Jump to content

Recommended Posts

Posted

Hi there, I am quite mystified as to why this is not working...

 

I have vanilla Windows 10 clients on my 2008 R2 server.

I have set up a GPO called W10RemoveRun

For testing purposes, I have added TStaffsGroup to the Security Filtering. TStaffsGroup is my group for all Teaching Staff users...

GPM_General.png

 

Here are the configuration settings for the GPO, all pretty simple really...

W10RemoveRun.png

 

These are the delegation settings:

W10RemoveRunDelegation.png

 

This is the actual setting I am enabling. I note in "Supported on" it doesn't mention Windows 10, but you would assume, if it is supported on earlier OSs, it would be on Windows 10.

RemoveRunSettings.png

 

After several GPUPDATE /FORCE commands reboots etc, it is not working on any system on the site here.

Users can right click the start menu on Windows 10 and select and use the run command. They can also access it by pressing Start Menu Key + R.

 

Can anyone give me any ideas on why?

 

I have googled how to disable Run on Windows 10 and several sites like this one are showing that I am doing it the right way.

 

Baffled:(

Posted
What does gpresult show for a user in the group?

 

I have attached the result to this post. I had to ZIP it as the forum does not allow HTML attachments.

GPReport.zip

If there is any easier way to link to it, just let me know and I will do it. :)

 

The computer in question is located in Site>ICT Suite DELL.

The GPO in question is located in Site, so it should be getting to this system.

SiteStructure.JPG

Posted
I have attached the result to this post. I had to ZIP it as the forum does not allow HTML attachments.

[ATTACH]54612[/ATTACH]

If there is any easier way to link to it, just let me know and I will do it. :)

 

The computer in question is located in Site>ICT Suite DELL.

The GPO in question is located in Site, so it should be getting to this system.

[ATTACH=CONFIG]54613[/ATTACH]

 

It's a user policy, so it needs to be in the OU the users are in, or you need to enable loopback processing. The only user policies being applied are your chrome and printer policies.

  • Thanks 1
Posted
It's a user policy, so it needs to be in the OU the users are in, or you need to enable loopback processing. The only user policies being applied are your chrome and printer policies.

 

Thanks so much, that did the trick.

I am a little rusty. I am an ICT teacher, but I was originally a network manager. It is hard to remember everything whilst doing the lessons.

So it isn't worth me adding the groups to Security Filtering, I should just link the GPO in the teacher user folder for any policies which include user configuration changes?

Posted
Thanks so much, that did the trick.

I am a little rusty. I am an ICT teacher, but I was originally a network manager. It is hard to remember everything whilst doing the lessons.

So it isn't worth me adding the groups to Security Filtering, I should just link the GPO in the teacher user folder for any policies which include user configuration changes?

 

If you want the policies to apply to the users regardless of where they log in, then yes.

 

If you want the policies to apply only when they log on to a computer in a certain ou, then you would need to put the policy in the computer ou and enable loopback processing.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...