Gongalong Posted June 25, 2025 Posted June 25, 2025 I’ve got an issue with GPO processing order. The background is that we have a GPO that applies to all staff and sets the screensaver timeout to 10 mins, that’s done under User Configuration > Policies > Administrative Templates > Control Panel > Personalization > Screen saver timeout. That’s coupled with two other settings in the same folder, to Password protect the saver, and to Enable the screen saver. We have a separate issue with some staff that have been caught several times with unlocked PCs, and the plan is to set their timeout to 2 minutes. Therefore, I have created a new GPO with that setting and moved it above in link order. My understanding is that a GPO that’s above will be processed first, yet it doesn’t seem to take effect and 10 minutes still applies. I’ve tried moving it below for lack of a better idea, same problem. The first GPO is applied to a user group which includes the test user, whereas the second GPO only applies to the test user. Any ideas why this isn’t working? I’ll tinker some more and double check that it isn’t set in any other GPOs. Thanks
Steve21 Posted June 25, 2025 Posted June 25, 2025 I’m sure we had something similar to that before and it’s because there’s two “lock/screensaver” timers Setting the wrong one as such is always overridden by the right one that defaults to 10 minutes so unless you reduce both it looks like neither works Let me see if I can find my old notes Steve 1
Gongalong Posted June 26, 2025 Author Posted June 26, 2025 I've used gpresult, and the GPO isn't showing at all for this user. Under scope > security filtering I have added a group that the user is a member of, and also the user directly. Is authenticated users also required, or will that then apply it anyone who logs in?
CHiLL Posted June 26, 2025 Posted June 26, 2025 Isn't the GPO process order backwards? As in if it's higher in the priority list, it gets applied first but the last policy applied wins? Therefore shouldn't your new 2 minute policy be set lower in the order, so it's applied after the 10 minute priority and thus be set?
Steve21 Posted June 26, 2025 Posted June 26, 2025 If you scoped it and removed auth users then you need to add auth users back into the delegation tab else they won’t be able to read it Steve
Davit2005 Posted June 26, 2025 Posted June 26, 2025 (edited) Think the better option would be to teach users to lock their PCs. Enough damage could be done in 10 seconds let alone 10mins. This is for their own protection not jus for protection of the network and it's data. This should be followed up/enforced by senior staff members and policies. At the end of the day if something happens and it is traced to the PC is staff member going to be able to prove it wasn't them. In first Edu role I was in there were loads of issues caused by students when the staff member was away from their desk and had left their PCs unlocked. Edited June 26, 2025 by Davit2005
Gongalong Posted June 27, 2025 Author Posted June 27, 2025 20 hours ago, Davit2005 said: Think the better option would be to teach users to lock their PCs. Enough damage could be done in 10 seconds let alone 10mins. This is for their own protection not jus for protection of the network and it's data. This should be followed up/enforced by senior staff members and policies. At the end of the day if something happens and it is traced to the PC is staff member going to be able to prove it wasn't them. In first Edu role I was in there were loads of issues caused by students when the staff member was away from their desk and had left their PCs unlocked. They've been taught, caught, told, repeatedly. I had the opportunity to ask our county legal team, and this was their recommendation. Just trying to do the right thing. Thanks all for the replies. I managed to sort it by separating out the 10 minute screen saver setting into its own policy, and creating a separate 2 minute policy. The 10 minute policy had authenticated users and the relevant staff group in scope, and then under delegation permissions it had the 2 minute group added with deny. In the 2 minute policy, authenticated users had read access under delegation, and had apply group policy unticked.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now