Jump to content

Recommended Posts

Posted

Hi all,

 

Wondered if any of you have any ideas about the following. I have created a GPO for students with all the necessary lock downs tweaks etc. However, using a test account, it is not filtering to all machines that I log onto. Those machines that it has not filtered onto, using the test account, I can get into the group policy and notice that some of the policies are not even listed nevermind set. Any idea why this would be?

 

Cheers

 

Manick

Posted

Install Gp Management console on the server then run a test from there and it will tell you if the correct GP is being applied.

 

It could be that the default domain policy is being applied unless you block inheritance of it.

 

GP Management Console will tell you for sure.

Posted

rsop.msc will only show you the policy for the currently logged on pc and the machine though. you would be unlikely to be able to run this while on a student account as the run command should be disabled so you will be unable to check wether the student accounts get the correct policy applied.

 

The best route for all Group Policy needs is Group Policy Management Snap in.

Posted

Lo again,

 

Right, first, thanks for the replies, however, looked at the tests etc and the following is the results.

 

inheritance isn't blocked

 

when trying to run the group policy results wizard, i get the following error:

 

"Failed to connect to [pc] due to error listed below. Ensure that the WMI service is enabled on the target computer and consult the event log for further details.

 

The RPC server is unavailable."

 

WMI is enabled, nothing out of the ordinary in Event Viewer, rpc is running on the local machine.

 

Any ideas (again???)

 

many thanks

 

manick

Posted

Running rsop.msc as an admin user on a client will indicate if the group policy infrastructure is failing for the user or computer configuration components. It also gives a good indication that DNS is configured correctly on the client, which would be my next suggestion.

 

Can you ping the DC using the FQDN?

Posted

lo,

 

Logged on as student can ping dc using FQDN, also rsop shows that computer config isn't applying correctly.

 

What does that point to then???

 

Thanks

 

manick

Posted

Right click the properties of computer configuration, click the error information tab and post the results.

 

Re-joining the client to the domain may resolve the issue though, and sometimes this is quicker than diagnosing GPO issues.

Posted

OK with your help, we are slowly getting there!

 

No errors but pupil group policy isn't being picked up at all for computer config, I can't understand this though as about half of our machines are picking it up!?

 

In security filtering, only authenticated users is listed, does it need the computer groups in there as well?

 

thanks

 

Manick

Posted

I certainly won't hurt to put them in there but GPRESULT would normally indicate that the computer settings have been filtered out.

 

Have you tried running GPRESULT on the client?

Posted

This is the result of gpresult on the client machine (logged in as student, co they can do everything at the mo!!!)

 

Computer config:

Appied group policy objects:

IS THE PUPILS ONE SUPPOSED TO BE HERE, IF SO IT ISN'T!

other policies are

 

User Config:

Applied group policy objects:

pupils

and others

 

The following GPOs were not applied because they were filtered out :

 

Local group policy

filtering. not applied (empty)

 

 

Thanks

 

Manick

Posted

Yes if you have configured settings in the computer configuration for the GPO it should be there.

 

Check the GPO on the DC again, if you haven't already do so, install the Group Policy Management Console on the server

 

You can run the Group Policy Management Console by typing gpmc.msc

 

In GPMC expand "Group Policy Objects" click on the GPO and check the scope

 

Right click the GPO and check the status and make sure the Computer Configuration Setings are not disabled.

 

Click the OU where the GPO is linked and check that the GPO is linked and also check the Group Policy Inheritance

Posted

Morning!!,

 

OK checked all of those and all OK:

 

scope = applied to student user group, sec filtering = authenticated users, wmi filtering = none.

 

both users and computer config enabled

 

linked GPO - OK and enforced

gp inheritance = 1=pupils 2= default domain policy.

 

Any other ideas?

 

cheers

 

Manick

Posted

About 3 months ago they were!!, I've been fiddling with policies since then, trying to lock the school down!!!

 

Cheers

 

manick

 

P.S. I'm glad you won't be beat one this one, me neither, I'm googling my ass off, looking for this RPC server error!

Posted

Lo.

 

yes firewall is running, but having just compared machines that are working against those that aren't, there isn't any difference between the exceptions apart from RemoteExec is allowed on those that are picking up GP (or appear to be).

 

Bit of confusion here though, earlier someone said that the pupils policy should show in both computer config and user config, however it isn't showing in computer config, but is applying all the settings???

 

manick

Posted

Just a thought but how many DC's do you have in the domain. I had a nightmare with GPO not applying on some PC's a while back and it turned out to be a screwed sysvol folder on one of the DC's and replication was not functioning.

 

I am sure I had the same RPC error on the client.

Posted

I've made quite a few changes in the computer config part of the pupils gpo, but they haven't taken on around half of the machines.

 

 

manick

Posted

I've made quite a few changes in the computer config part of the pupils gpo, but they haven't taken on around half of the machines.

 

We have two DCs, I'll look into the Sysvol idea.

 

 

manick

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...