Jump to content

Recommended Posts

Posted

I just noticed that some of my computer based policies are no longer applying on some computers. After a bit of hunting round, I fixed the issue by adding 'Domain computers' to the 'Delegations' tab in the GPO.

 

So whats going on?

Was 'Domain computers' there originally, but MS has been removed from the GPOs at some point.

Did MS make a change that now requires 'Domain computers' under the delegation tab at some point?

Posted
is this the same as adding 'domain computers - read' to security filtering? That happened in 2018.

 

I have no idea if that does the same thing, I just have 'authenticated users' listed there. Perhaps someone else can answer if they do the same job, or which I should be adding 'domain computers' onto.

Posted (edited)

Just found this, so they both do the same thing, more or less.

 

 

If you use the delegation tab of a GPO and click advanced you can assign the Read and Apply permissions to a user or group. if you do this (and if the GPO is linked to the correct level) then the GPO will apply to that user or group. more than this if you do use the delegation tab and click advanced and assign the read and apply permissions to a user or group then that user or group will appear in the security filtering section of the GPO.

 

in reverse if you edit the security filtering section and add a user or group then that user or group will appear on the delegation tab and if you look at advanced you will see that the user or group has appeared there with the read and apply permissions.

 

So the security filtering and the delegation tab advanced are doing the same thing!

 

However using delegation tab you can assign additional permission for the GPO so you could assign permission to edit the gpo for example. in short the delegation tab is more powerful but if you just want the GPO to apply to a user or group you can use either the security filtering or the adv section of the delegation tab.

 

Edited by TwistedHelixis
Posted (edited)

iirc... wasn't it something to do with 'Authenticated Users' ...?

 

I don't have 'Domain Computers' in any of my GPOs, but do have 'Authenticated Users' in the 'Security Filtering' and 'Delegation' (Read from Security Filtering) tab...

 

But, yeah that was also a long time ago... hence the hazy memory!

 

Edit: The question is, have you found out why the GPOs stopped working, did you remove something or did MS...?

Edited by Koldov
Posted
don't have 'Domain Computers' in any of my GPOs, but do have 'Authenticated Users' in the 'Security Filtering' and 'Delegation' (Read from Security Filtering) tab

 

Have you noticed (or checked) any 'Computer' based polices that have recently stopped working?

 

Wondering why I now need to add 'Domain computers' to get the policy applying.

Posted (edited)
Have you noticed (or checked) any 'Computer' based polices that have recently stopped working?

 

No... and I was just going to say I'm not sure if I would notice... :p However, I have just removed the 'Disable USB' GPO to install an OS upgrade from USB and that was working (as in it stopped me) and also allowed USB to work when removed, so it seems to be all OK.

 

Wondering why I now need to add 'Domain computers' to get the policy applying.

 

Do you have 'Authenticated Users' in your GPO? I think it definitely needs to have one or the other depending on if it's computer GPO or user, but 'Authenticated Users' covers both if you know what I mean...?

Edited by Koldov
Posted (edited)

"Does GPO require authenticated users?

To receive the settings from a GPO a computer or user must have Read and Apply rights on the GPO. If they don't have both Read and Apply rights the GPO will not be applied. This might not be something you notice initially as Authenticated Users are assigned Read and Apply by default."

 

More information here:

 

https://www.easy365manager.com/gpo-security-filtering-and-delegation/#:~:text=To%20receive%20the%20settings%20from,Read%20and%20Apply%20by%20default.

 

Plus this:

 

https://community.spiceworks.com/topic/2327373-does-group-policy-always-need-authenticated-users

 

...and this...

 

Mistake #2: Removing “Authenticated Users” from the Group Policy Object Security Filtering

 

EDIT: I didn't fact check these links for accuracy or whether the advice contained within is current (they're just the first few hits in Google for the question).

Edited by Koldov
Posted
Do you have 'Authenticated Users' in your GPO?

Yes I do have Authenticated Users

 

The first GPO that I noticed not applying was the 'Local Users and Groups' policy.

 

I have also just noticed the policy seems to not be applying to our pupil laptops / devices only, but is still applying to our teaching staff. Does that take us any closer to working out whats going on?

I assumed all domain users (teachers and pupils) are automatically added to 'Authenticated users', perhaps this is not the case.

Posted (edited)

What does 'gpresult /r' show for 'Computer Settings' on an affected machine?

 

Especially 'Applied Group Policy Objects', 'The following GPOs were not applied...' and 'The computer is part of the following......'

Edited by Koldov
Posted
@Koldov thanks, ill take a look at those links

 

I think they'd only really be relevant if you didn't have 'Authenticated Users' or 'Domain Computer' in the GPO, as you do, then possibly there is something else going on as you say...

Posted
I've also had to use Domain Computers in the past for GPOs was a long time back, like 2015 so can't remember why I did it but I know I had to do it to get required result.
Posted
To receive the settings from a GPO a computer or user must have Read and Apply rights on the GPO

If I look at the 'Authenticated Users' rights under delegation, it lists read in the main window, but if i then click 'Advanced' it also lists 'apply'.

 

One of the links has this - My preferred method is to configure read permissions on all existing GPOs to "Domain Computers", - although it doesn't go over the reason why.

 

The last link doesnt open = https://azurecloudai.blog/2018/12/31/most-common-mistakes-in-active-directory-and-domain-services-part-1/

 

this is interesting as it says not to use 'Apply' for the authenticated users, but the other site says the opposite, grrrr

Do It Right: When changing Group Policy Security Filtering, make sure you add the “Authenticated Users” group in the delegation tab and provide it with “Read” permission only.
Posted
I think they'd only really be relevant if you didn't have 'Authenticated Users' or 'Domain Computer' in the GPO, as you do, then possibly there is something else going on as you say...

I didn't have 'Domain Computer' in the GPO originally. It only started working after I added that as read only.

 

I've also had to use Domain Computers in the past for GPOs was a long time back, like 2015 so can't remember why I did it but I know I had to do it to get required result.

 

Always good to know its not just me

Posted
What does 'gpresult /r' show for 'Computer Settings' on an affected machine?

 

Especially 'Applied Group Policy Objects', 'The following GPOs were not applied...' and 'The computer is part of the following......'

 

Just heading out the door and not back at this school for a few weeks now.

Posted (edited)

Thing is, I'm not sure what angle to go with, don't get too hung up on it as it probably might not be the 'Authenticated User' or 'Domain Computer' part... say if you get 2 computers (in their respective OUs) and apply the same computer GPO, if one gets it and the other doesn't that points to the object being the 'issue' not the policy, no?

 

Other questions:

 

When was the last time you knew it worked?

Have you done anything since then?

Is there anyone else on site that could have?

 

 

All my policies are very simple and just do the thing... I've never looked into messing about with delegation, filtering, loopback, WMI, etc. They mostly just contain the defaults for all those things.

 

Link opens for me no problem, is it blocked by your filtering as a blog?

 

What about the cached version?:

 

https://webcache.googleusercontent.com/search?q=cache:OGXWJqAaUeoJ:https://azurecloudai.blog/2018/12/31/most-common-mistakes-in-active-directory-and-domain-services-part-1/&cd=2&hl=en&ct=clnk&gl=uk

Edited by Koldov
Posted
Just heading out the door and not back at this school for a few weeks now.

 

No worries... :D

 

Just as a test what do your default policies get created as?

 

I just created a basic 'no setting' TEST GPO:

 

Auth.jpg

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...