talksr Posted August 5, 2019 Posted August 5, 2019 Hi there, I am quite mystified as to why this is not working... I have vanilla Windows 10 clients on my 2008 R2 server. I have set up a GPO called W10RemoveRun For testing purposes, I have added TStaffsGroup to the Security Filtering. TStaffsGroup is my group for all Teaching Staff users... Here are the configuration settings for the GPO, all pretty simple really... These are the delegation settings: This is the actual setting I am enabling. I note in "Supported on" it doesn't mention Windows 10, but you would assume, if it is supported on earlier OSs, it would be on Windows 10. After several GPUPDATE /FORCE commands reboots etc, it is not working on any system on the site here. Users can right click the start menu on Windows 10 and select and use the run command. They can also access it by pressing Start Menu Key + R. Can anyone give me any ideas on why? I have googled how to disable Run on Windows 10 and several sites like this one are showing that I am doing it the right way. Baffled:(
bald_pig Posted August 5, 2019 Posted August 5, 2019 What does gpresult show for a user in the group? 1
talksr Posted August 5, 2019 Author Posted August 5, 2019 What does gpresult show for a user in the group? I have attached the result to this post. I had to ZIP it as the forum does not allow HTML attachments. GPReport.zip If there is any easier way to link to it, just let me know and I will do it. The computer in question is located in Site>ICT Suite DELL. The GPO in question is located in Site, so it should be getting to this system.
bald_pig Posted August 5, 2019 Posted August 5, 2019 I have attached the result to this post. I had to ZIP it as the forum does not allow HTML attachments. [ATTACH]54612[/ATTACH] If there is any easier way to link to it, just let me know and I will do it. The computer in question is located in Site>ICT Suite DELL. The GPO in question is located in Site, so it should be getting to this system. [ATTACH=CONFIG]54613[/ATTACH] It's a user policy, so it needs to be in the OU the users are in, or you need to enable loopback processing. The only user policies being applied are your chrome and printer policies. 1
talksr Posted August 5, 2019 Author Posted August 5, 2019 It's a user policy, so it needs to be in the OU the users are in, or you need to enable loopback processing. The only user policies being applied are your chrome and printer policies. Thanks so much, that did the trick. I am a little rusty. I am an ICT teacher, but I was originally a network manager. It is hard to remember everything whilst doing the lessons. So it isn't worth me adding the groups to Security Filtering, I should just link the GPO in the teacher user folder for any policies which include user configuration changes?
bald_pig Posted August 5, 2019 Posted August 5, 2019 Thanks so much, that did the trick. I am a little rusty. I am an ICT teacher, but I was originally a network manager. It is hard to remember everything whilst doing the lessons. So it isn't worth me adding the groups to Security Filtering, I should just link the GPO in the teacher user folder for any policies which include user configuration changes? If you want the policies to apply to the users regardless of where they log in, then yes. If you want the policies to apply only when they log on to a computer in a certain ou, then you would need to put the policy in the computer ou and enable loopback processing. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now