Jump to content

Recommended Posts

Posted

Hi,

 

Ive been wrestling with Group Policy today trying to get a policy to apply to a group of users, or even one user.

The modelling wizard comes back exactly as I would expect, but loggin onto that PC with that particular user doesnt seem to apply.

 

Im trying to allow command prompt for that user to diagnose anything really, but it still seems to be blocked.

 

My research this afternoon seems to suggest that to solve this particular problem I need a Read policy (but not apply) in Delegation for my Domain Computers group and possibly Authenticated users.

Ive toggled these on and off all day and Im fed up!

 

Any advice please?

 

Thanks

Posted
use the "group policy results" and pick them up for the workstation that fails. (you can choose for which user) WMI and other pre requisites can stop a deployment.
  • Thanks 1
Posted

Hi, thanks for the reply.. Im not quite sure which area of Group Policy Results you mean though.

 

I can get a GPResult from the workstation Im testing on, although this is more a user logon issue rather than computer.

Im trying to allow command prompt for one user so that I can diagnose why Pastoral Genie cant pull Sims reports using commandreporter.

 

Pastoral Genie has a debug mode, but its output is displayed in command prompt (which closes instantly), so Im purely trying to get command prompt to stay open.

 

Ive used the "User Configuration > Application settings > System > Prevent Access to Command Prompt > Disable" in the hopes it would override the "Enabled" setting higher up the chain.

My GPO Modelling results for a given desktop and user come back as I want, but the GPO doesnt apply on the actual login.

 

Thanks

Posted

You can "enforce" a gpo this will prevent changes to it.

 

Just to be clear is the GPO not applying? or the functionality (of the GPOs) is not as expected?

Posted
Hi, no clues in the event viewer.. good idea though. I wonder if this could be a loopback issue? I though that enforcing the rule would make this overide anything higher up the chain..?
Posted (edited)
Hi, no clues in the event viewer.. good idea though. I wonder if this could be a loopback issue? I though that enforcing the rule would make this overide anything higher up the chain..?

 

Replace wipes out the entirety of the higher up user policy, whereas merge just overwrites the settings in the gpo. I figured this out when none of my drive mappings applied in a certain room - I'd ticked replace instead of merge in error. In that case I had redirected the desktop based on location, which still didn't apply with merge until I recreated the desktop file structure. Strangely, the gpo applied using replace but not merge.

Edited by jdmackay
  • Thanks 1
Posted

I'd try and avoid loopback where ever possible. It always just seems to over complicate things and cause issues without much benefit. Currently trying to unpick the GPOs in a system that had loopback liberally splattered across it.

 

But that is my limited experience, I'm sure some have found fantastic applications.

  • Thanks 1
  • 2 weeks later...
Posted

I got this sorted eventually.. i didnt need to enable command prompt in the end.

 

I tried changing our one GPO with loopback settings to merge and good-god did it break alot of things. :D

 

I was trying to get Pastoral genie working, but it was still blocked by applocker. This was because Pastoral Genie calls (SIMS) commandreporter using the network share path and I'd setup my allow rule for the fully qualified path. Took me a while to spot this.. eventviewer for applocker helped.

 

Thanks for everyones help. :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...