Re: GPO at sides don't work

From: Karin Galli [MS] (i-kgbauz_at_online.microsoft.com)
Date: 03/23/04


Date: Tue, 23 Mar 2004 11:30:19 +0100

Check if you have "block policy inheritance" enabled.

Cheers!

-- 
=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
"Axel Bredow" <anonymous@discussions.microsoft.com> wrote in message news:11c6601c410bf$bf8c56e0$a401280a@phx.gbl...
> Hello News-Group,
> 
> I've a problem with the following situation:
> 
> There is one Domain with two sides.
> The side with the PDC Emulator works fine, the other not.
> There are no errors posted in the event log for SceCli on 
> Clients at the fail side.
> Also the event log on the DC has no errors.
> Read and execute permissions for the GPO exists.
> GPtool print the policies for the side with "OK".
> 
> Just the extended log at a Client, activated by DWord 
> UserEnvDebugLevel in registry shows errors, but I can't 
> handle it.
> 
> Here is a part of it:
> 
> USERENV(bc.4e8) 15:04:48:493 SearchDSObject:  Searching 
> <CN=Invalidenstr,CN=Sites,CN=Configuration,DC=Andu-
> X,DC=local>
> USERENV(bc.4e8) 15:04:48:493 SearchDSObject:  Found GPO
> (s):  <[LDAP://CN={144F4672-9D24-4BCA-9633-
> B334DF3C7F80},CN=Policies,CN=System,DC=Andu-X,DC=local;0]
> [LDAP://CN={BC64958B-E678-4FE5-B917-
> CCA7EED37767},CN=Policies,CN=System,DC=Andu-X,DC=local;0]>
> USERENV(bc.4e8) 15:04:48:503 ProcessGPO:  
> ==============================
> USERENV(bc.4e8) 15:04:48:503 AddGPO:  GPO  will not be 
> added to the list since the Block flag is set and this GPO 
> is not in enforce mode.
> USERENV(bc.4e8) 15:04:48:513 ProcessGPO:  Deferring search 
> for <LDAP://CN={144F4672-9D24-4BCA-9633-
> B334DF3C7F80},CN=Policies,CN=System,DC=Andu-X,DC=local>
> USERENV(bc.4e8) 15:04:48:513 ProcessGPO:  
> ==============================
> USERENV(bc.4e8) 15:04:48:513 AddGPO:  GPO  will not be 
> added to the list since the Block flag is set and this GPO 
> is not in enforce mode.
> 
> Dose anyone knows how to go on?
> 
> SDCheck also shows errors.
> 
> Yours sincerely
> 
> Axel Bredow
> 


Relevant Pages

  • GPO at sides dont work
    ... Also the event log on the DC has no errors. ... Read and execute permissions for the GPO exists. ... is not in enforce mode. ... USERENV15:04:48:513 ProcessGPO: Deferring search ...
    (microsoft.public.win2000.group_policy)
  • Re: Logoff scripts didnt run, Event 1000 errors in App log
    ... Have a look in the event log and look for netlogon errors. ... > About a month ago I created a GPO to run a logoff script to delete ... > Event Source: Userenv ...
    (microsoft.public.windows.group_policy)
  • Re: GP user settings does not apply - W2000 TS
    ... Here's a verbose version of the log: (the GPO is named T) ... USERENV08:25:25:848 GetGPOInfo: Entering... ... USERENV08:25:25:879 ProcessGPO: Deferring ... and no security group membership change and extension ...
    (microsoft.public.win2000.group_policy)
  • GP not applying for W2000 TS User
    ... W2000 Terminal server using Group policy. ... Here's a verbose version of the user env log: (the GPO is ... USERENV08:25:25:879 ProcessGPO: Deferring ... and no security group membership change and extension ...
    (microsoft.public.win2000.group_policy)
  • GPO not applied userenv log shows error 53 path not found
    ... I am trying to get a startup script to run on machines in an OU in a Windows ... 2000 AD domain using GPO. ... USERENV16:16:09:433 ProcessGPO: Machine has access to this GPO. ... USERENV16:16:09:473 GetGPOInfo: EvaluateDeferredGPOs failed. ...
    (microsoft.public.win2000.group_policy)