certainly give this a go now. I think I started off too granular.
Ripleys Posted December 17, 2015 Author Posted December 17, 2015 Sorry for double post but where do yous actually apply the GPO? To the root user OU or root group OU? Do yous have an OU structure for your groups?
clareq Posted December 17, 2015 Posted December 17, 2015 Drive mapping GPO I apply to the appropriate user OU - so staff drive mapping to the staff OU, student mapping to the student OU
Ripleys Posted December 17, 2015 Author Posted December 17, 2015 (edited) Hmm.... atm I have 5 map drives. The current User/Group structure is Me>TEST ALLIT> TEST ALLADMIN>TEST ALLSTAFF I set ILT on all maps. 1st map was set to the TEST ALLIT group 2nd map was set to the TEST ALLADMIN 3rd map was set to the TEST ALLSTAFF 4th map was set to myself (User ILT) 5th map was set to Teachers (An actual group) I only received the 4th and 5th maps. I have reason to believe I am not correctly setting up my test groups. Should the root group be a member of something else? EDIT: Reading how ILT works I know for a fact groups don't work the way I intended them to. 2nd EDIT: "the user is a member of the security group" I think this is where I fumbled. Can someone clarify if this is true. Take the following group structure. Me>TEST ALLIT> TEST ALLADMIN>TEST ALLSTAFF If I set the security group to "TEST ALLADMIN" this will apply the GPO to Me as I am in "TEST ALLIT" which is in "TEST ALLADMIN" Edited December 17, 2015 by Ripleys
clareq Posted December 17, 2015 Posted December 17, 2015 Group structure or OU structure? Are you nesting security groups?
Ripleys Posted December 17, 2015 Author Posted December 17, 2015 Group structure or OU structure? Are you nesting security groups? Group Structure. And yes. You asking me this makes me believe you cannot do that. Security Groups are still quite new to me.
clareq Posted December 17, 2015 Posted December 17, 2015 You can, but it isn't necessary. Users (or computers) can be members of more than one group. I'd only nest groups for ease - if I wanted, for example, all form tutors in a group I'd add the Y7 form tutors, y8 Form tutors etc to one group.
Ripleys Posted December 17, 2015 Author Posted December 17, 2015 I was just reading there that you should nest more than once. But what I don't understand is though, is that I apply the ILT to the TEST ALLIT group, which has Me in it and it doesn't work. However I am also in the teachers (active) group and that pulls the map fine when I set ILT to teachers
clareq Posted December 17, 2015 Posted December 17, 2015 Can you post a screen shot of your ILT page?
Ripleys Posted December 17, 2015 Author Posted December 17, 2015 Right so I have taken all ILT off all maps and after a gpupdate all drives are mapped to me. However when I go to add the TEST ALLIT group and perform gpupdate, that specific drive disappears. I shall post a SS shortly
clareq Posted December 17, 2015 Posted December 17, 2015 One more thought - if you have more than one DC have you allowed time for group membership to replicate between servers? 1
penfold Posted December 17, 2015 Posted December 17, 2015 I'm not sure I understand what you have configured already, but the way we have it set up is: OU> Staff> StaffDrives GPO assigned at this level. Staff accounts listed in this OU get the following settings In StaffDrives GPO we have the settings Map "Y" drive to "Fileserver1\Maths Dept" with Item Level Targeting for "Maths dept" Map "Y" drive to "Fileserver1\Eng Dept" with Item Level Targeting "Engineering dept" Map "Y" drive to "Fileserver1\IT Dept" with Item Level Targeting "IT dept" That way all users get a "Y:" drive but each see their own department folders. 1
Ripleys Posted December 17, 2015 Author Posted December 17, 2015 It's never crossed my mind, sorry. I just tried using the OU ILT instead of the security group and that worked fine
Ripleys Posted December 21, 2015 Author Posted December 21, 2015 Good Afternoon guys, Back into school for my last 3 days before Xmas. I had left my computer on over the weekend. When coming back into work I went into AD and checked on the test groups. When clicking the Member Of it mentioned something about not being able to refresh some things. After closing AD and reopening AD I go back to the group and check the Member Of tab, the warning message disappeared. I thought I would give the ILT security groups another go. 1st to the test group my account is in. 2nd to the next up group that contains the group from the first setting 3rd to the group that I mention in the 2nd setting 4th left alone for the "Authenticated Users" that is set in the security filtering for the GPO 5th to the teachers group, an active group within AD. A gpupdate /force in CMD made all the drives pop up. I believe clareq previous post One more thought - if you have more than one DC have you allowed time for group membership to replicate between servers? is be the reasoning behind my issue. Is there anyway you can manually push replication? I'd like to thank you all for the time and effort yous have put in to help me Enjoy the Holidays guys
Ripleys Posted December 21, 2015 Author Posted December 21, 2015 Map "Y" drive to "Fileserver1\Maths Dept" with Item Level Targeting for "Maths dept" Map "Y" drive to "Fileserver1\Eng Dept" with Item Level Targeting "Engineering dept" Map "Y" drive to "Fileserver1\IT Dept" with Item Level Targeting "IT dept" That way all users get a "Y:" drive but each see their own department folders. penfold, this is something I was actually looking into later on down the line. At the moment it is just one share that has folders for the departments. Thank you
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now