Andi Posted June 28, 2007 Posted June 28, 2007 I'm trying to assign some software via GPO to a select group of PCs that are spread out over a few different OUs. I've created a group and made the stations a member of the group. Created a GPO that assigns the software and removed authenticated users from the security filtering section and added my new group giving them 'assign group policy' rights. However, the software never seems to arrive. I've tested the same package just by assigning it to a test OU which is as I normally would allocate software and it installs with no issues. What stage am I missing? I've googled this to death and can't find what I've done wrong.
pooley Posted June 28, 2007 Posted June 28, 2007 Set the loopback policy to merge http://support.microsoft.com/kb/231287
Andi Posted June 28, 2007 Author Posted June 28, 2007 Thanks for the reply. Why would I need to do that? The computer itself is a member of the security group, not the user, and the policy is set on the computer section of the GPO.
Andi Posted June 28, 2007 Author Posted June 28, 2007 Tried it with the user policy merged but no difference. Any ideas?
Andi Posted June 28, 2007 Author Posted June 28, 2007 The GPO is at the top level of the OU tree. e.g. Network Computer (GPO set here) - ICT1 Computers - ICT2 Computers - Science Computers
Geoff Posted June 28, 2007 Posted June 28, 2007 Ok, well it sounds like it's setup right to me. What happens when you do Group Policy modelling? Does the GPMC think it'll apply?
Andi Posted June 29, 2007 Author Posted June 29, 2007 Sorry to keep bumping this, has anyone got any more ideas? I cannot see what I have done wrong. Could it be something like permissions on the packages share?
Andi Posted June 29, 2007 Author Posted June 29, 2007 Just gave the specific group full NTFS permissions on the packages folder, and everyone has read access to the share, still nothing. Nothing in the local machine's eventvwr. I just tried allocating a different package to the same group but nada.
cheesypete Posted June 29, 2007 Posted June 29, 2007 If there is nothing in the clients event log then there is clearly an issue elsewhere - the evnt log would confirm that a GPO has been applied successfully or whether an issue has occurred I've never had to set the loopback mechanism for software distrubution so i dont think its that Have you run the "test the policy" routine from GPMC?
maniac Posted June 29, 2007 Posted June 29, 2007 I would run gpresult on a workstation to see what GPOs are actually applied. Then run gpupdate /force on a workstation to make sure the policy is being pulled through.
plexer Posted June 29, 2007 Posted June 29, 2007 If you move one of the computers into a new ou and set the policy on that ou does that single computer apply the softwar policy as you would expect? Ben
plexer Posted June 29, 2007 Posted June 29, 2007 If you move one of the computers into a new ou and set the policy on that ou does that single computer apply the softwar policy as you would expect? Ben
Andi Posted June 29, 2007 Author Posted June 29, 2007 I've already done the gpupdate /force so it's not that. I will try the other suggestions though. Thanks.
mrforgetful Posted June 29, 2007 Posted June 29, 2007 Is it a Computer Configuration setting? If so it needs applying to Computers, not Users, or else it won't take effect. The reason I'm confused about it is you mention moving computers to OUs but also mention adding User Groups to security. You can't mix them both. If it's a Computer Configuration it must be linked to OUs containing computers. If it's a User Configuration then it must be linked to OUs containing Users.
Andi Posted June 29, 2007 Author Posted June 29, 2007 I may have worded something wrong that confused you. It is a computer policy and it is set in the computer config section of the GPO. The OU only contains computers. The computers I want it to apply to have been added to a security group. This group has been given 'apply group policy' permission in the security filtering section of the GPMC.
Andi Posted June 29, 2007 Author Posted June 29, 2007 If you move one of the computers into a new ou and set the policy on that ou does that single computer apply the softwar policy as you would expect? Ben Yes, when deployed in the usual way the software installs with no problem.
Andi Posted June 29, 2007 Author Posted June 29, 2007 gpresult turned up some answers. "Install Olympus Dictaphone Filtering: Denied (Security)" Now to find out why it has been denied.
Andi Posted June 29, 2007 Author Posted June 29, 2007 Now we're getting somewhere. If I add the computer name itself to the security filtering the policy gets applied. If that computer is a member of a security group and the group is added to the security filtering the policy gets denied. So, my only thoughts are that computers cannot be filtered in terms of their groups? Does domain local or global make a difference in this instance?
Grommit Posted June 29, 2007 Posted June 29, 2007 Is there a place to download GPO's from ? like uber strict ones ?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now