Jump to content

Recommended Posts

Posted

Hi Guys,

 

I have had Windows 2008r2 and Windows 7 setup and running fine for the past year, but two days I noticed some users have the full GPO pulled over and some users dont have it at all. The Home Drives come up fine.

 

I took one machine and tested it with two users, one user has a fully locked down PC which is good but another user in the same group has full accsess to the machine.

 

I have rebooted the DC's, when I done a gpupdate /force on the DC it did come back with an error but this has been fixed now. I have also put a new image onto the PC just to see if this was the cause but still no luck.

 

Any help on this would be great.

Posted (edited)

From a command line, run

gpresult /v > result.txt

Then view the result.txt file in Notepad.

 

This will show you if any policies have been filtered out (maybe by mistake)

 

If this sheds no light, you could run a GPO simulation through the Group Policy Management tool against the user and machine for both cases, see if there's any differences in the simulation results between the two machines/users.

Edited by jinnantonnixx
  • Thanks 1
Posted
Thought this was fixed but no luck. When I type in \\domain.local sometimes it asks for a username and password and sometimes it will come straight up and even when I enter the administrator one it doesnt work. It seems to be a intermittent problem
Posted

Just to explain abit more. We have about 3-4 students in each class that logon with no GPO loaded or what appears to be. They have the default Windows 7 wallpaper and full local admin rights. I have made a note of the user details and tested on another PC and the GPO will pull accross, this seems like a really weird problem we have never experienced before. The affected account seems completely random, I have taken one user account and logged in with it to 30 classroom computers and between 5 and 10 logons will not pull the GPO accross.

 

Our Domain Controllers are pretty much just maintained as we don't like to mess about with em (Ruuning 2008 R2, fully updated)

 

Something that might be related to the problem is when I type \\domain.local\ in run I get a logon box instead of explorer showing the domain controllers sysvol folder. Any details I enter in this box will not allow me access the sysvol (even the domain administrator account)

Here is the troubleshooting we have done so far;

 

Image the PC/PC's

Check the user account in AD for membership

Reboot Domain Controllers

Reboot the core switch

Restored a backup of the student GPO

Checked the services on the servers

 

Pretty much at a loss right now, any help is much appreciated.

Posted

What does Event Viewer say? Compare a working with a non-working machine, see what the differences are.

 

I must say this is ringing a bell; I think I had something similar when I set up a Windows 7 system. I'll see if I've made any notes (I often do!)

Posted

We have 2 domain controllers, FRS went up and down all day yesterday but there is nothing in there for today.

 

 

One frequent error is

 

"The File Replication Service is no longer preventing the computer DC01 from becoming a domain controller. The system volume has been successfully initialized and the Netlogon service has been notified that the system volume is now ready to be shared as SYSVOL.

 

Type "net share" to check for the SYSVOL share."

Posted

Found the root problem, rogue DNS entries that were conflicting with domain controllers, removed them now I'm able to access the sysvol consistently thus GPO's are applied 100% of logons.

 

Thanks for all of your replies.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...