FN-GM Posted October 1, 2009 Posted October 1, 2009 (edited) Hi, Yesterday we had a powercut. Because of this we shutdown all our servers. Last night we powered it all on and everything now works but one thing. Group policy it not applying settings. I have done a gpresult and the policy shows up there but the only way for it to kick in is to run gpupdate /force. Nothing shows in the event logs of servers or clients. We have the clients setup to wait for the network on startup. DNS and replication is running just fine without any problems. We are running Server 2008 Enterprise Domain at 2008 level with XP clients Does anyone have any thoughts? Thanks PS: the user policy applies fine, it is the computer policy with the problem Edited October 1, 2009 by FN-GM
IanT Posted October 1, 2009 Posted October 1, 2009 Double check all DNS Servers? Give all servers a reboot, force replication
FN-GM Posted October 1, 2009 Author Posted October 1, 2009 Done that, reboot and replication. and DNS seems fine
FN-GM Posted October 1, 2009 Author Posted October 1, 2009 Just thought i would update. I am still having problems. I know its not DNS now and have rebooted all the DC's again and still no joy. Replication is going fine and still nothing in the event logs Its abit odd this one
ful56_uk Posted October 1, 2009 Posted October 1, 2009 have you tried wait for network setting as a new gpo and placed that so it applys first?
marekbrad Posted October 1, 2009 Posted October 1, 2009 Have you tried this... Group Policy application fails on a computer that is running Windows 2000, Windows XP Service Pack 1, or Windows XP Service Pack 2
ful56_uk Posted October 1, 2009 Posted October 1, 2009 so are none of the gpo applying or just certain ones, loopback mode?
FN-GM Posted October 1, 2009 Author Posted October 1, 2009 so are none of the gpo applying or just certain ones, loopback mode? nothing like that no Have you tried this... Group Policy application fails on a computer that is running Windows 2000, Windows XP Service Pack 1, or Windows XP Service Pack 2 i might give that a shot in the morning, thanks
DMcCoy Posted October 1, 2009 Posted October 1, 2009 If it's happening on all the clients then it must be something wrong with the servers. What does a full dcdiag show? Are the permissions on sysvol correct?
FN-GM Posted October 2, 2009 Author Posted October 2, 2009 (edited) Hi, I have had a look this morning, i created a new policy and deployed LanSchool MSI. Rebooted the machines and the MSI installed fine. I also impored some ADM templates to set the chanel number. They are the same policy as the software deployment but will only apply with a gpupdate /force. It used to work flawlessly before using the same templates why is this? Edited October 2, 2009 by FN-GM
tmcd35 Posted October 2, 2009 Posted October 2, 2009 I was under the impression that GPO updates happened every x hours (I think the default is 24) +/- a random amount of time (I think the default is upto 45min). These setting can be changed in a GPO. Could it be the machine was outside of it's scheduled GPO refresh time and thus you had to gpupdate /force to get it going?
ricki Posted October 2, 2009 Posted October 2, 2009 Have you tried a dcdiag and a netdiag and see if you get any errors. Also have you tried rebooting the switch or switches switches sometimes have a wobbler with power surges. I think the group policy refresh interval is under Computer Configuration, Administrative Templates, System, Group Policy in gpo Richard
Guest blacksheep Posted October 2, 2009 Posted October 2, 2009 I was under the impression that GPO updates happened every x hours (I think the default is 24) +/- a random amount of time (I think the default is upto 45min). These setting can be changed in a GPO. Could it be the machine was outside of it's scheduled GPO refresh time and thus you had to gpupdate /force to get it going? regardless of those settings GPO is refreshed when a client reboots, those setting are for when the machine is in use.
jsnetman Posted October 2, 2009 Posted October 2, 2009 We had issues like that maybe 1 or 2 years ago but it happened randomly on some machines. Turned out the security database was corrupt on those stations. There are tools to analyze and report the state of the database, start by searching for secedit. Don't know if this is your problem but at least you could rule it out by looking. 1
Guest blacksheep Posted October 2, 2009 Posted October 2, 2009 Chances are if ALL machines are doing it then 99% chance its server related, if only a couple then what jsnetman said is another avenue to explore. I hate GP sometimes
tmcd35 Posted October 2, 2009 Posted October 2, 2009 We had issues like that maybe 1 or 2 years ago but it happened randomly on some machines. Turned out the security database was corrupt on those stations. There are tools to analyze and report the state of the database, start by searching for secedit. Don't know if this is your problem but at least you could rule it out by looking. Could be an answer to some random problems I'm having here.
Cools Posted October 2, 2009 Posted October 2, 2009 Have you tried this... Group Policy application fails on a computer that is running Windows 2000, Windows XP Service Pack 1, or Windows XP Service Pack 2 i had this proble. I did the the link said and it fixed it .. then i made a GPO for all PCs.. my adm File i use (and a few tweaks) i run the same setup 2008 an xp (dont we all) lol ------------------------------cut below and past--------------------------------- ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; CLASS MACHINE ;;;;;;;;;;;;;;;;;;;; ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; CATEGORY !!COSOFTWARE CATEGORY !!CADEL KEYNAME "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" POLICY !!CADELPOL EXPLAIN !!CADELTXT PART !!CADELPRT CHECKBOX VALUENAME "DisableCAD" VALUEOFF NUMERIC 0 VALUEON NUMERIC 1 END PART END POLICY END CATEGORY ; CADEL CATEGORY !!GPNST KEYNAME "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" POLICY !!GPNSTPOL EXPLAIN !!GPNSTTXT PART !!GPNSTPPRT NUMERIC VALUENAME "GpNetworkStartTimeoutPolicyValue" MIN 30 MAX 600 DEFAULT 60 END PART END POLICY END CATEGORY ; GPNST CATEGORY !!GPNST2 KEYNAME "SOFTWARE\Policies\Microsoft\Windows\System" POLICY !!GPNST2POL EXPLAIN !!GPNST2TXT PART !!GPNSTP2PRT NUMERIC VALUENAME "GpNetworkStartTimeoutPolicyValue" MIN 30 MAX 600 DEFAULT 60 END PART END POLICY END CATEGORY ; GPNST2 CATEGORY !!Wallpaper KEYNAME ".DEFAULT\Control Panel\Desktop" POLICY !!Wallpaper EXPLAIN !!Wallpaper_Help PART !!WallpaperName EDITTEXT REQUIRED VALUENAME "Wallpaper" END PART PART !!Wallpaper_Tip1 TEXT END PART PART !!Wallpaper_Tip2 TEXT END PART END POLICY END CATEGORY; Wallpaper END CATEGORY; COSSOFTWARE ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; CLASS USER ;;;;;;;;;;;;;;;;;;;; ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; CATEGORY !!COSOFTWARE END CATEGORY; COSSOFTWARE [strings] COSOFTWARE="Custom GPO Settings" CADEL=" Disable CTRL - ALT - DEL at logon" CADELPOL="Disable CAD Logon" CADELPRT="Disable CAD" CADELTXT="Select the settings you want to Disable CTRL ALT DEL at logon on networked computers" GPNST="Group Policy network start timeout policy" GPNSTPOL="Group Policy network start timeout policy" GPNSTPPRT="Group Policy network start timeout policy" GPNSTTXT="This entry defines the number of seconds to wait before trying to run the Group Policy startup script again. To find the value that will work for your configuration, define a decimal value of 60, and then increase the value until the problem is resolved. " GPNST2="Group Policy network start timeout policy" GPNST2POL="Group Policy network start timeout policy" GPNSTP2PRT="Group Policy network start timeout policy" GPNST2TXT="This entry defines the number of seconds to wait before trying to run the Group Policy startup script again. To find the value that will work for your configuration, define a decimal value of 60, and then increase the value until the problem is resolved. " Wallpaper="Desktop Wallpaper At ATL+CTRL+DEL login" Wallpaper_Help="Specifies the desktop background ("wallpaper") displayed on all Computers Login Screen.\n\nThis setting lets you specify the wallpaper Login ' The wallpaper you specify can be stored in a bitmap (*.bmp) file.\n\nTo use this setting, type the fully qualified path and name of the file that stores the wallpaper image. You can type a local path, such as C:\Windows\web\wallpaper\home.jpg or a UNC path, such as \\Server\Share\Corp.jpg. If the specified file is not available when the user logs on, no wallpaper is displayed. Users cannot specify alternative wallpaper. You can also use this setting to specify that the wallpaper image be centered, tiled, or stretched. Users cannot change this specification.\n\nIf you disable this setting or do not configure it, no wallpaper is displayed. However, users can select the wallpaper of their choice.\n\nAlso, see the "Allow only bitmapped wallpaper" in the same location, and the "Prevent changing wallpaper" setting in User Configuration\Administrative Templates\Control Panel.\n\nNote: You need to enable the Active Desktop to use this setting.\n\nNote: This setting does not apply to Terminal Server sessions." WallpaperName="Wallpaper Name:" WallpaperStyle="Wallpaper Style:" WallpaperStyle_Center="Center" WallpaperStyle_Tile="Tile" WallpaperStyle_Stretch="Stretch" Wallpaper_Tip1="Example: Using a local path: C:\windows\web\wallpaper\home.jpg" Wallpaper_Tip2="Example: Using a UNC path: \\Server\Share\Corp.jpg"
FN-GM Posted October 2, 2009 Author Posted October 2, 2009 woo hoo fixed it. Right click the policy then enforce it. No idea why
ful56_uk Posted October 2, 2009 Posted October 2, 2009 enforce will do the following Enforced: This was previously referred to in Win2K as "No Override". The Enforced flag is set on a GPO link using the GPMC. Essentially what is does is say, "If there are any conflicting policy settings on downstream GPOs (GPOs processed after the enforced GPO), those settings will always be overridden". Essentially how this works is that any GPO links that are marked as Enforced, will be moved to the bottom of the Group Policy processing list. This ensures that the enforced policy is always processed last, and thus "wins" over any downstream GPOs. Enforced GPOs will override Block Inheritance (described next). 1
Guest blacksheep Posted October 2, 2009 Posted October 2, 2009 (edited) Had probs with redirection of folders with some strange error code but never got to sorting it out, totally random! Tend to encourage users to use their mapped drives Also IE proxy settings, only worked when had no unset GPO after it. As if they was no such thing as an unset proxy entry. Glad to hear you sorted it GPO are not the best thing, bring on scripts (well ok when they work) Edited October 2, 2009 by blacksheep
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now