Jump to content

Recommended Posts

Posted (edited)

Hi folks,

 

I'm having some issues with configuring group policy on my server that i need your gentle help with.

 

What i'm trying to achieve is to put a auto-shutdown policy on some of the computers in the domain.

the way I wanted to configure it is to create a scheduled task which i believe the picture below is the right way of doing it.

01.png

 

* - Then I linked this GPO to my domain:

02.png

 

* - Then I filtered the GPO using security filters with the security group that contains the select computers i'd like to perform the action on

03.png

 

 

 

With all of these steps, I can't see the shutdown GPO under the GP results outcome page. What am i missing?

04.png

 

Thanks

Edited by Alexir
Posted

1 - Create a .bat with the command

2 - Create a new GPO

3 - Under Computer add the .bat on start script

4 - Filter using security filter (do not forget click on apply GPO)

5 - Link the GPO onto your OU

Posted
1 - Create a .bat with the command

2 - Create a new GPO

3 - Under Computer add the .bat on start script

4 - Filter using security filter (do not forget click on apply GPO)

5 - Link the GPO onto your OU

 

Thanks, but my main issue is to get the policy to show-up as applied GPO which without it i don't think it would work at all.

Posted
Could you try removing the security filtering altogether and then, apply the GPO to the Sales Computers OU rather than at the root of your domain?
Posted
Could you try removing the security filtering altogether and then, apply the GPO to the Sales Computers OU rather than at the root of your domain?

 

The "sales computers OU" is an empty OU and it doesn't actually contain any computer accounts. (I created it as test)

The current OU structure is by "user accounts" and "departments" all computer accounts are still in the default "computers" container which is why i applied the policy to the whole domain.

 

Do you think it would be good practice to separate computers into different OUs as well?

Posted
Thanks, but my main issue is to get the policy to show-up as applied GPO which without it i don't think it would work at all.

 

The GPO will be shown as applied. You can check it on a workstation using admin local user (or other with privileges) and rsop

Posted

Is there another solution rather than moving the computers into an OU and assigning the GPO to the OU?

 

Example: Root level GPO with security filtering (what i've been trying to do but it's not working)

Posted (edited)

0k, this is what I do

 

screenshot1.png

 

screenshot2.png

 

screenshot3.png

 

and it works....

 

I have a 2008 R2 Functional Level and W7 workstations

 

Before, I had 2003 R2 servers and FL and the only way I was able to do it was with a script (as I said in previous replies)

 

Try using %windir% instead of C:\Windows

Edited by vimagoes
  • Thanks 1
Posted (edited)
0k, this is what I do

 

[ATTACH=CONFIG]35715[/ATTACH]

 

[ATTACH=CONFIG]35713[/ATTACH]

 

[ATTACH=CONFIG]35716[/ATTACH]

 

and it works....

 

I have a 2008 R2 Functional Level and W7 workstations

 

Before, I had 2003 R2 servers and FL and the only way I was able to do it was with a script (as I said in previous replies)

 

Try using %windir% instead of C:\Windows

 

Thanks,

I'm using Windows Server 2012 R2 functional level + W7 clients

I'm gonna try this way as well, so far on my side it finally started showing up in the results (I guess it needed more time (couple of hours))

but another issue that came up is that i noticed from the list of the computers i've put this policy on, some got the policy as "applied" and some have it as "denied" which makes no sense because all users/computers from that list are have the same other policies (technically) but somehow it's getting denied for some reason.

 

what do you guys use to narrow down where these permissions are getting inherited from? (something more detailed than GPresults)

 

Thank you.

Edited by Alexir

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...