Quillyn Posted September 21, 2017 Posted September 21, 2017 We have a issue with a few stubborn machines with GPOs and we are really struggling to pin it down. On the majority of machines new to the network all GPOs are seen and apply successfully, yet on some only 2-3 GPOs are seen and applied. All the machines that were on the network before the summer are fine as well. gpresult /r or /h on such machines just does not list the GPOs as applied Policy objects or denied GPOs or even recognise they should be applied. The main issues with machines seem to be windows 10 laptops all getting 2/10 GPOs. One of the techs here is sure that one of the windows 7 desktops was getting 10/10 GPOs but now its at 3/10. - At this stage we have only been testing with domain admin logins to keep this consistent. - There are no errors in the group policy event viewer on machines short on GPOs - We have checked GPO replication and both servers are identical and the issue appears no matter which of the server the GPOs are pulled from. - Applied GPOs are always internet settings/ printers / security missing GPOs tend to be drive maps/ redirections Any ideas what else we should be looking at?
Steve21 Posted September 21, 2017 Posted September 21, 2017 Normally if it's majorly broke best way to clear it I find is delete the secedit database and the gpo history folder, reboot, gupdate and reboot again And it should pull down all policies again Steve
Quillyn Posted October 2, 2017 Author Posted October 2, 2017 Hmm seems my first reply went awry. Cleared the database, the GPO history folder was not created (windows 10) but did clear system32/grouppolicy. Sadly on two test machines I am left with the same 2 GPOS. We have also tried Rejoining the domain Re imaging of one machines
jamesreedersmith Posted October 2, 2017 Posted October 2, 2017 Are you reusing machine names - i have seen it before that AD doesnt tell the machine to reapply if the machine name still existed and was effectively overewritten. try remove, new SID, renmae, rejoin to domain and gpupdate /sync
Quillyn Posted October 9, 2017 Author Posted October 9, 2017 Been trying a number of things again no luck as yet... Cheers for the suggestion, we tried it with a couple of windows 10 laptops but they are still only pulling down 2 GPOs. We have noticed that the GPOs go out fine to our 2016 servers in full every time so it does not seem to be compatibility.
ollyyllo Posted October 9, 2017 Posted October 9, 2017 Some simples things if you haven't already checked... Are the machine in the same OU as other machines that are working? Are you using security filtering on any of your GPO's, are the machines in the required groups?
Steve21 Posted October 9, 2017 Posted October 9, 2017 When you say some of the laptops are Win10 are they all those that are failing? As in older ones on Win7 work? If so could be something silly like WMI filter. Also is it the same GPOs that are always missing? As from your last comment it sounds like the issue with you having security filters but not modifying the GPOs to allow users to read them since the changes a while ago. e.g. If one that fails has it filtered to students, did you re-put auth users in the delegation tab? Steve
Quillyn Posted October 9, 2017 Author Posted October 9, 2017 For testing purposes we are testing / trying to fix using the same domain admin logon. We have a fair few new windows 10 laptops that are all pulling down only the same 2 GPOs. We have some windows 7 machines most of which work, some which only pull down two or three GPOs all based on images that have been in place about 18 months. Some of the GPOs that are not being pulled down are all authenticated users on the entire domain.
Steve21 Posted October 9, 2017 Posted October 9, 2017 It might help if you throw a few screenshots up of an example one with it's settings (Auth and Links), and the machine it's supposed to apply to OU wise etc. If all of them are pulling the same 2 down Win10 wise, it's more likely something is up with the GPO or link rather than each machine, unless a patch has borked something. Even something silly like an old WMI filter in place that's causing it to be filtered out The "realllly" old ones might just have a local cache already, and it's something else that's borked so all new ones wouldn't apply it Steve
TwistedHelixis Posted October 9, 2017 Posted October 9, 2017 I would also take a look at DNS and make sure the computers not getting the policies are not shearing the same ip's as another network computer.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now