Jump to content

Recommended Posts

Posted

Hello everyone,

 

I am having issues with GPO User Drive Mappings.

 

First off a little info on what we have now. We are currently using logon scripts to map 3-5 drives, depending on the level of user.

 

I decided to remove the logon script from my own user account and try using GPO preferences. At the moment I have the GPO's OU set to Users>Staff>AdminStaff, which is me and several other members. I have the Security Filtering set to my individual account. From what I have been reading, Replace sounds like the best option to have, along with reconnect. This works, to my knowledge, perfectly.

 

Now, what I tried to do was push back the OU to Users>Staff which has two more OUs inside (AdminStaff & TeachingStaff, both with users inside) and set the Security Filtering to AllStaff. AllStaff is just a test group that has another group inside it, AllIT, which has myself in it. However this does not seem to work.

 

Essentially what I want to try out is, instead of having this GPO drilled right down to an individual, I would like scale it back to all staff but for testing reasons, still keep it working for just myself.

 

I have tried Item-Level Targetting to say "only apply these to the AllIT group" (Me alone in the group) but still got no luck from it.

 

Do these type of policies not cascade down Groups, like what happens to OUs.

 

Am I just missing something small? Am I going around this the completely wrong way? Is what I am doing even possible? Any help would be much appreciated.

Posted
You can specify specific Users or Security Groups when targeting, but remember it's part of a specific Group Policy, so it has to be linked within the correct place within your structure also.
Posted

The best thing to do would probably create a TestOU with the same structure as the one you are trying to apply it to. We do not use security filtering on the GPO but we do use Item Level Targeting on the drive maps. If you do this you can apply it to your account only and then change that to a group once you know it is working. Be aware though if you have a script running which also maps drives, this will replace your GPP as the script runs last. Easiest way to check is create a new GPO with only drive mapping GPP and see how it works.

 

Check your preferences that you have got run in logged-on users context ticked also.

Posted
Sorry for double post but where do yous actually apply the GPO? To the root user OU or root group OU? Do yous have an OU structure for your groups?
Posted (edited)

Hmm.... atm I have 5 map drives. The current User/Group structure is

 

Me>TEST ALLIT> TEST ALLADMIN>TEST ALLSTAFF

 

I set ILT on all maps.

 

1st map was set to the TEST ALLIT group

2nd map was set to the TEST ALLADMIN

3rd map was set to the TEST ALLSTAFF

4th map was set to myself (User ILT)

5th map was set to Teachers (An actual group)

 

I only received the 4th and 5th maps.

 

I have reason to believe I am not correctly setting up my test groups. Should the root group be a member of something else?

 

EDIT: Reading how ILT works I know for a fact groups don't work the way I intended them to.

 

2nd EDIT: "the user is a member of the security group" I think this is where I fumbled.

 

Can someone clarify if this is true. Take the following group structure.

 

Me>TEST ALLIT> TEST ALLADMIN>TEST ALLSTAFF

 

If I set the security group to "TEST ALLADMIN" this will apply the GPO to Me as I am in "TEST ALLIT" which is in "TEST ALLADMIN"

Edited by Ripleys
Posted
Group structure or OU structure? Are you nesting security groups?

 

Group Structure. And yes. You asking me this makes me believe you cannot do that. Security Groups are still quite new to me.

Posted
You can, but it isn't necessary. Users (or computers) can be members of more than one group. I'd only nest groups for ease - if I wanted, for example, all form tutors in a group I'd add the Y7 form tutors, y8 Form tutors etc to one group.
Posted
I was just reading there that you should nest more than once. But what I don't understand is though, is that I apply the ILT to the TEST ALLIT group, which has Me in it and it doesn't work. However I am also in the teachers (active) group and that pulls the map fine when I set ILT to teachers
Posted
Right so I have taken all ILT off all maps and after a gpupdate all drives are mapped to me. However when I go to add the TEST ALLIT group and perform gpupdate, that specific drive disappears. I shall post a SS shortly :)
Posted

I'm not sure I understand what you have configured already, but the way we have it set up is:

OU>

Staff> StaffDrives GPO assigned at this level. Staff accounts listed in this OU get the following settings

 

In StaffDrives GPO we have the settings

Map "Y" drive to "Fileserver1\Maths Dept" with Item Level Targeting for "Maths dept"

Map "Y" drive to "Fileserver1\Eng Dept" with Item Level Targeting "Engineering dept"

Map "Y" drive to "Fileserver1\IT Dept" with Item Level Targeting "IT dept"

 

That way all users get a "Y:" drive but each see their own department folders.

  • Thanks 1
Posted

Good Afternoon guys,

 

Back into school for my last 3 days before Xmas. I had left my computer on over the weekend. When coming back into work I went into AD and checked on the test groups. When clicking the Member Of it mentioned something about not being able to refresh some things. After closing AD and reopening AD I go back to the group and check the Member Of tab, the warning message disappeared. I thought I would give the ILT security groups another go.

 

1st to the test group my account is in.

2nd to the next up group that contains the group from the first setting

3rd to the group that I mention in the 2nd setting

4th left alone for the "Authenticated Users" that is set in the security filtering for the GPO

5th to the teachers group, an active group within AD.

 

A gpupdate /force in CMD made all the drives pop up.

 

I believe clareq previous post

 

One more thought - if you have more than one DC have you allowed time for group membership to replicate between servers?

 

is be the reasoning behind my issue.

 

Is there anyway you can manually push replication?

 

I'd like to thank you all for the time and effort yous have put in to help me :)

 

Enjoy the Holidays guys

Posted
Map "Y" drive to "Fileserver1\Maths Dept" with Item Level Targeting for "Maths dept"

Map "Y" drive to "Fileserver1\Eng Dept" with Item Level Targeting "Engineering dept"

Map "Y" drive to "Fileserver1\IT Dept" with Item Level Targeting "IT dept"

 

That way all users get a "Y:" drive but each see their own department folders.

 

penfold, this is something I was actually looking into later on down the line. At the moment it is just one share that has folders for the departments. Thank you

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...