Jump to content

Recommended Posts

Posted

Hi

Just come across an issue after finding out how students are changing some settings.

In GPO I have it set so that the users cannot access control panel so should remove the below from the explorer window.

26-05-2016 19-36-50.jpg

 

Currently I know of 3 PCs of which when the user logs on, the setting is not applied and the button can be clicked and enter control panel. There are also other policy settings that do not apply to these particular PCs - such as accessing UNC paths from the address bar in my computer.

 

If I remove the GPO setting back to not configured, the button appears on all computers. Re-apply the setting and it removes from other computers, but not these ones with the issue!

 

I have

1. Removed from domain, and re-joined

2. check event viewer - says that x number of policies have been applied

3. ran gpupdate /force

4. checked forward and reverse DNS entries - only 1 entry and IP/names match

5. deleted the IP in DHCP, rebooted to get a new address

6. checked GPO management - in one room OU there are 3 pcs out the 26 which the policies do not apply on.

 

As a last resort I was going to re-image the PC, but before I do this, any other suggestions?

Posted
Rename registery.pol file in C:\windows\system32\grouppolicy

 

Reboot and gpipdate again

 

Steve

 

File doesn't exist!

Posted (edited)
You turned hidden and system files to show on? Else would be hidden

 

Steve

 

yep, all turned on..and the folders are empty. Folders are all the same even on the working clients, there is no registry.pol file

 

26-05-2016 19-57-18.png

Edited by ITGURU
Posted

Strange :s That's the one we delete when GPOs locally break. On all the machines I've just checked for us.

 

No idea then I'm afraid if that's not there for you.

 

Steve

Posted

Did you try running rsop.msc on the client machines, as it can show errors.

 

Also, have you looked in event viewer, not at the Application log, but at the Group Policy log?

 

Simon

Posted

RSOP is showing that the policy setting is ENABLED.

No errors showing in the GroupPolicy event log - all information and shows the policy name in the applicable policies!

Posted

Just an update to this - if I re-image the PC and add to the network using the same name , the policy then applies correctly every time.

Therefore it is a local machine issue but not sure what else to check /change/delete that would cure this on the other machines....

Posted

Could it be DNS related?

 

If you ipconfig /all on a station.

 

Is the DNS suffix set correctly - eg: school.local

and are the DNS servers all local DNS Domain Controllers (eg. you dont have any external non-DC DNS entries as secondary or anything for internet access).

 

Is DHCP issuing IPv6 DNS entries? If so, do these resolve local DNS Domain Controllers, and is IPv6 enabled on those servers.

Posted

I wouldn't have thought so, as all workstations are on DHCP. Also I removed all DNS entries for the name before re-imaging, rebooted so grabbed a new IP, and it's still got the same computer name as before.

 

All DNS Servers in DHCP are local ones, then forwarders used for internet sites.

 

Could it be DNS related?

 

If you ipconfig /all on a station.

 

Is the DNS suffix set correctly - eg: school.local

and are the DNS servers all local DNS Domain Controllers (eg. you dont have any external non-DC DNS entries as secondary or anything for internet access).

 

Is DHCP issuing IPv6 DNS entries? If so, do these resolve local DNS Domain Controllers, and is IPv6 enabled on those servers.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...