Re: Group Police Effect

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 04/17/04


Date: Sat, 17 Apr 2004 18:53:54 GMT

Other things to check for a Group Policy problem include that the GPO is linked to
the container, that the policy is enabled in the Group Policy options page, that
computer and or user configuration is enabled in Group Policy properties page, that
"no override" is not selected for a GPO in the Group Policy options page at a upper
level such as domain that may not allow the changes to take effect if they are
defined in the GPO where no override is configured, and that the user/group has
read/apply permissions and no "deny" permissions to the GPO in the
properties/security page. Normally "authenticated users" has read/apply permissions.
Domain computers are also members of the authenticated users group. The everyone
group should have read permissions to the sysvol share on the domain controller and
authenticated users need at least read/list/execute ntfs permissions to it. Also
check the Event Viewer on the domain controller for any pertinent error messages. The
links below may be helpful. --- Steve

http://www.microsoft.com/windows2000/techinfo/planning/management/groupsteps.asp
http://support.microsoft.com/default.aspx?scid=KB;EN-US;q250842&

"Roma" <anonymous@discussions.microsoft.com> wrote in message
news:03f301c42480$14accfa0$a501280a@phx.gbl...
> Thank's for you
>
> But the GP it was worked perfect , but the server it was
> hacked. i used the Tools it's gave me all test ok
> but any changes to the GP no any effect , thsi the
> problem .
>
> >-----Original Message-----
> >The user/computer that you are trying to enforce the
> policy on must be within the
> >scope of influence of the GPO. For instance if you
> configure Group Policy for an OU,
> >the user or computer must reside in that OU structure.
> Keep in mind that for domain
> >user accounts that password/account policy can only be
> applied at the domain level.
> >Nediag and gpresult are two great tools to troubleshoot
> GP problems. I would run
> >netdiag on the computer you are having a problem with
> first looking for any failed
> >tests that may indicate why policy is not applying to
> that machine or user logging
> >onto the machine. In particular look for failed
> tests/errors for dns,dclist, and
> >domain membership. Gpresult will show where policy is
> being applied to a
> >user/computer and the last time policy was refreshed.
> Remember policy will not be
> >applied immediately though a reboot. logoff/logon, or
> using secedit can speed up most
> >policy propagation. -- Steve
> >
> >http://support.microsoft.com/default.aspx?scid=kb;en-
> us;301423 --- works on non
> >servers also.
> >
> >"Roma" <anonymous@discussions.microsoft.com> wrote in
> message
> >news:18e0401c4211e$25496900$a601280a@phx.gbl...
> >> Hi all
> >> I have problem with the group police effect , i have
> OU's
> >> and each has group police , the effect for group police
> >> for OU not working , all my changes for it dosen't take
> >> any effect why , and this is the same problem with the
> DC
> >> group POlice any changes , no any effect
> >> How i can fix the problem.
> >> Pls help.
> >
> >
> >.
> >



Relevant Pages

  • Re: Help with GPO problem! PLEASE!!
    ... Can you create a new GPO?? ... If so use it to compare permissions to the two ... > Configuration information could not be read from the domain controller, ... Failed to open the Group Policy Object. ...
    (microsoft.public.windows.group_policy)
  • Remove Add or Remove Programs GPO Question
    ... Programs" GPO but with the following stipulations: ... I have created an OU with the desktop computer accounts and an OU with the ... Authenticated Users - Allow Apply Group Policy ...
    (microsoft.public.windows.server.active_directory)
  • Re: GPO and Group Policy
    ... There are plenty of explanations of setting Share and NTFS ... Setting Special Permissions are not really any harder (after you do Standard ... You can ONLY LINK a GPO to a 'container', either a Site, Domain, or OU. ... The ONLY way you can use Groups with Group Policy (yes we know it ...
    (microsoft.public.windows.server.active_directory)
  • Re: Win2003 "cannot access the file gpt.ini"
    ... think a certain antivirus program messed the permissions up. ... fine, so we created a new blank GPO, then copied its gpt.ini back to the ... > I have installed Windows Server 2003 as a "first server on the network". ... > Windows cannot query for the list of Group Policy objects. ...
    (microsoft.public.windows.server.setup)
  • Re: Using Group Policy to give install permission
    ... Group Policy is simply (well, ... Active Directory there is only one Organizational Unit: ... Your user account objects or computer account objects must directly reside ... in the Organizational Unit to which you linked the GPO. ...
    (microsoft.public.win2000.group_policy)

Quantcast