Re: Group policy not applied to certain users
- From: "Klaas" <p.j.g.van_andel@xxxxxxxxxxxxxx>
- Date: Fri, 6 May 2005 10:42:14 +0200
Hi,
Some additional info:
Using the GPMC, from Group Policy Results I can't select these users from
the computer they logged on to. I can only select another user on that
computer.
Peter
"Klaas" <p.j.g.van_andel@xxxxxxxxxxxxxx> wrote in message
news:uhH2PWLTFHA.1152@xxxxxxxxxxxxxxxxxxxxxxx
> Hi,
>
> We have a problem applying GPO's to users.
> One OU contains two users (pjg-test and pjg-test2). A GPO is applied to a
> parent OU and contains a logon script. That script is processed for
> pjgvanandel, but not for pjg-test. It's tested on one workstation.
> In userenv.log we see the following for pjgvanandel:
>
> USERENV(29c.b14) 14:12:28:657 ProcessGPOs: Calling GetGPOInfo for normal
> policy mode
> USERENV(29c.b14) 14:12:28:657 GetGPOInfo:
********************************
> USERENV(29c.b14) 14:12:28:657 GetGPOInfo: Entering...
> USERENV(29c.b14) 14:12:28:672 GetGPOInfo: Server connection established.
> USERENV(29c.b14) 14:12:28:688 GetGPOInfo: Bound successfully.
> USERENV(29c.b14) 14:12:28:703 SearchDSObject: Searching
> <OU=cdiv,OU=dnst,OU=LUMC,dc=mycomp,dc=prod,dc=dom>
> USERENV(29c.b14) 14:12:28:703 SearchDSObject: Found GPO(s): < >
> USERENV(29c.b14) 14:12:28:703 SearchDSObject: Searching
> <OU=dnst,OU=LUMC,dc=mycomp,dc=prod,dc=dom>
> USERENV(29c.b14) 14:12:28:703 SearchDSObject: Found GPO(s):
>
<[LDAP://cn={9F51BBEB-40FE-4A7C-A059-4C6C9BB4810B},cn=policies,cn=system,dc=
>
mycomp,dc=prod,dc=dom;0][LDAP://cn={553CFF2D-34F4-4C58-955A-A96164BA9F8A},cn
> =policies,cn=system,dc=mycomp,dc=prod,dc=dom;0]>
> USERENV(29c.b14) 14:12:28:703 ProcessGPO: ==============================
> USERENV(29c.b14) 14:12:28:703 ProcessGPO: Deferring search for
>
<LDAP://cn={9F51BBEB-40FE-4A7C-A059-4C6C9BB4810B},cn=policies,cn=system,dc=m
> ycomp,dc=prod,dc=dom>
> USERENV(29c.b14) 14:12:28:703 ProcessGPO: ==============================
> USERENV(29c.b14) 14:12:28:703 ProcessGPO: Deferring search for
>
<LDAP://cn={553CFF2D-34F4-4C58-955A-A96164BA9F8A},cn=policies,cn=system,dc=m
> ycomp,dc=prod,dc=dom>
> USERENV(29c.b14) 14:12:28:703 SearchDSObject: Searching
> <OU=LUMC,dc=mycomp,dc=prod,dc=dom>
> USERENV(29c.b14) 14:12:28:703 SearchDSObject: Found GPO(s):
>
<[LDAP://cn={6BC72289-1270-4FC4-B13B-7B72659F2295},cn=policies,cn=system,dc=
> mycomp,dc=prod,dc=dom;2]>
> USERENV(29c.b14) 14:12:28:703 ProcessGPO: ==============================
> USERENV(29c.b14) 14:12:28:703 ProcessGPO: Deferring search for
>
<LDAP://cn={6BC72289-1270-4FC4-B13B-7B72659F2295},cn=policies,cn=system,dc=m
> ycomp,dc=prod,dc=dom>
> USERENV(29c.b14) 14:12:28:703 SearchDSObject: Searching
> <dc=mycomp,dc=prod,dc=dom>
> USERENV(29c.b14) 14:12:28:703 SearchDSObject: Found GPO(s):
>
<[LDAP://CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,dc=
> mycomp,dc=prod,dc=dom;0]>
> USERENV(29c.b14) 14:12:28:703 ProcessGPO: ==============================
> USERENV(29c.b14) 14:12:28:703 ProcessGPO: Deferring search for
>
<LDAP://CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,dc=m
> ycomp,dc=prod,dc=dom>
> USERENV(29c.b14) 14:12:28:719 SearchDSObject: Searching
> <CN=Default-First-Site-Name,CN=Sites,CN=Configuration,dc=prod,dc=dom>
> USERENV(29c.b14) 14:12:28:719 SearchDSObject: No GPO(s) for this object.
> USERENV(29c.b14) 14:12:28:719 ProcessGPO: ==============================
> USERENV(29c.b14) 14:12:28:719 ProcessGPO: Searching
>
<cn={6BC72289-1270-4FC4-B13B-7B72659F2295},cn=policies,cn=system,dc=mycomp,d
> c=prod,dc=dom>
> USERENV(29c.b14) 14:12:28:719 ProcessGPO: User has access to this GPO.
>
> For pjg-test we see the errors "Processing failed with error 997"and
> "Leaving with 0":
>
> USERENV(29c.a5c) 12:22:08:762 ProcessGPOs: Calling GetGPOInfo for normal
> policy mode
> USERENV(29c.a5c) 12:22:08:762 GetGPOInfo:
********************************
> USERENV(29c.a5c) 12:22:08:762 GetGPOInfo: Entering...
> USERENV(29c.a5c) 12:22:08:762 GetGPOInfo: Server connection established.
> USERENV(29c.a5c) 12:22:08:778 GetGPOInfo: Bound successfully.
> USERENV(29c.a5c) 12:22:08:778 SearchDSObject: Searching
> <OU=cdiv,OU=dnst,OU=LUMC,dc=mycomp,dc=prod,dc=dom>
> USERENV(29c.a5c) 12:22:08:778 SearchDSObject: Found GPO(s): < >
> USERENV(29c.a5c) 12:22:08:778 SearchDSObject: Searching
> <OU=dnst,OU=LUMC,dc=mycomp,dc=prod,dc=dom>
> USERENV(29c.a5c) 12:22:08:778 SearchDSObject: Found GPO(s):
>
<[LDAP://cn={9F51BBEB-40FE-4A7C-A059-4C6C9BB4810B},cn=policies,cn=system,dc=
>
mycomp,dc=prod,dc=dom;0][LDAP://cn={553CFF2D-34F4-4C58-955A-A96164BA9F8A},cn
> =policies,cn=system,dc=mycomp,dc=prod,dc=dom;0]>
> USERENV(29c.a5c) 12:22:08:778 ProcessGPO: ==============================
> USERENV(29c.a5c) 12:22:08:778 ProcessGPO: Deferring search for
>
<LDAP://cn={9F51BBEB-40FE-4A7C-A059-4C6C9BB4810B},cn=policies,cn=system,dc=m
> ycomp,dc=prod,dc=dom>
> USERENV(29c.a5c) 12:22:08:778 ProcessGPO: ==============================
> USERENV(29c.a5c) 12:22:08:778 ProcessGPO: Deferring search for
>
<LDAP://cn={553CFF2D-34F4-4C58-955A-A96164BA9F8A},cn=policies,cn=system,dc=m
> ycomp,dc=prod,dc=dom>
> USERENV(29c.a5c) 12:22:08:778 SearchDSObject: Searching
> <OU=LUMC,dc=mycomp,dc=prod,dc=dom>
> USERENV(29c.a5c) 12:22:08:778 SearchDSObject: Found GPO(s):
>
<[LDAP://cn={6BC72289-1270-4FC4-B13B-7B72659F2295},cn=policies,cn=system,dc=
> mycomp,dc=prod,dc=dom;2]>
> USERENV(29c.a5c) 12:22:08:778 ProcessGPO: ==============================
> USERENV(29c.a5c) 12:22:08:778 ProcessGPO: Deferring search for
>
<LDAP://cn={6BC72289-1270-4FC4-B13B-7B72659F2295},cn=policies,cn=system,dc=m
> ycomp,dc=prod,dc=dom>
> USERENV(29c.a5c) 12:22:08:778 SearchDSObject: Searching
> <dc=mycomp,dc=prod,dc=dom>
> USERENV(29c.a5c) 12:22:08:778 SearchDSObject: Found GPO(s):
>
<[LDAP://CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,dc=
> mycomp,dc=prod,dc=dom;0]>
> USERENV(29c.a5c) 12:22:08:778 ProcessGPO: ==============================
> USERENV(29c.a5c) 12:22:08:778 ProcessGPO: Deferring search for
>
<LDAP://CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,dc=m
> ycomp,dc=prod,dc=dom>
> USERENV(29c.a5c) 12:22:08:778 GetGPOInfo: Leaving with 0
> USERENV(29c.a5c) 12:22:08:778 GetGPOInfo:
********************************
> USERENV(29c.a5c) 12:22:08:778 ProcessGPOs: GetGPOInfo failed.
> USERENV(29c.a5c) 12:22:08:778 ProcessGPOs: No WMI logging done in this
> policy cycle.
> USERENV(29c.a5c) 12:22:08:794 ProcessGPOs: Processing failed with error
997.
> USERENV(29c.a5c) 12:22:08:794 LeaveCriticalPolicySection: Critical section
> 0x988 has been released.
> USERENV(29c.a5c) 12:22:08:794 ProcessGPOs: User Group Policy has been
> applied.
> USERENV(29c.a5c) 12:22:08:794 ProcessGPOs: Leaving with 0.
> USERENV(29c.a5c) 12:22:08:794 ApplyGroupPolicy: Leaving successfully.
>
> The difference is that for pjg-test there's no entry
> SearchDSObject: Searching
> <CN=Default-First-Site-Name,CN=Sites,CN=Configuration,dc=prod,dc=dom> in
> userenv.log
> My conclusion is that the policy engine crashes at this point, but why?
The
> user can browse to that site using AD Sites and Services. There is no GPO
> linked to the site.
> Both users are ordinary users. Adding user pjg-test to the Domain Admins
> group didn't help.
> DNS is OK. I can start
>
\\mycomp.prod.dom\sysvol\mycomp.prod.dom\policies\{553CFF2D-34F4-4C58-955A-A
> 96164BA9F8A}\user\scripts\logon\cinfo.vbs from \Start\Run (XP SP1), so
both
> users have access to this policy.
>
> Can somebody help me with this one?
> TIA, Peter
>
>
.
- Prev by Date: access rights for local Admin to a Domain Controller
- Next by Date: Re: access rights for local Admin to a Domain Controller
- Previous by thread: access rights for local Admin to a Domain Controller
- Next by thread: Re: Applying Computer Policy to Users
- Index(es):
Relevant Pages
|
Loading