Re: GPO applies to one user and not to another ??

From: Steven L Umbach (n9rou_at_nscomcast.net)
Date: 06/06/04


Date: Sun, 06 Jun 2004 21:30:33 GMT

First make sure that the new user is in the same container as the user that
the policy applies to. Then check your dns configuration to make sure that
your domain controller points only to itself as it's preferred dns server in
tcp/ip properties and that the domain computers point only to the domain
controller as their dns pfreferred dns server. Misconfiguration of dns is
probably the cause of ninety percent of Group Policy problems. I would also
run first netdiag and then dcdiag on the domain controller looking for any
pertinent failed tests/errors/warnings and run netdiag on the domain
computer the new user is logging onto. You can also use gpresult to help
determine what policy is applying to a computer user by running it while
loggedon as that user on their computer. Use the /v switch for more detailed
info. Those tolls are located on the install cd under support/tools where
you need to run the setup or .msi file there. The links below may be
helpful. --- Steve

http://www.microsoft.com/windowsxp/pro/using/itpro/managing/gpresults.asp -
- same for W2K
http://support.microsoft.com/default.aspx?scid=kb;en-us;810739 -- white
paper, well worth a read
http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B250842

"Laddoo" <kshah@esi-solutions.ca> wrote in message
news:5C89765C-BAF6-4220-9234-9279D0CA842C@microsoft.com...
> DC with W2k Server, All clients W2K Pro. I have had a GPO for a particular
user for 1 year. A new user added to this GPO does not apply the GPO when
logged.
> Both users share the same roaming mandatory profile.
> Event IDs logged on clients machines
> Event ID 111 : Source : Folder Redirection. Unable to apply folder
redirection policy, initialization failed.
> Event ID 1000 : Source: Userenv. The Group Policy client-side extension
Folder Redirection was passed flags (0) and returned a failure status code
of (203).
> Event ID 1012: Source: WinLogon. The automatic certificate enrollment
subsystem could not access local resources needed for enrollment.
Enrollment will not be performed. (0x80070005) Access is denied.
>
> The Folder redirection policy is not enabled.
> The tried creating a thrid user, a copy of the 1st user, but no help. The
1st user still does apply the GPO
>
> Please help
>



Relevant Pages

  • Re: OUs dont work in AD
    ... without any specific configuration information and what type of GPO policies ... DNS, it will not work. ... acquire from the policy ... MVP Microsoft MVP - Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: gp error
    ... PASS - All the DNS entries for DC are registered on DNS server ... Starting test: CrossRefValidation ... Friendly name: Default Domain Policy ... Friendly name: New Group Policy Object ...
    (microsoft.public.windows.group_policy)
  • Re: W2K Server / XP Pro Clients / Group Policy -- LOCK TASKBAR
    ... make your dns configuration is correct in that domain ... > only to themselves or other domain controllers as their preferred dns ... > they are in an Organizational Unit, then the policy should be configured ... >> are on the domain controller and I am logging onto the domain from the ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: W2K Server / XP Pro Clients / Group Policy -- LOCK TASKBAR
    ... make your dns configuration is correct in that domain ... > only to themselves or other domain controllers as their preferred dns ... > they are in an Organizational Unit, then the policy should be configured ... >> are on the domain controller and I am logging onto the domain from the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Path Rules - Enabled Paths sometime are restricted
    ... machine I ran netdiag and dcdiag. ... all DC were as expected and DNS records were good. ... the proper policy was applied and came from our ... domain controler named SKIP. ...
    (microsoft.public.windows.group_policy)