Re: _Group Policy only 1 of 6 is working

From: Derek Melber [MVP] (derekm_at_braincore.net)
Date: 04/14/04

  • Next message: Oli Restorick [MVP]: "Re: network printers"
    Date: Wed, 14 Apr 2004 14:11:34 -0700
    
    

    Ok, thanks for that info!

    If you have 6 GPOs applied to one OU, all with Password policies, then you
    will only get one Password policy result. The one at the top of the list
    (the highest priority).

    -- 
    Derek Melber
    BrainCore.Net
    derekm@braincore.net
    "David Stal" <None@guesswhere.sk> wrote in message
    news:ul7r701d0ch8j918t5ps2m2kme4h6ae9sc@4ax.com...
    > You understand it correctly, except all users are in Department OUs
    > under CopmanyOU
    >
    > ACLs on the GPOs: Athenticated users have read and Apply Group Policy.
    > unless filtering is handled else where?
    >
    > All of the GPOs do have settings, specifically the password policy I
    > detailed earlier. Unless you mean something else by that. :o)
    >
    >
    >
    >
    > On Wed, 14 Apr 2004 13:07:02 -0700, "Derek Melber [MVP]"
    > <derekm@braincore.net> wrote:
    >
    > >David,
    > >
    > >Let me make sure I understand what you have:
    > >
    > >Domain level:
    > >Default Domain GPO with default settings
    > >
    > >CompanyOU:
    > >GPO1
    > >GPO2
    > >GPO3
    > >GPO4
    > >GPO5
    > >GPO6
    > >
    > >User and computer accounts are scattered in the OUs, but some are in the
    > >CompanyOU.
    > >Only one of the GPOs from the CompanyOU level are applying to the
    computer
    > >accounts that reside in the CompanyOU.
    > >The other 5 indicate that the GPO is <empty>.
    > >
    > >This indicates to me that you have not configured ANY GPO settings in
    these
    > >other GPOs. I know that sounds strange... but this is what it is telling
    me.
    > >The other possibility is that you have filtered out all user and computer
    > >accoutns from applying these 5 GPOs? Have you checked the filters (ACL)
    on
    > >the GPOs?
    > >
    > >-- 
    > >Derek Melber
    > >BrainCore.Net
    > >derekm@braincore.net
    > >"David Stal" <None@guesswhere.sk> wrote in message
    > >news:5c2r701lbpss2oco1g1ohrh13i48jmb5pq@4ax.com...
    > >> Sorry, links has
    > >> Domain
    > >> Domain/CompanyOU <- this where I applied the GPO <Blush>I
    > >> didn't hit the Find now button </BLUSH>
    > >>
    > >> No Blocks at all
    > >>
    > >> FRS is working (netlogon is replicating between DCs) and nothing in
    > >> the event logs.
    > >>
    > >> 2 DCs
    > >>
    > >> Correction: 5 of 6 are coming back "empty" in GPUPDATE. 1 is updating
    > >> OK
    > >>
    > >>
    > >> On Wed, 14 Apr 2004 11:44:44 -0700, "Derek Melber [MVP]"
    > >> <derekm@braincore.net> wrote:
    > >>
    > >> >you say there are NO LINKS? Do you really mean that? I assume not.
    > >> >
    > >> >Do you have ANY block policy inheritance on the OUs?
    > >> >
    > >> >I am also wondering if the SYSVOL issue is something here? Are you
    > >getting
    > >> >ANY FRS problems or events on the DCs? I think we need to 100% verify
    FRS
    > >is
    > >> >working first, then see about the GPOs. If the GPUPDATE is saying that
    > >all
    > >> >GPOs are empty... that is troubling. How many DCs?
    > >>
    > >
    >
    

  • Next message: Oli Restorick [MVP]: "Re: network printers"