Jump to content

Recommended Posts

Posted

Right, got Windows 10 Enterprise here. User assigned to the following security groups: staff, slt, sims.

 

I have a 2008 R2 PDC and a 2012 R2 DC.

 

3 Group Policies - staff settings (maps 4 drives), slt drive map (maps 1 drive), s drive map (maps 2 drives). User config, Preferences, Windows Settings, Drive Maps.

 

Staff settings applies to staff security group.

SLT drive map applies to SLT security group.

S Drive map applies to SIMS security group.

 

Logging on user only gets the staff settings applied. GPResult confirms that SLT and SIMS policies have not been applied. If I manually map them, they show up fine, so it's not a permissions issue.

 

WHAT IS IT?!?!

Posted
recommend running "gpresult /h path_to_store_report.htm" on each of the accounts on the client pcs to see what it actually processes and sees..
Posted

Does this only affect a single user?

Are they in an OU that has all 3 policies applied to it?

 

If your doing item level targeting using security groups, why not just have one group policy, and put it in a OU that applies to all users.

Posted
you might do better putting them all on 1 policy but using targeting to give out the slt/sims drive maps rather than a separate policy
Posted (edited)

The problem with having just 1 policy is that the drives still show up in This PC, but the user can't access them. I'd rather that they didn't show up at all.

 

Correct OUs yes. They are security filtered and it is happening on my new Windows 10 machines for the users logging onto them. HOWEVER - when I log on I get all of the correct mapped drives (as domain admin).

 

GPResult:

User is part of these security groups:

staff

SLT

SIMS

etc.

 

Applied Group Policy Objects:

Staff Settings

Office Settings

Default Domain

etc.

 

Following GPOs not applied:

Local Group Policy

Filtering: Not Applied (empty)

 

User is in this OU and has the following GPOs applied.

Capture.PNG

User is member of the correct security groups.

Capture.PNG

Edited by Joanne
Posted (edited)
The problem with having just 1 policy is that the drives still show up in This PC, but the user can't access them. I'd rather that they didn't show up at all.

thats where targeting comes in it wont show for anyone not in the target group. I generally have my drive map policy at domain root level so it can apply to everyone but only allow specific drives to specific groups

 

targeting.png

Edited by sted
  • Thanks 1
Posted

Run the command from your machine against each user that is currently logged in on the affected machine...

 

gpresult /r /s machinename /user:NETBIOS\username

 

This will list all the GPOs that have been applied (and what hasn't because of WMI filtering) and what security groups the affected user is in.

Posted (edited)

Rather than use Security filtering, you could use Item-level targeting, users wont be able to see the drive in This PC unless they are a member of the security group allocated. Might be worth testing.

 

In the properties of each drive map, under the common tab you can select item-level targeting and add a rule for Security Group, remember to change the item option to 'Or' if your targeting multiple groups.

Edited by ollyyllo
  • Thanks 1
Posted

Yes! Item Level Targetting works! Although you have to remove the local profile from the machine first.

 

Just weird that it would apply one policy which is almost the same as the others, but discriminate against them!!

Posted
Yes! Item Level Targetting works! Although you have to remove the local profile from the machine first.

 

Just weird that it would apply one policy which is almost the same as the others, but discriminate against them!!

 

diddnt gpo get "broken" a while ago so you cant just put a user/group against a policy as the pc then cant read/apply it you need to add say staff and domain computers

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...