manamaga2512 Posted November 15, 2018 Posted November 15, 2018 Hi all, I have configure the GPO Interactive logon: Do not require CTRL+ALT+DEL and scoped it to a small suite of W10 Enterprise LTSB machines, however the policy does not seem to be working. Having done rsop.msc on one of the machines, the policy is there and shows the source GPO as being the correct one but it still doesn't have the desired affect. Bit of a head scratcher. Any advice would be most appreciated because it's little things like this that prevent me from sleeping at night! LOL Ta very much.
vimagoes Posted November 15, 2018 Posted November 15, 2018 Hi all, I have configure the GPO Interactive logon: Do not require CTRL+ALT+DEL and scoped it to a small suite of W10 Enterprise LTSB machines, however the policy does not seem to be working. Having done rsop.msc on one of the machines, the policy is there and shows the source GPO as being the correct one but it still doesn't have the desired affect. Bit of a head scratcher. Any advice would be most appreciated because it's little things like this that prevent me from sleeping at night! LOL Ta very much.You sure there isn't other policy applied over ruling this one?
manamaga2512 Posted November 15, 2018 Author Posted November 15, 2018 The same settings were being applied to the Computers OU but not working, so I created a GPO in the OU which contains all the machines in the suite (this should take precedence), but still not applying despite the policy being received by the machines.
vimagoes Posted November 15, 2018 Posted November 15, 2018 (edited) Create a group adding the computer you want this policy being applied and apply this policy to the group instead to Authenticated Users. (Assuming you are not doing this already, also assuming you are using Computer settings on the GPO) Edited November 15, 2018 by vimagoes
manamaga2512 Posted November 15, 2018 Author Posted November 15, 2018 Create a group adding the computer you want this policy being applied and apply this policy to the group instead to Authenticated Users. (Assuming you are not doing this already, also assuming you are using Computer settings on the GPO) Not sure I understand that fully. Currently the GPO is linked to the OU with security filtering to Authenticated Users
manamaga2512 Posted November 15, 2018 Author Posted November 15, 2018 Create a group adding the computer you want this policy being applied and apply this policy to the group instead to Authenticated Users. (Assuming you are not doing this already, also assuming you are using Computer settings on the GPO) Yes, Interactive Logon is indeed a Computer Configuration, and I have it applied to an OU containing computers, and not users.
vimagoes Posted November 15, 2018 Posted November 15, 2018 Create a Group, add those computers to the group. Then in Delegation Tab untick authenticated user for being applied. Add the group and tick Read and Apply this policy. Restart one computer to be sure it takes the changes. gpupdate /force will do the same but you need to see if the change is made at the login stage, so I'd restart the computer. Authenticated User includes User/Computers joined to the domain but this is just to discard any User policy you may have messing around or a loopback enabled policy. It's worth to try and see if this makes any difference.
manamaga2512 Posted November 15, 2018 Author Posted November 15, 2018 Then in Delegation Tab untick authenticated user for being applied. - for being applied? - Do you mean from the Delegation tab>Advanced>Authenticated Users and untick Apply Group Policy? Add the group and tick Read and Apply this policy - Add which group?
vimagoes Posted November 15, 2018 Posted November 15, 2018 Ok, sorry for not being very clear. 1 - Create security group 2 - Add those computers to this security group 4 - Link the GPO to your OU 5 - Select the Policy and click on Delegation tab 6 - Click on Advanced 7 - Select Authenticated Users and untick "Apply group policy" on Allow column 8 - Add the group you have previously created and tick Allow : "Read" and "Apply group policy" 9 - Now your Scope / Security Filtering will show the group in which this policy is going to be applied I hope now is more clear.
manamaga2512 Posted November 15, 2018 Author Posted November 15, 2018 Ok, sorry for not being very clear. 1 - Create security group 2 - Add those computers to this security group 4 - Link the GPO to your OU 5 - Select the Policy and click on Delegation tab 6 - Click on Advanced 7 - Select Authenticated Users and untick "Apply group policy" on Allow column 8 - Add the group you have previously created and tick Allow : "Read" and "Apply group policy" 9 - Now your Scope / Security Filtering will show the group in which this policy is going to be applied I hope now is more clear. No problem, I just wanted to be sure I've got this right. I'll have a bash at that when I can grab a minute. Thanks!
manamaga2512 Posted November 16, 2018 Author Posted November 16, 2018 Quick update on this. Done all the above but still machines are not at the logon screen. I have got the correct GPO setting haven't I? The machines are sat at this screen: And in order to prompt the login username / password fields, we have to CTRL+ALT+DEL or hit any key.
Arthur Posted November 16, 2018 Posted November 16, 2018 (edited) Quick update on this. Done all the above but still machines are not at the logon screen. I have got the correct GPO setting haven't I? The machines are sat at this screen: You need to enable the GPO that disables the lockscreen. This is the policy you need to change... https://gpsearch.azurewebsites.net/#7401 Edited November 16, 2018 by Arthur 1
BKGarry Posted November 16, 2018 Posted November 16, 2018 Silly question, have you run RSOP on the machine? That may tell you if something is taking precedent which is hidden out of the way?
manamaga2512 Posted November 16, 2018 Author Posted November 16, 2018 You need to enable the GPO that disables the lockscreen. This is the policy you need to change... https://gpsearch.azurewebsites.net/#7401 You Sir, are a star!! Thanks for that, I can sleep this weekend :-D
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now