Announcement

Collapse
No announcement yet.

Not Overriden GPO is not appling to OU

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Not Overriden GPO is not appling to OU

    I created Policy to OU, but it's settings still doesn't applies to OU even if it is blocked from Inheritence please help me what to do...

  • #2
    Re: Not Overriden GPO is not appling to OU

    A bit more info is required about the setup i.e. do you just have your domain policy and then a policy on this specific OU? After making the changes have you ran "gpupdate" or rebooted the machine? What info do you get when you run "gpresult"?

    Help us to help you

    Michael
    Michael Armstrong
    www.m80arm.co.uk
    MCITP: EA, MCTS, MCSE 2003, MCSA 2003: Messaging, CCA, VCP 3.5, 4, 5, VCAP5-DCD, VCAP5-DCA, ITIL, MCP, PGP Certified Technician

    ** Remember to give credit where credit is due and leave reputation points sigpic where appropriate **

    Comment


    • #3
      Re: Not Overriden GPO is not appling to OU

      thanx for your reply...

      i have default domain policy and default domain conroller policy

      and also i hav e created a special policy fo r OU whic h contains ".test" group in it with users (must they be the members of ".test" group or not, actually i made) also i blocked it from Inheritence and overridness

      i updated it and checked gpresult even restarted the machine but the settings that i made to my policy is not effects the ".test" OU

      please help...or i will not pass the exams

      sorry for my english, i am the begginner

      Comment


      • #4
        Re: Not Overriden GPO is not appling to OU

        Hi,
        One thing you might want to check is that everyone has permissions to read and apply the GPO.

        To check this open Active Directory Users and Computers.
        -->right click on the OU you have applied the GPO to and select Permissions.
        -->Go to the Group Policy tab.
        -->Select the GPO you are working with and select Properties.
        -->Now select the Security tab.
        Check this to see that the Everyone group has permission to Read and permission to Apply the GPO.

        This talk of a ".test" group is interesting. You can't apply a GPO directly to a group, you can filter what a GPO is applied to using groups though.
        I'm also interested in that you used a fullstop in a OU/Group name? This may also be something to check. So try an OU "Test" instead of anything called ".test".


        Maybe someone else knows about using fullstops in OU/group names?
        I'm not going to chance it myself atm. .
        I don't know anything about (you or your) computers.
        Research/test for yourself when listening to free advice.

        Comment


        • #5
          Re: Not Overriden GPO is not appling to OU

          thanx
          yes add the permissions to every one i.e.

          >creater owners
          >domain admins
          >authenticated users and etc...

          but nothing have changed

          OU doesn't want to hide THe RUN button from start menu


          about fullstops I also don't know for what especially they are, but my admin recommended me to create GROUPS with fullstops

          anyway thanx

          waiting for solutions..//

          Comment


          • #6
            Re: Not Overriden GPO is not appling to OU

            Kk, thanks for trying.
            I think you will have to do a
            Code:
            gpresult >c:\gpresult.txt
            at the command prompt.
            Then edit the resulting file at c:\gpresult.txt so we can't see things we shouldn't (like your domain name).
            Then post the results back here for us.
            It would also help us when looking at that file to know what the name of the GPO we wish to have applied is.


            ---------------------------------------------
            Just so you know what we will primarily look at/for when we run gpresult in this case is:
            The user received "Registry" settings from these GPOs:
            Last time Group Policy was applied: 32 March 2107 at 56:00:59
            Group Policy was applied from: my.super.secret.domain.com
            and
            The computer received "Registry" settings from these GPOs:
            but the rest can be helpful too.
            I don't know anything about (you or your) computers.
            Research/test for yourself when listening to free advice.

            Comment


            • #7
              Re: Not Overriden GPO is not appling to OU

              gpresult >c:\gpresult.txt



              RSOP data for CONTOSO\administrator on SERVER01 : Logging Mode
              ---------------------------------------------------------------

              OS Type: Microsoft(R) Windows(R) Server 2003, Standard Edition
              OS Configuration: Primary Domain Controller
              OS Version: 5.2.3790
              Terminal Server Mode: Remote Administration
              Site Name: Default-First-Site-Name
              Roaming Profile:
              Local Profile: C:\Documents and Settings\Administrator
              Connected over a slow link?: No


              COMPUTER SETTINGS
              ------------------
              CN=SERVER01,OU=Domain Controllers,DC=contoso,DC=com
              Last time Group Policy was applied: 7/21/2007 at 10:45:31 AM
              Group Policy was applied from: server01.contoso.com
              Group Policy slow link threshold: 500 kbps
              Domain Name: contoso
              Domain Type: Windows 2000

              Applied Group Policy Objects
              -----------------------------
              Default Domain Controllers Policy
              Default Domain Policy
              Local Group Policy

              The following GPOs were not applied because they were filtered out
              -------------------------------------------------------------------
              GPO kk
              Filtering: Not Applied (Empty)

              The computer is a part of the following security groups
              -------------------------------------------------------
              BUILTIN\Administrators
              Everyone
              BUILTIN\Pre-Windows 2000 Compatible Access
              BUILTIN\Users
              Windows Authorization Access Group
              NT AUTHORITY\NETWORK
              NT AUTHORITY\Authenticated Users
              This Organization
              SERVER01$
              Domain Controllers
              NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS


              USER SETTINGS
              --------------
              CN=Administrator,CN=Users,DC=contoso,DC=com
              Last time Group Policy was applied: 7/21/2007 at 10:47:36 AM
              Group Policy was applied from: server01.contoso.com
              Group Policy slow link threshold: 500 kbps
              Domain Name: CONTOSO
              Domain Type: Windows 2000

              Applied Group Policy Objects
              -----------------------------
              Default Domain Policy

              The following GPOs were not applied because they were filtered out
              -------------------------------------------------------------------
              GPO kk
              Filtering: Not Applied (Empty)

              Local Group Policy
              Filtering: Not Applied (Empty)

              The user is a part of the following security groups
              ---------------------------------------------------
              Domain Users
              Everyone
              BUILTIN\Administrators
              BUILTIN\Users
              BUILTIN\Pre-Windows 2000 Compatible Access
              REMOTE INTERACTIVE LOGON
              NT AUTHORITY\INTERACTIVE
              NT AUTHORITY\Authenticated Users
              This Organization
              LOCAL
              Schema Admins
              Domain Admins
              Group Policy Creator Owners
              Enterprise Admins

              Comment


              • #8
                Re: Not Overriden GPO is not appling to OU

                there is no even the name of my policy i have created...
                GPO kK is existing within the site


                but gpo ppp which is within OU Test not appears


                About fullstops, maybe they are just for easy searching the groups by pressing " . "

                Comment


                • #9
                  Re: Not Overriden GPO is not appling to OU

                  I think we can see the problem here:
                  Originally posted by 1antraman1 View Post

                  Applied Group Policy Objects
                  -----------------------------
                  Default Domain Controllers Policy
                  Default Domain Policy
                  Local Group Policy

                  The following GPOs were not applied because they were filtered out
                  -------------------------------------------------------------------
                  GPO kk
                  Filtering: Not Applied (Empty)

                  The computer is a part of the following security groups
                  -------------------------------------------------------
                  BUILTIN\Administrators
                  Everyone
                  BUILTIN\Pre-Windows 2000 Compatible Access
                  BUILTIN\Users
                  Windows Authorization Access Group
                  NT AUTHORITY\NETWORK
                  NT AUTHORITY\Authenticated Users
                  This Organization
                  SERVER01$
                  Domain Controllers
                  NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
                  and

                  Originally posted by 1antraman1 View Post
                  Applied Group Policy Objects
                  -----------------------------
                  Default Domain Policy

                  The following GPOs were not applied because they were filtered out
                  -------------------------------------------------------------------
                  GPO kk
                  Filtering: Not Applied (Empty)

                  Local Group Policy
                  Filtering: Not Applied (Empty)

                  The user is a part of the following security groups
                  ---------------------------------------------------
                  Domain Users
                  Everyone
                  BUILTIN\Administrators
                  BUILTIN\Users
                  BUILTIN\Pre-Windows 2000 Compatible Access
                  REMOTE INTERACTIVE LOGON
                  NT AUTHORITY\INTERACTIVE
                  NT AUTHORITY\Authenticated Users
                  This Organization
                  LOCAL
                  Schema Admins
                  Domain Admins
                  Group Policy Creator Owners
                  Enterprise Admins

                  I created Policy to OU, but it's settings still doesn't applies to OU even if it is blocked from Inheritence please help me what to do...
                  I believe you will have to re-apply the blocking of Inheritance and see if you can find what is filtering out thoses GPOs you have applied. Check permissions again and check that the GPOs have settings in them.
                  The
                  The following GPOs were not applied because they were filtered out
                  -------------------------------------------------------------------
                  GPO kk
                  Filtering: Not Applied (Empty)
                  empty part suggests that it has no settings to apply from what I can tell.
                  I don't know anything about (you or your) computers.
                  Research/test for yourself when listening to free advice.

                  Comment


                  • #10
                    Re: Not Overriden GPO is not appling to OU

                    so my dear helpers let me again complain you

                    i have a DC, to which i want to create some policies
                    in DN lab4.com i have two defoult GPOs
                    Default Domain Policy
                    and Default Domain Controller Policy
                    which are enabled i haven't touched them Yet
                    ( i'm using GPMS)

                    next, i opened OU named 'Home' created 'GPO Home', created a group '.gp' and one user by making him a member of '.gp', also i've added the '.gp' group in security tab of 'GPO Home' properties, also i disabled the computer configurations

                    also local policy group.


                    in security tab i gave permission to 'read' and 'apply group policy' for '.gp'



                    after i configured some settings in 'user config.' of 'GPO Home' i.e.

                    help,search,run,control panel menus for testing the users in '.gp' group.


                    of course i executed the cmd 'gpupdate \force'
                    i i executed the cmd 'gpresult >c:/results.txt'

                    result is:
                    Code:
                    COMPUTER SETTINGS
                    ------------------
                        CN=SERVER01,OU=Domain Controllers,DC=lab4,DC=com
                        Last time Group Policy was applied: 7/26/2007 at 4:20:52 PM
                        Group Policy was applied from:      server01.lab4.com
                        Group Policy slow link threshold:   500 kbps
                        Domain Name:                        lab4
                        Domain Type:                        Windows 2000
                    
                        Applied Group Policy Objects
                        -----------------------------
                            Default Domain Controllers Policy
                            Default Domain Policy
                    
                        The following GPOs were not applied because they were filtered out
                        -------------------------------------------------------------------
                            Local Group Policy
                                Filtering:  Disabled (GPO)
                    
                            GPO Home
                                Filtering:  Disabled (GPO)
                    
                        The computer is a part of the following security groups
                        -------------------------------------------------------
                            BUILTIN\Administrators
                            Everyone
                            BUILTIN\Users
                            BUILTIN\Pre-Windows 2000 Compatible Access
                            Windows Authorization Access Group
                            NT AUTHORITY\NETWORK
                            NT AUTHORITY\Authenticated Users
                            This Organization
                            SERVER01$
                            Domain Controllers
                            NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
                    
                    
                    USER SETTINGS
                    --------------
                        CN=Administrator,CN=Users,DC=lab4,DC=com
                        Last time Group Policy was applied: 7/26/2007 at 4:05:39 PM
                        Group Policy was applied from:      server01.lab4.com
                        Group Policy slow link threshold:   500 kbps
                        Domain Name:                        LAB4
                        Domain Type:                        Windows 2000
                        
                        Applied Group Policy Objects
                        -----------------------------
                            Default Domain Policy
                    
                        The following GPOs were not applied because they were filtered out
                        -------------------------------------------------------------------
                            Local Group Policy
                                Filtering:  Disabled (GPO)
                    
                        The user is a part of the following security groups
                        ---------------------------------------------------
                            Domain Users
                            Everyone
                            BUILTIN\Administrators
                            BUILTIN\Users
                            BUILTIN\Pre-Windows 2000 Compatible Access
                            NT AUTHORITY\INTERACTIVE
                            NT AUTHORITY\Authenticated Users
                            This Organization
                            LOCAL
                            Schema Admins
                            Group Policy Creator Owners
                            Domain Admins
                            Enterprise Admins



                    yes Dr.Kernel thanx


                    i 've tested your recommendations but still can't find solutions,in terminal server everything is going well, all GPO's working excellently

                    here we have 20 computers and , one DC and even with one GPO we can't manage them, they all working by default policy.

                    also after config the GPO i even restarted the DC, but nothing good


                    so if some one know please inform me ,

                    regards

                    Comment


                    • #11
                      Re: Not Overriden GPO is not appling to OU

                      pay attention that

                      in comp. configuration
                      the GPO Home filtering Disabled(why? /hot to change it???)

                      in user configuration
                      i can't see even the name of GPO 'Home' why????


                      or i have to work only with Default Domain POlicy/user configurations?

                      then the policy will apply to administrtors also as i know.




                      also i don't know how to work with filters
                      The following GPOs were not applied because they were filtered out
                      how to filter them and where

                      Comment


                      • #12
                        Re: Not Overriden GPO is not appling to OU

                        also i wanted to ask
                        what is


                        N/A
                        when the policy is not applied?

                        Comment


                        • #13
                          Re: Not Overriden GPO is not appling to OU

                          Hi,
                          Ok lets start with the easy one first.

                          N/A
                          means not applicable.

                          In the GPO tab in the AD Users and Computers OU Properties window do you see an Edit and a Properties button? If you click on these are any of the fields ticked?

                          Might you have ticked the Disable Computer Configuration and/or the Disable User Configuration

                          Have you had a look at Petri's GPO page? It might be a help.

                          Originally posted by wkasdo View Post
                          Filtered means that there is a security setting prohibiting application of the policy. Check the permissions of the GPO link, perhaps Auth Users was removed, or has a deny 'apply policy'
                          As for filtering
                          Originally posted by emjtech View Post
                          Here's what I have found and then I have another question for you...

                          I figured out why the policy was filtered out for the user... because the policy didn't have any user settings, only computer settings.

                          i am going to create a new post with my new question...
                          I don't know anything about (you or your) computers.
                          Research/test for yourself when listening to free advice.

                          Comment

                          Working...
                          X