Re: GP user settings does not apply - W2000 TS

From: Update (technet_at_update.se)
Date: 10/22/04


Date: Thu, 21 Oct 2004 23:37:30 -0700

Here's a verbose version of the log: (the GPO is named T)
USERENV(964.1454) 08:25:25:832 ProcessGPOs: User name
is: CN=Casawin
Terminal,OU=Terminaler,DC=aristok,DC=local, Domain name
is: ARISTOK
USERENV(964.1454) 08:25:25:832 ProcessGPOs: Domain
controller is: \\aristodc.aristok.local Domain DN is
aristok.local
USERENV(964.1454) 08:25:25:832 MyGetDomainDNSName:
Successfully determined fqdn CN=Casawin
Terminal,OU=Terminaler,DC=aristok,DC=local
USERENV(964.1454) 08:25:25:832 MyGetDomainDNSName:
Successfully obtained domain dns name aristok.local
USERENV(964.1454) 08:25:25:832 ReadStatus: Failed to open
reg key with 5.
USERENV(964.1454) 08:25:25:832 ReadStatus: Failed to open
reg key with 5.
USERENV(964.1454) 08:25:25:848 ProcessGPOs: Calling
GetGPOInfo for normal policy mode
USERENV(964.1454) 08:25:25:848 GetGPOInfo:
********************************
USERENV(964.1454) 08:25:25:848 GetGPOInfo: Entering...
USERENV(964.1454) 08:25:25:848 GetGPOInfo: Server
connection established.
USERENV(964.1454) 08:25:25:863 GetGPOInfo: Bound
successfully.
USERENV(964.1454) 08:25:25:879 SearchDSObject: Searching
<OU=Terminaler,DC=aristok,DC=local>
USERENV(964.1454) 08:25:25:879 SearchDSObject: Found GPO
(s): <[LDAP://CN={62DA425B-C651-458C-9A93-
5590DA4F0540},CN=Policies,CN=System,DC=aristok,DC=local;2]
>
USERENV(964.1454) 08:25:25:879 ProcessGPO:
==============================
USERENV(964.1454) 08:25:25:879 ProcessGPO: Deferring
search for <LDAP://CN={62DA425B-C651-458C-9A93-
5590DA4F0540},CN=Policies,CN=System,DC=aristok,DC=local>
USERENV(964.1454) 08:25:25:879 SearchDSObject: Searching
<DC=aristok,DC=local>
USERENV(964.1454) 08:25:25:879 SearchDSObject: Found GPO
(s): <[LDAP://CN={31B2F340-016D-11D2-945F-
00C04FB984F9},CN=Policies,CN=System,DC=aristok,DC=local;0]
>
USERENV(964.1454) 08:25:25:879 ProcessGPO:
==============================
USERENV(964.1454) 08:25:25:879 ProcessGPO: Deferring
search for <LDAP://CN={31B2F340-016D-11D2-945F-
00C04FB984F9},CN=Policies,CN=System,DC=aristok,DC=local>
USERENV(964.1454) 08:25:25:894 SearchDSObject: Searching
<CN=Default-First-
Site,CN=Sites,CN=Configuration,DC=aristok,DC=local>
USERENV(964.1454) 08:25:25:894 SearchDSObject: No GPO(s)
for this object.
USERENV(964.1454) 08:25:25:894 EvaluateDeferredGPOs:
Searching for GPOs in
cn=policies,cn=system,DC=aristok,DC=local
USERENV(964.1454) 08:25:25:894 ProcessGPO:
==============================
USERENV(964.1454) 08:25:25:894 ProcessGPO: Searching <CN=
{62DA425B-C651-458C-9A93-
5590DA4F0540},CN=Policies,CN=System,DC=aristok,DC=local>
USERENV(964.1454) 08:25:25:894 ProcessGPO: User has
access to this GPO.
USERENV(964.1454) 08:25:25:894 ProcessGPO: Found
functionality version of: 2
USERENV(964.1454) 08:25:25:894 ProcessGPO: Found file
system path of:
<\\aristok.local\SysVol\aristok.local\Policies\{62DA425B-
C651-458C-9A93-5590DA4F0540}>
USERENV(964.1454) 08:25:25:910 ProcessGPO: Found common
name of: <{62DA425B-C651-458C-9A93-5590DA4F0540}>
USERENV(964.1454) 08:25:25:910 ProcessGPO: Found display
name of: <T>
USERENV(964.1454) 08:25:25:910 ProcessGPO: Found user
version of: GPC is 6, GPT is 6
USERENV(964.1454) 08:25:25:910 ProcessGPO: Found flags
of: 0
USERENV(964.1454) 08:25:25:910 ProcessGPO: Found
extensions: [{35378EAC-683F-11D2-A89A-00C04FBBCFA2}
{0F6B957E-509E-11D1-A7CC-0000F87571E3}]
USERENV(964.1454) 08:25:25:910 ProcessGPO:
==============================
USERENV(964.1454) 08:25:25:910 ProcessGPO:
==============================
USERENV(964.1454) 08:25:25:910 ProcessGPO: Searching <CN=
{31B2F340-016D-11D2-945F-
00C04FB984F9},CN=Policies,CN=System,DC=aristok,DC=local>
USERENV(964.1454) 08:25:25:910 ProcessGPO: User has
access to this GPO.
USERENV(964.1454) 08:25:25:910 ProcessGPO: Found
functionality version of: 2
USERENV(964.1454) 08:25:25:910 ProcessGPO: Found file
system path of:
<\\aristok.local\sysvol\aristok.local\Policies\{31B2F340-
016D-11D2-945F-00C04FB984F9}>
USERENV(964.1454) 08:25:25:926 ProcessGPO: Found common
name of: <{31B2F340-016D-11D2-945F-00C04FB984F9}>
USERENV(964.1454) 08:25:25:926 ProcessGPO: Found display
name of: <Default Domain Policy>
USERENV(964.1454) 08:25:25:926 ProcessGPO: Found user
version of: GPC is 1, GPT is 1
USERENV(964.1454) 08:25:25:926 ProcessGPO: Found flags
of: 0
USERENV(964.1454) 08:25:25:926 ProcessGPO: Found
extensions: [{3060E8D0-7020-11D2-842D-00C04FA372D4}
{3060E8CE-7020-11D2-842D-00C04FA372D4}]
USERENV(964.1454) 08:25:25:926 ProcessGPO:
==============================
USERENV(964.1454) 08:25:25:926 GetGPOInfo: GPO Local
Group Policy doesn't contain any data since the version
number is 0. It will be skipped.
USERENV(964.1454) 08:25:25:926 GetGPOInfo: Leaving with 1
USERENV(964.1454) 08:25:25:926 GetGPOInfo:
********************************
USERENV(964.1454) 08:25:25:926 ProcessGPOs:
OpenThreadToken failed with error 1008, assuming thread
is not impersonating
USERENV(964.1454) 08:25:25:926 ProcessGPOs: --------------
---------
USERENV(964.1454) 08:25:25:926 ProcessGPOs: Processing
extension Registry
USERENV(964.1454) 08:25:25:941 CompareGPOLists: The
lists are the same.
USERENV(964.1454) 08:25:25:941 CheckGPOs: No GPO changes
and no security group membership change and extension
Registry has NoGPOChanges set.
USERENV(964.1454) 08:25:25:941 ProcessGPOs: --------------
---------
USERENV(964.1454) 08:25:25:941 ProcessGPOs: --------------
---------
USERENV(964.1454) 08:25:25:941 ProcessGPOs: Processing
extension Folder Redirection
USERENV(964.1454) 08:25:25:941 CompareGPOLists: The
lists are the same.
USERENV(964.1454) 08:25:25:941 CheckGPOs: No GPO changes
but couldn't read extension Folder Redirection's status
or policy time.
USERENV(964.1454) 08:25:25:941 ProcessGPOs: Extension
Folder Redirection skipped because both deleted and
changed GPO lists are empty.
USERENV(964.1454) 08:25:25:941 ProcessGPOs: --------------
---------
USERENV(964.1454) 08:25:25:941 ProcessGPOs: Processing
extension Microsoft Disk Quota
USERENV(964.1454) 08:25:25:941 ProcessGPOs: Extension
Microsoft Disk Quota skipped with flags 0x6.
USERENV(964.1454) 08:25:25:941 ProcessGPOs: --------------
---------
USERENV(964.1454) 08:25:25:941 ProcessGPOs: Processing
extension Scripts
USERENV(964.1454) 08:25:25:941 CompareGPOLists: The
lists are the same.
USERENV(964.1454) 08:25:25:941 CheckGPOs: No GPO changes
but couldn't read extension Scripts's status or policy
time.
USERENV(964.1454) 08:25:25:941 ProcessGPOs: Extension
Scripts skipped because both deleted and changed GPO
lists are empty.
USERENV(964.1454) 08:25:25:941 ProcessGPOs: --------------
---------
USERENV(964.1454) 08:25:25:941 ProcessGPOs: Processing
extension Security
USERENV(964.1454) 08:25:25:941 ProcessGPOs: Extension
Security skipped with flags 0x6.
USERENV(964.1454) 08:25:25:941 ProcessGPOs: --------------
---------
USERENV(964.1454) 08:25:25:941 ProcessGPOs: Processing
extension Internet Explorer Branding
USERENV(964.1454) 08:25:25:941 CompareGPOLists: The
lists are the same.
USERENV(964.1454) 08:25:25:957 CheckGPOs: No GPO changes
but extension Internet Explorer Branding had returned
ERROR_OVERRIDE_NOCHANGES for previous policy processing
call.
USERENV(964.1454) 08:25:25:957 ProcessGPOs: Extension
Internet Explorer Branding skipped because both deleted
and changed GPO lists are empty.
USERENV(964.1454) 08:25:25:957 ProcessGPOs: --------------
---------
USERENV(964.1454) 08:25:25:957 ProcessGPOs: Processing
extension EFS recovery
USERENV(964.1454) 08:25:25:957 ProcessGPOs: Extension EFS
recovery skipped with flags 0x6.
USERENV(964.1454) 08:25:25:957 ProcessGPOs: --------------
---------
USERENV(964.1454) 08:25:25:957 ProcessGPOs: Processing
extension Application Management
USERENV(964.1454) 08:25:25:957 ProcessGPOs: Extension
Application Management skipped with flags 0x6.
USERENV(964.1454) 08:25:25:957 ProcessGPOs: --------------
---------
USERENV(964.1454) 08:25:25:957 ProcessGPOs: Processing
extension IP Security
USERENV(964.1454) 08:25:25:957 ProcessGPOs: Extension IP
Security skipped with flags 0x6.
USERENV(964.1454) 08:25:25:957
LeaveCriticalPolicySection: Critical section 0x1a4 has
been released.
USERENV(964.1454) 08:25:25:957 ProcessGPOs: User Group
Policy has been applied.
USERENV(964.1454) 08:25:25:957 ProcessGPOs: Leaving with
1.
USERENV(964.1454) 08:25:25:957 ApplyGroupPolicy: Leaving
successfully.
USERENV(f48.1368) 08:25:26:098 LibMain: Process Name:
C:\WINNT\system32\userinit.exe
USERENV(964.1344) 08:25:26:988 GPOThread: Next refresh
will happen in 98 minutes
USERENV(93c.8e4) 08:25:36:019 LibMain: Process Name:
C:\WINNT\system32\ipconfig.exe
USERENV(8e4.93c) 08:25:40:191 LibMain: Process Name:
C:\WINNT\system32\gpresult.exe
USERENV(8e4.93c) 08:25:40:191 EnterCriticalPolicySection:
User critical section has been claimed. Handle = 0x39c
USERENV(8e4.93c) 08:25:40:191 EnterCriticalPolicySection:
Machine critical section has been claimed. Handle = 0x398
USERENV(8e4.93c) 08:25:40:988 GetAppliedGPOList:
Entering. Extension = {35378EAC-683F-11D2-A89A-
00C04FBBCFA2}
USERENV(8e4.93c) 08:25:40:988 GetAppliedGPOList:
Entering. Extension = {25537BA6-77A8-11D2-9B6C-
0000F8080861}
USERENV(8e4.93c) 08:25:40:988 GetAppliedGPOList:
Entering. Extension = {3610EDA5-77EF-11D2-8DC5-
00C04FA31A66}
USERENV(8e4.93c) 08:25:40:988 GetAppliedGPOList:
Entering. Extension = {42B5FAAE-6536-11D2-AE5A-
0000F87571E3}
USERENV(8e4.93c) 08:25:40:988 GetAppliedGPOList:
Entering. Extension = {827D319E-6EAC-11D2-A4EA-
00C04F79F83A}
USERENV(8e4.93c) 08:25:41:004 GetAppliedGPOList:
Entering. Extension = {A2E30F80-D7DE-11D2-BBDE-
00C04F86AE3B}
USERENV(8e4.93c) 08:25:41:004 GetAppliedGPOList:
Entering. Extension = {B1BE8D72-6EAC-11D2-A4EA-
00C04F79F83A}
USERENV(8e4.93c) 08:25:41:019 GetAppliedGPOList:
Entering. Extension = {C6DC5466-785A-11D2-84D0-
00C04FB169F7}
USERENV(8e4.93c) 08:25:41:113 GetAppliedGPOList:
Entering. Extension = {E437BC1C-AA7D-11D2-A382-
00C04F991E27}
USERENV(8e4.93c) 08:25:41:113 LeaveCriticalPolicySection:
Critical section 0x39c has been released.
USERENV(8e4.93c) 08:25:41:113 LeaveCriticalPolicySection:
Critical section 0x398 has been released.
USERENV(964.ba0) 08:25:57:973 UnloadUserProfile:
Entering, hProfile = <0x160>
USERENV(964.ba0) 08:25:57:973 GetUserMutex: entering
USERENV(964.ba0) 08:25:57:973 GetUserMutex: Waiting...
USERENV(964.ba0) 08:25:57:973 GetUserMutex: Wait
succeeded. Mutex currently held.
USERENV(964.ba0) 08:25:57:973 UnloadUserProfile: Didn't
unload user profile, Ref Count is 2
USERENV(964.ba0) 08:25:57:973 LoadUserProfile: Releasing
mutex.
USERENV(964.ba0) 08:25:57:973 UnloadUserProfile: Leaving
with a return value of 1

Regards,
Patrik
>-----Original Message-----
>You need to turn up the verbosity on this log to make it
useful.
>http://support.microsoft.com/default.aspx?scid=kb;en-
us;221833
>
>The current output is not of much help to determine why
the GPO is not
>applying.
>
>--
>Glenn L
>CCNA, MCSE 2000, MCSE 2003 + Security
>
>
>"Update" <anonymous@discussions.microsoft.com> wrote in
message
>news:03db01c4b75f$83aa2ac0$a601280a@phx.gbl...
>> (See below for earlier messages in this subject)
>> The DNS setting is correctly pointing to the DC.
>>
>> Earlier the user object lied in a sub OU under the
>> companyOU, so I tried making a new root ou and added a
>> new Policy there. Moved the user to the
>> new ou and enforced a update.
>> The result was computer recieving these GPOS: Local
Group
>> policy, Default domain policy only. The policy in the
>> root OU that the user was in before had disappeared but
>> the newly created policy is not applied.
>>
>> Looked at the Troubleshooting link and found a
>> lot of errors in the userenv file, but can't find
>> anything to do about it.
>> Here's the log output:
>> USERENV(42c.438) 02:00:00:187 Profile was loaded but
the
>> Ref Count is 1 !!!
>> USERENV(42c.fa4) 02:00:06:718 MyRegUnLoadKey: Hive
unload
>> for S-1-5-21-1844237615-412668190-725345543-500 failed
>> due to open registry key. Windows will try unloading
the
>> registry hive once a second for the next 60 seconds
(max).
>> USERENV(42c.fa4) 02:01:06:827 MyRegUnLoadKey: Windows
was
>> not able to unload the registry hive.
>> USERENV(42c.fa4) 02:01:06:827 MyRegUnLoadKey: Failed
to
>> unmount hive 5
>> USERENV(42c.fa4) 02:01:06:827 UnloadUserProfile:
Didn't
>> unload user profile <err = 5>
>> USERENV(42c.fa4) 02:01:06:827 DumpOpenRegistryHandle: 2
>> user registry Handles leaked from \Registry\User\S-1-5-
21-
>> 1844237615-412668190-725345543-500
>> USERENV(123c.c50) 11:03:39:800 CreateEnvironmentBlock:
>> Failed to open HKEY_CURRENT_USER, error = 5
>> USERENV(123c.c50) 11:03:39:832
>> ExpandEnvironmentStringsForUser:
CreateEnvironmentBlock
>> failed with = 203
>> USERENV(123c.ec0) 11:06:07:582 RegisterGPNotification:
>> CreateEvent failed with 5
>> USERENV(123c.ec0) 11:06:07:582 RegisterGPNotification:
>> CreateEvent failed with 5
>> USERENV(1044.1130) 11:21:08:597 CreateEnvironmentBlock:
>> Failed to open HKEY_CURRENT_USER, error = 5
>> USERENV(1044.1130) 11:21:08:628
>> ExpandEnvironmentStringsForUser:
CreateEnvironmentBlock
>> failed with = 203
>> USERENV(148.1388) 11:21:09:566 CreateEnvironmentBlock:
>> Failed to open HKEY_CURRENT_USER, error = 5
>> USERENV(148.1388) 11:21:09:566
>> ExpandEnvironmentStringsForUser:
CreateEnvironmentBlock
>> failed with = 203
>>
>> Thankful for any help
>>
>> Regards,
>> Patrik Gisselsson
>>
>>
>> >-----Original Message-----
>> >Hi Partrik,
>> >
>> >Thanks for your posting here.
>> >
>> >This behavior can occur if a DNS server address is not
>> correctly configured
>> >in the client computer's Internet Protocol (IP)
>> properties.
>> >
>> >To resolve this issue:
>> >
>> >1. Right-click My Network Places, and then click
>> Properties.
>> >
>> >2. Right-click Local Area Connection, and then click
>> Properties.
>> >
>> >3. Double-click Internet Protocol (TCP/IP).
>> >
>> >4. Click "Use the following DNS server addresses", and
>> then type the
>> >correct DNS server address. I recommend that you point
>> it to the same DNS
>> >server as your Domain Controller.
>> >
>> >You can use Gpresult.exe (a tool included in the
>> Microsoft Windows 2000
>> >Resource Kit) to troubleshoot group policy issues.
>> >
>> >You can also refer to the following document for more
>> information about
>> >troubleshooting procedures for Group Policy processing
>> on a Windows 2000
>> >client computer.
>> >
>> >250842 Troubleshooting Group Policy Application
Problems
>> >http://support.microsoft.com/?id=250842
>> >
>> >Wish it helps.
>> >
>> >Regards,
>> >Bob Qin
>> >Microsoft Online Partner Support
>> >
>> >Get Secure! - www.microsoft.com/security
>> >
>> >====================================================
>> >When responding to posts, please "Reply to Group" via
>> your newsreader so
>> >that others may learn and benefit from your issue.
>> >====================================================
>> >This posting is provided "AS IS" with no warranties,
and
>> confers no rights.
>> >
>> >--------------------
>> > From: "Update" <technet@update.se>
>> > Subject: GP in Terminal server
>> > Date: Thu, 14 Oct 2004 10:52:28 -0700
>> > Newsgroups:
microsoft.public.windows.group_policy
>> >
>> > I want to restrict a users desktop in W2000
>> Terminal
>> > server. Disable Internet explorer, controlpanel,
>> my
>> > network and so on. Made a OU for the restricted
>> user and
>> > moved the user there. Then added the OU GP with
>> the
>> > restrictions in user configuration. But the
>> restrictions
>> > does not apply. Tried checking block
inheritance &
>> no
>> > overide, using secedit to update the policys,
>> adding a
>> > group with the user to the GP security.
>> > What should I do to make this work?
>> >
>> > Regards,
>> > Patrik Gisselsson
>> >
>> >
>> >.
>> >
>> .
>>
>>
>
>
>.
>



Relevant Pages

  • constant USERENV 1030 errors
    ... USERENV05:05:08:106 ReadExtStatus: Reading Previous Status ... for extension ... USERENV05:05:08:215 ProcessGPO: ...
    (microsoft.public.win2000.group_policy)
  • GP not applying for W2000 TS User
    ... W2000 Terminal server using Group policy. ... Here's a verbose version of the user env log: (the GPO is ... USERENV08:25:25:879 ProcessGPO: Deferring ... and no security group membership change and extension ...
    (microsoft.public.win2000.group_policy)
  • Re: Logon Scripts dont run if user logs in too early
    ... USERENV10:35:11:343 LibMain: Process Name: ... USERENV10:37:48:593 SearchDSObject: Searching ... USERENV10:37:48:593 ProcessGPO: Deferring search for ... USERENV10:37:48:718 ProcessGPOs: Processing extension Registrierung ...
    (microsoft.public.win2000.general)
  • Slow Login on One Member Server
    ... USERENV16:02:59:875 ExtractProfileFromBackup: A profile already ... USERENV16:03:00:218 ProcessGPO: Deferring search for ... USERENV16:03:00:421 ProcessGPOs: Processing extension Registry ...
    (microsoft.public.windows.server.active_directory)
  • GPO not applied userenv log shows error 53 path not found
    ... I am trying to get a startup script to run on machines in an OU in a Windows ... 2000 AD domain using GPO. ... USERENV16:16:09:433 ProcessGPO: Machine has access to this GPO. ... USERENV16:16:09:473 GetGPOInfo: EvaluateDeferredGPOs failed. ...
    (microsoft.public.win2000.group_policy)