Re: GPO for user not applied



Hi,

That was the problem, Authenticated users lacked read permissions on the OU where the user object is.

Thanks for your help Mike

Kind Regards,
Uffe

"Mike Luo [MSFT]" <v-miluo@xxxxxxxxxxxxxxxxxxxx> wrote in message news:ifdP5TEbHHA.296@xxxxxxxxxxxxxxxxxxxxxxxxx
Hello,

I checked the userenv.log file and found "GetUserNameEx failed with 1317".
This message means that the user can't be determined and apply GPOs.
This may be caused the Authenticated Users group having no permissions on
the container including users and computers, please check the domain, OU,
computers, make sure that Authenticated Users group has read permission.

Thanks & Regards,

Mike Luo

Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.


.



Relevant Pages

  • RE: AD users and computers security
    ... computers and logged on as that test user to test admin capabilities. ... Authenticated Users was included on all OUs with read permissions -- that's ... > Authenticated Users Group Has Too Many Permissions to the SYSVOL Network ... Windows Server 2003 family provides three groups whose ...
    (microsoft.public.windows.server.migration)
  • Re: Mistake, please help !
    ... Under ADSIedit I have open the properties and find a permissions tab, ... > entry for the authenticated users group with the full control DENY ...
    (microsoft.public.exchange.admin)
  • Microsoft Secure DNS and Authenticated Users group interdependencies
    ... I would really appreciate anyone who considers themselves DNS experts to take a good look at this post. ... Only if Authenticated Users group has a write access will the record update. ... If the a record is set with default permissions and Authenticated Users has elevated permissions set, after the client's successfully updates the record, the client is added to the ACE with WRITE permissions and Authenticated Users permissions get reset. ...
    (microsoft.public.windows.server.dns)
  • Re: Prevent "Authenticated Users" from browsing Active Directory
    ... > properties/security and remove everyone and authenticated users from the ... > permissions - that is why I recommend removing the whole group. ... > enterprise administrator, schema administrator, administrators, and ...
    (microsoft.public.win2000.security)
  • Re: ActiveDirectoryMembershipProvider woes
    ... Domain Users are indeed members of the Pre-Windows 2000 Compatible Access group as are Authenticated Users and Exchange Domain Servers. ... many cases permissions are delegated to the Pre-Win2K group but in some domains the Domain Users group is not included in this group so normal users only end up getting the permissions that are delegated to Authenticated Users instead. ... Co-author of "The .NET Developer's Guide to Directory Services ... "Thomas" wrote in message ...
    (microsoft.public.dotnet.framework.aspnet.security)