Jump to content

Recommended Posts

Posted

This is a bit of an odd one.

 

I've verified that SYSVOL is replicating perfectly. New GPOs appear on both DCs in no time; they're just not all applying to Win7 machines (either user or computer policies). Win10 PCs in the exact same OUs using the exact same user work fine and pick up changes to the same GPOs immediately.

 

I've tried recreating them, importing the settings to a new GPO... No WMI filters are in operation and I've tried reimaging the machines to eliminate any GPO tattooing... These aren't Win10-specific settings either - they're relatively simple things like drive mappings. In event viewer I have a ton of 1085 errors:

 

"Windows failed to apply the Group Policy Printers/Drive Maps/Folder Redirection settings. Group Policy Printers settings might have its own log file. Please click on the "More information" link."

 

Servers are 2012R2 with a functional level of the same.

Posted (edited)

Sounds ACL related, are the permissions correct on the folders which are being redirected?

 

IIRC there was a bug with a certain W7 update which broke GPP drive maps. Required adding "Authenticated Users" read permissions to the "Delegation" tab.

Edited by cscc
Posted (edited)

I tried creating a new GPO to map the netlogon folder (standard permissions). Again, using same user worked fine in Win10 but not Win7.

I also tried adding Domain Computers explicitly to the Security Filtering on the GPO itself.

 

To your last comment - Authenticated Users have read permissions on the Delegation tab by default?

Edited by cakeinmilk
Posted

It has to be "Authenticated Users" in Delegation not in Scope. That's the only security group which cures this issue I believe.

 

Obviously applied to the policy which incorporates the GPP drive maps.

Posted
Ok cool, thats the bug, so remove this and re-add the group and give it read. It should then not say (read from security filtering) next to it. This should resolve the issue.
Posted
Cool, so I removed it, which obviously removed it from Security Filtering. I then added Domain Users in the Security Filtering. No joy. I then explicitly added my test user in there. Still nothing, I'm afraid.
Posted
Did you add Authenticated Users back in with read? That's what cured it for me. Providing it doesn't have (from security filtering) next to it.
Posted

Odd, sorry I'm not sure in that case.

 

Possibly try Domain Computers with read?

 

I think it was KB3159398 that initially broke it but its now incorporated into a roll-up.

Posted (edited)

Thanks - just uninstalling that update on both clients and servers.. fingers crossed.

 

Still no luck, unfortunately...

Edited by cakeinmilk

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...