Olliedawg Posted January 27, 2023 Posted January 27, 2023 Hey all, At the moment, we have no way of doing a mass gpupdate /force. If a change has been made to a group of classroom PC's for example, we have to manually go and type this command in using admin creds, to ensure the change is made & not relying on the automatic refresh of GP. I have seen that you can force a gpupdate to an entire OU within GPMC, although when I try to do this I get errors stating connection blocked / RPC not available. This can be fixed via a simple starter GPO apparently named " Group Policy Remote Update Firewall Ports ". For some reason, this is not in my list of starter GPO's on any of my 3 DC's. Does anybody know how I can get this to appear? Or why it would be missing? DC's Windows Server 2012 R2 TIA
mavhc Posted January 27, 2023 Posted January 27, 2023 Probably because you're still using 2012 R2, which expires in Oct 2023. I'd just make a new gpo from scratch. https://support.auvik.com/hc/en-us/articles/204424994-How-to-enable-WinRM-with-domain-controller-Group-Policy-for-WMI-monitoring might help
Olliedawg Posted January 27, 2023 Author Posted January 27, 2023 Probably because you're still using 2012 R2, which expires in Oct 2023. I'd just make a new gpo from scratch. https://support.auvik.com/hc/en-us/articles/204424994-How-to-enable-WinRM-with-domain-controller-Group-Policy-for-WMI-monitoring might help Thanks for that will check it out. We are looking to migrate DC's to either 2016 or 2019 this summer, as those are the only remaining VM's we have, which are not at a minimum of 2016.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now