Jump to content

Recommended Posts

Posted

Does it have a dhcp lease?

Did it deregulated in dns?

Did it join the domain without error? Where in you AD is the computer now?

Does gpupdate /force work?

Posted
Have you time synced with domain controller if more then 5 mins out if can do this. Also check regional settings are correct including county
Posted
Does it have a dhcp lease?

Did it deregulated in dns?

Did it join the domain without error? Where in you AD is the computer now?

Does gpupdate /force work?

 

Hmm. When I do ipconfig on the laptop, it gives me an IP address but when I look at the DHCP client list on the router, that IP address isn't listed.

 

Also, when I ping the laptop's name from any computer, not just the domain controller, it times out. However, it does find the IPv6 address of the laptop.

 

It joined the domain normally, just with no GPOs.

 

gpupdate /force shows an error where it can't resolve the domain controller.

 

Have you time synced with domain controller if more then 5 mins out if can do this. Also check regional settings are correct including county

 

The laptop and the domain controller have the same time.

  • 2 weeks later...
Posted

I've just updated to the Windows 10 Fall Creators update on the laptop and it's still not resolved.

 

Anything else I could try? At this point In really stuck.

 

I don't understand how it works with Windows 7 and not with Windows 10. Everything was working fine until a few weeks ago.

Posted

I'll be honest and say I skipped a few posts but if it's just windows 10 have you done the gpo to disable unc hardening against your dc netlogon and sysvol folders?

 

Steve

Posted (edited)

Is the test domain on the same network using the same IP range and router as your existing one?

 

I had thought of the sysvol hardening as a potential root cause, but I'd have expected you to report that you were unable to browse the sysvol shares if you were hitting that. See:

https://blogs.technet.microsoft.com/leesteve/2017/08/09/demystifying-the-unc-hardening-dilemma/

I note that in your case you can browse the shares, and the errors logged when trying to apply policy are different. I do not believe the solution to lie in this direction.

 

 

Now @Joanne was having a problem with the same symptoms as you and actually found a solution that worked for her few years ago: http://www.edugeek.net/forums/windows/126210-computer-policies-not-applying.html#post1079012

There are some elements (Windows 7 vs 10 and dodgy imaging capture) which may or may not make her solution applicable in your case.

 

More technical detail behind Joanne's solution is in this technet forum post: https://social.technet.microsoft.com/Forums/en-US/7df794c4-542e-4f71-8e66-39bd7a9e41cc/group-policy-access-denied-for-computer-policy-only?forum=winserverGP

The last post in that thread is from somebody having exactly your problem this month, and it worked for them.

 

You have joined the laptop to a new domain, and GPOs work - this is consistent with the issue being cached credentials for your original domain needing a clear out, as per Joanne's issue and the Technet thread.

Edited by psydii
Posted
Is the test domain on the same network using the same IP range and router as your existing one?

 

I had thought of the sysvol hardening as a potential root cause, but I'd have expected you to report that you were unable to browse the sysvol shares if you were hitting that. See:

https://blogs.technet.microsoft.com/leesteve/2017/08/09/demystifying-the-unc-hardening-dilemma/

I note that in your case you can browse the shares, and the errors logged when trying to apply policy are different. I do not believe the solution to lie in this direction.

 

 

Now @Joanne was having a problem with the same symptoms as you and actually found a solution that worked for her few years ago: http://www.edugeek.net/forums/windows/126210-computer-policies-not-applying.html#post1079012

There are some elements (Windows 7 vs 10 and dodgy imaging capture) which may or may not make her solution applicable in your case.

 

More technical detail behind Joanne's solution is in this technet forum post: https://social.technet.microsoft.com/Forums/en-US/7df794c4-542e-4f71-8e66-39bd7a9e41cc/group-policy-access-denied-for-computer-policy-only?forum=winserverGP

The last post in that thread is from somebody having exactly your problem this month, and it worked for them.

 

You have joined the laptop to a new domain, and GPOs work - this is consistent with the issue being cached credentials for your original domain needing a clear out, as per Joanne's issue and the Technet thread.

Yes, everything is on the same subnet.

 

I'll have a look at the other thread.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...