Joanne Posted May 5, 2017 Posted May 5, 2017 Right, got Windows 10 Enterprise here. User assigned to the following security groups: staff, slt, sims. I have a 2008 R2 PDC and a 2012 R2 DC. 3 Group Policies - staff settings (maps 4 drives), slt drive map (maps 1 drive), s drive map (maps 2 drives). User config, Preferences, Windows Settings, Drive Maps. Staff settings applies to staff security group. SLT drive map applies to SLT security group. S Drive map applies to SIMS security group. Logging on user only gets the staff settings applied. GPResult confirms that SLT and SIMS policies have not been applied. If I manually map them, they show up fine, so it's not a permissions issue. WHAT IS IT?!?!
JonThompson Posted May 5, 2017 Posted May 5, 2017 Are the policies security filtered? Are they assigned to the correct OU's?
Martin48 Posted May 5, 2017 Posted May 5, 2017 recommend running "gpresult /h path_to_store_report.htm" on each of the accounts on the client pcs to see what it actually processes and sees..
ollyyllo Posted May 5, 2017 Posted May 5, 2017 Does this only affect a single user? Are they in an OU that has all 3 policies applied to it? If your doing item level targeting using security groups, why not just have one group policy, and put it in a OU that applies to all users.
sted Posted May 5, 2017 Posted May 5, 2017 you might do better putting them all on 1 policy but using targeting to give out the slt/sims drive maps rather than a separate policy
Joanne Posted May 5, 2017 Author Posted May 5, 2017 (edited) The problem with having just 1 policy is that the drives still show up in This PC, but the user can't access them. I'd rather that they didn't show up at all. Correct OUs yes. They are security filtered and it is happening on my new Windows 10 machines for the users logging onto them. HOWEVER - when I log on I get all of the correct mapped drives (as domain admin). GPResult: User is part of these security groups: staff SLT SIMS etc. Applied Group Policy Objects: Staff Settings Office Settings Default Domain etc. Following GPOs not applied: Local Group Policy Filtering: Not Applied (empty) User is in this OU and has the following GPOs applied. User is member of the correct security groups. Edited May 5, 2017 by Joanne
sted Posted May 5, 2017 Posted May 5, 2017 (edited) The problem with having just 1 policy is that the drives still show up in This PC, but the user can't access them. I'd rather that they didn't show up at all. thats where targeting comes in it wont show for anyone not in the target group. I generally have my drive map policy at domain root level so it can apply to everyone but only allow specific drives to specific groups Edited May 5, 2017 by sted 1
Chuckster Posted May 5, 2017 Posted May 5, 2017 Run the command from your machine against each user that is currently logged in on the affected machine... gpresult /r /s machinename /user:NETBIOS\username This will list all the GPOs that have been applied (and what hasn't because of WMI filtering) and what security groups the affected user is in.
ollyyllo Posted May 5, 2017 Posted May 5, 2017 (edited) Rather than use Security filtering, you could use Item-level targeting, users wont be able to see the drive in This PC unless they are a member of the security group allocated. Might be worth testing. In the properties of each drive map, under the common tab you can select item-level targeting and add a rule for Security Group, remember to change the item option to 'Or' if your targeting multiple groups. Edited May 5, 2017 by ollyyllo 1
Joanne Posted May 5, 2017 Author Posted May 5, 2017 Yes! Item Level Targetting works! Although you have to remove the local profile from the machine first. Just weird that it would apply one policy which is almost the same as the others, but discriminate against them!!
sted Posted May 5, 2017 Posted May 5, 2017 Yes! Item Level Targetting works! Although you have to remove the local profile from the machine first. Just weird that it would apply one policy which is almost the same as the others, but discriminate against them!! diddnt gpo get "broken" a while ago so you cant just put a user/group against a policy as the pc then cant read/apply it you need to add say staff and domain computers
Joanne Posted May 5, 2017 Author Posted May 5, 2017 the staff settings one does have the staff security group and authenticated users... hmmm...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now