sippo Posted November 6, 2008 Posted November 6, 2008 I have put in a Ctrl, Alt and Delete GPO so that users can see the Code of conduct before logging in. This has applied to some managed PC's but not all. I have tried a GPupdate force, but still nothing. It says it has applied the policy, but it hasn't. Is there a local service that needs to be started. It seems as if the local policy is over-riding the network one.
Ric_ Posted November 6, 2008 Posted November 6, 2008 Use GPMC (Group Policy Management Console) to run a GP Results report. This should tell you why the GPO hasn't applied. There will undoubtably be an error in the logs about it.
dbsocs08 Posted November 6, 2008 Posted November 6, 2008 Same as Ric_, but also try running the RSOP snap-in on the machines that aren't working, at least then you'll be able to see what is being applied by GPO and then check the events to watch for errors.
dtakias Posted November 6, 2008 Posted November 6, 2008 I have put in a Ctrl, Alt and Delete GPO so that users can see the Code of conduct before logging in. This has applied to some managed PC's but not all. I have tried a GPupdate force, but still nothing. It says it has applied the policy, but it hasn't. Is there a local service that needs to be started. It seems as if the local policy is over-riding the network one. It should work for every PC that is managed by the domain, as the domain policy takes priority over the local one. Obviously this entry should be disabled or 0 otherwise LegalNoticeCaption and LegalNoticeText will not work. Also try running rsop.msc on the PCs that fail to pick up the policy just after you are logged on the domain. That should tell you if the policy has been applied locally
sippo Posted November 6, 2008 Author Posted November 6, 2008 Use GPMC (Group Policy Management Console) to run a GP Results report. This should tell you why the GPO hasn't applied. There will undoubtably be an error in the logs about it. How do I do this?? Is it on the server or local client?
dtakias Posted November 6, 2008 Posted November 6, 2008 How do I do this?? Is it on the server or local client? It's on the server. I think this is what he means...
sippo Posted November 6, 2008 Author Posted November 6, 2008 See I've done a gpresult on a client pc, it says it has been applied but you can clearly see it hasn't.
Nick_Parker Posted November 6, 2008 Posted November 6, 2008 I have put in a Ctrl, Alt and Delete GPO so that users can see the Code of conduct before logging in. This has applied to some managed PC's but not all. I have tried a GPupdate force, but still nothing. It says it has applied the policy, but it hasn't. Is there a local service that needs to be started. It seems as if the local policy is over-riding the network one. We had a problem with GP applying because we had a 2nd Domain Controller (as a backup) and it was somehow taking control, but didn't have the logon scripts available. Just out of interest, how are you doing the Code of Conduct?? I'm looking for a way of doing it @ our college
sippo Posted November 6, 2008 Author Posted November 6, 2008 Nick we have a 2nd domain controller aswell, but how did you realise 'it was taking over'? As for the code of conduct, its just something I wipped up. I'll see if I can dig out an electronic copy.
dbsocs08 Posted November 6, 2008 Posted November 6, 2008 Have you created a new GPO or added it to an existing one?
sippo Posted November 6, 2008 Author Posted November 6, 2008 At first I put in a existing one which didn't work, then I created a new one.
dbsocs08 Posted November 6, 2008 Posted November 6, 2008 OK mate, no worries, didn't wanna sound patronizing about checking that the new GPO is assigned to all machines, created under a stations OU? :)
dbsocs08 Posted November 6, 2008 Posted November 6, 2008 have you tried running the rsop snap in on the client machine, I know the GPO results showed that it had applied, but obviously it hasn't. If you run that you can see exactly what is being applied to the machine.
Gatt Posted November 6, 2008 Posted November 6, 2008 There's a reg hack for the issue of 2 DCs - something to do with DC priorities... linky 1 - LdapSrvWeight Linky 2 - LdapSrvPriority Had this issue myself - only noticed cos of my KiX scripts!
sippo Posted November 6, 2008 Author Posted November 6, 2008 Make a local copy of \\FCC.local\SysVol\FCC.local\Policies\{BDABA1CB-0280-46C8-833E-962DAFBEB74E}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf. GPLinkDomain Make a local copy of \\FCC.local\SysVol\FCC.local\Policies\{C7FAA822-4CF9-46A1-B0A4-4B44C48540AE}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf. GPLinkOrganizationUnit Make a local copy of \\FCC.local\SysVol\FCC.local\Policies\{01872F1E-05C1-4EEF-BB3C-0548042D91E0}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf. GPLinkOrganizationUnit Make a local copy of \\FCC.local\sysvol\FCC.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf. GPLinkDomain Process GP template gpt00000.dom. This is not the last GPO. ------------------------------------------- 06 November 2008 12:34:40 Error 1208: An extended error has occurred. Error creating database. ----Configuration engine was initialized with one or more errors.----
sippo Posted November 6, 2008 Author Posted November 6, 2008 I've sorted it now. Thanks for your help everyone. The local security policy was corrupt. Means I have to ghost hell of a lot of pc's now!!
Gatt Posted November 6, 2008 Posted November 6, 2008 Hang fire on the Ghosting - you should be able to repair the Local Security Policy Step-by-Step Guide to Using the Security Configuration Tool Set
Gatt Posted November 6, 2008 Posted November 6, 2008 (edited) Hmmm.. Ok try this link How to reset security settings back to the defaults Which is what i meant in the first place Edited November 6, 2008 by Gatt
ZeroHour Posted November 6, 2008 Posted November 6, 2008 You could try this: How to reset security settings back to the defaults
ZeroHour Posted November 6, 2008 Posted November 6, 2008 LOL you posted while I was hunting the link out
sippo Posted November 7, 2008 Author Posted November 7, 2008 Resetting the Security policy doesn't fix the corrupt database unfortunately.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now