Group Policy Wont update on client



Hi All
Setup :
Novell 6.5 for File and Print, Primary login
Windows 2k3 AD as secondary login ,all passwords synced with Novell
All Client XP SP2 with SUS for updates (about 1000)
GPOs at OU level

Our issue was after a recent change to a GPO, no clients would receive updated GPOs. They also hung for about 30 seconds on preparing network connections during boot. All users could login but received no profiles (mapped in user account profile tab in AD).

We backed out of the change but the GPOs wouldnt re-apply. Even domain admins could not force a policy update on the clients. Removing from domain and re-entering worked as did re-image of machine. We tried adding new GPOs, disabling the old one but to no effect.

It would appear that local file rights had changed, to the extent where Group Policy couldnt update itself on the local machine.The change made was to remove Creator Owner rights on %SystemRoot% to prevent people deleting files they had created their themselves (Users were given Read and Execute through other group membership). This was to stop people intentionally breaking an in house application by deleting a dll after it had been Zenned to the user through Novell.

In the end Psexec, cacls, visual basic and lots of coffee managed to resolve it short term but does anyone know what happened, or even how to theoretically recreate it in a lab for testing ?

Thanks
.



Relevant Pages

  • Re: Atomuhr-Abgleicher gesucht f???????????
    ... > und b) die Clients damit synchronisieren. ... > mein liebstes Kind wäre wenn der Novell Server sich die Uhrzeit vom W2K ... Die MS Clients bekommen AFAIR bei jedem Login die Uhrzeit vom ... Erinnerung nicht trügt) und für den Novell Server gibst du 100,- aus. ...
    (microsoft.public.de.german.win2000.sonstiges)
  • Re: AT&T WiFi at McDonalds, etc
    ... encrypted with a unique one time WPA key delivered by a RADIUS server, ... All current wireless clients auto detect the method of authentication, ... and supply a corresponding dialog box for login if required. ... What part of the WPA-RADIUS login process doesn't work the way I ...
    (alt.internet.wireless)
  • Re: Antw: Re: Wirtschaftlichkeit Microsoft ADS zur NDS
    ... und GPO verteilung haben wir vor der Einführung der ADS ... in unserem Netz gemacht und da nicht alle Clients in der ADS ... GPO per ZEN. ... Novell auf der Basis Novell Netware Server bis 6.5. ...
    (microsoft.public.de.german.windows.server.active_directory)
  • [Full-disclosure] Novell Security Announcement NOVELL-SA:2006:001
    ... Novell Security Announcement ... Novell GroupWise 6.0 ... Novell Security Public Key ... For GroupWise 7 - Customers running GroupWise 7.0 Windows Clients ...
    (Full-Disclosure)
  • Novell Security Announcement NOVELL-SA:2006:001
    ... Novell Security Announcement ... Novell GroupWise 6.0 ... Novell Security Public Key ... For GroupWise 7 - Customers running GroupWise 7.0 Windows Clients ...
    (Bugtraq)