Jump to content

Recommended Posts

Posted

Hi all, I have configure the GPO Interactive logon: Do not require CTRL+ALT+DEL and scoped it to a small suite of W10 Enterprise LTSB machines, however the policy does not seem to be working. Having done rsop.msc on one of the machines, the policy is there and shows the source GPO as being the correct one but it still doesn't have the desired affect. Bit of a head scratcher. Any advice would be most appreciated because it's little things like this that prevent me from sleeping at night! LOL

 

 

Ta very much.

Posted
Hi all, I have configure the GPO Interactive logon: Do not require CTRL+ALT+DEL and scoped it to a small suite of W10 Enterprise LTSB machines, however the policy does not seem to be working. Having done rsop.msc on one of the machines, the policy is there and shows the source GPO as being the correct one but it still doesn't have the desired affect. Bit of a head scratcher. Any advice would be most appreciated because it's little things like this that prevent me from sleeping at night! LOL

 

 

Ta very much.

You sure there isn't other policy applied over ruling this one?
Posted
The same settings were being applied to the Computers OU but not working, so I created a GPO in the OU which contains all the machines in the suite (this should take precedence), but still not applying despite the policy being received by the machines.
Posted (edited)
Create a group adding the computer you want this policy being applied and apply this policy to the group instead to Authenticated Users. (Assuming you are not doing this already, also assuming you are using Computer settings on the GPO) Edited by vimagoes
Posted
Create a group adding the computer you want this policy being applied and apply this policy to the group instead to Authenticated Users. (Assuming you are not doing this already, also assuming you are using Computer settings on the GPO)

 

Not sure I understand that fully. Currently the GPO is linked to the OU with security filtering to Authenticated Users

 

gpo.PNG

Posted
Create a group adding the computer you want this policy being applied and apply this policy to the group instead to Authenticated Users. (Assuming you are not doing this already, also assuming you are using Computer settings on the GPO)

 

Yes, Interactive Logon is indeed a Computer Configuration, and I have it applied to an OU containing computers, and not users.

Posted

Create a Group, add those computers to the group. Then in Delegation Tab untick authenticated user for being applied. Add the group and tick Read and Apply this policy. Restart one computer to be sure it takes the changes. gpupdate /force will do the same but you need to see if the change is made at the login stage, so I'd restart the computer.

 

Authenticated User includes User/Computers joined to the domain but this is just to discard any User policy you may have messing around or a loopback enabled policy. It's worth to try and see if this makes any difference.

Posted
Then in Delegation Tab untick authenticated user for being applied.
- for being applied? - Do you mean from the Delegation tab>Advanced>Authenticated Users and untick Apply Group Policy?

 

 

 

Add the group and tick Read and Apply this policy
- Add which group?
Posted

Ok, sorry for not being very clear.

 

1 - Create security group

2 - Add those computers to this security group

4 - Link the GPO to your OU

5 - Select the Policy and click on Delegation tab

6 - Click on Advanced

7 - Select Authenticated Users and untick "Apply group policy" on Allow column

8 - Add the group you have previously created and tick Allow : "Read" and "Apply group policy"

9 - Now your Scope / Security Filtering will show the group in which this policy is going to be applied

 

I hope now is more clear. :)

Posted
Ok, sorry for not being very clear.

 

1 - Create security group

2 - Add those computers to this security group

4 - Link the GPO to your OU

5 - Select the Policy and click on Delegation tab

6 - Click on Advanced

7 - Select Authenticated Users and untick "Apply group policy" on Allow column

8 - Add the group you have previously created and tick Allow : "Read" and "Apply group policy"

9 - Now your Scope / Security Filtering will show the group in which this policy is going to be applied

 

I hope now is more clear. :)

 

No problem, I just wanted to be sure I've got this right. I'll have a bash at that when I can grab a minute. Thanks!

Posted

Quick update on this. Done all the above but still machines are not at the logon screen. I have got the correct GPO setting haven't I? The machines are sat at this screen:

 

screen.PNG

 

And in order to prompt the login username / password fields, we have to CTRL+ALT+DEL or hit any key.

Posted (edited)
Quick update on this. Done all the above but still machines are not at the logon screen. I have got the correct GPO setting haven't I? The machines are sat at this screen:

You need to enable the GPO that disables the lockscreen.

 

This is the policy you need to change...

 

https://gpsearch.azurewebsites.net/#7401

Edited by Arthur
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...