Jump to content

dowlingm

Members
  • Posts

    2
  • Joined

  • Last visited

Everything posted by dowlingm

  1. Oh, thought of something. Being in a 2008 environment, your GP is ADMX. You can add ADM templates to a GPO *but* you are now managing two sets of templates within the Object not one. If a given GPO is managing Vista+ and XP, the Vista/7 boxen are managed with "administrative templates" but the XP ones by CLASSIC Administrative Templates (who should appear when you inject the ADMs). Personally I use separate GPOs and OUs for XP and Win6+ but that doesn't work for everyone
  2. If it was me, here's what I'd be doing: 1. Taking local GPs out of the game - gpedit.msc, right click Local Group Policy, Properties, check both boxes, reboot - if that works, you know your problem is in LGP and if you're running GPO you don't need LGP. 2. Bring up a new machine, preferably from factory disks, attach to domain in OU with no policies, then add to OU with just computer policy (and gpupdate, reboot), check again, add to OU with computer AND user policy (i.e. production OU), gpupdate, reboot. In step two, depending on where the setting flips you know what's tripping it. You should definitely be running GP Modelling against your site, computer and user to verify you know exactly how many GPOs are being applied - such as some idiot having configured the Default Domain Policy rather than leaving that well alone and applying solely bespoke GPOs. One other thing tripped us up lately - we've been starting the use of MDT2012 for rollouts, but by default it seems to apply a Local Group Policy pack. Wouldn't affect your problem but definitely came as a surprise to us since it broke integration with SMB shares until we reversed it out - one to know if getting into MDT.
×
×
  • Create New...