RE: Group Policy only works if user is member of local admin group

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



I checked the event logs and found nothing out of the ordinary in them. I
also ran group policy, selecting both the user and PC. The correct settings
showed up in the resulting report.

Is there any possibiity that our domain controller running without SP1 and
and all our other Win2k3 servers have SP1 installed create any issues? I
suppose that's something that can only be answered by applying SP1.

I'll have to play aournd a bit with your other suggestion about debug logging.

Thanks.

--


Bob Hartung, Dir of I.T.
Wisco Industries, Inc.
Oregon, WI 53575



"Brian Delaney" wrote:

Are there any errors on the clients in the Application Event log when running
gpupdate /force and the policies are not applying?

If you run rsop.msc as a user when the policies are not applying, is there a
red x on the user settings? If right click go to properties and error
information. What is the error?

Userenv debug logging may also help in troubleshooting the problem:
http://support.microsoft.com/kb/221833/en-us

Brian Delaney

"bhartung" wrote:

Within the last 6 months, I've been converting from a Netware NDS network to
a MS Windows 2003 Active Directory as our primary network. I've worked
through the file/directory rights issues and things are running pretty
smooth. One that's not working so smoothly is Group Policy.

I have several user groups that I want to enforce some fairly simple
policies on. For instance, on a group of PCs on our manufacturing floor, I
want to enforce the classic desktop and prevent changing the background.
Things like that. I created an organizational unit (OU), placed the users I
want to control in it and then created a group policy and associated it with
the OU.

The PCs these users are logging on to are Dell PCs with Windows XP Pro SP2.
They have all been successfully joined to our single domain.

When I test for these policies on the Dell PCs, none of them are enforced.
Even if I shell out and run "gpupdate /force" on both the domain controller
and pc and relogin and still no policies.

I have loaded the group policy snap-in on the Dell PCs and checked the local
group policies and nothing is conifigured.

Now here's an odd thing I discovered. If the user I'm logging in as is not a
member of the local admin group, the policies do not apply. If I add that
user to the local admin group, the policies can apply.

I'm the only one who has created any new policies and I've never made any
changes to the default domain policies

I'm stumped. I'd be grateful for any advice on what might be preventing
application of polices.

Bob Hartung, Dir of I.T.
Wisco Industries, Inc.
Oregon, WI 53575

.



Relevant Pages

  • Re: Boy, did I screw up some Group Policies!
    ... Create a new Group Policy for each set of policies you want to enforce. ... (There follows a number of specific policies set under Administrative Templates in the Group Editor.) ... I did all this work from the Domain Controller console, logged in under the Domain Administrator account. ... Now I'm a security novice, so it made no sense to me that after I made these changes, when I logged into a workstation as the Domain Controller, I had no Task bar context menu and no Control Panel. ...
    (microsoft.public.win2000.group_policy)
  • Re: password to expire in 2 days ... will laptop be inexcessable?
    ... This will reveal my general ignorance concerning Group Policy, ... Pro stand-alone (i.e. workgroup) box, the "password age" policy is not ... In Group Policies, none of the various settings is enabled. ...
    (microsoft.public.windowsxp.general)
  • RE: Error adjusting Group Policies
    ... But you should never change those policies. ... It will reset the ... How To Reset User Rights in the Default Domain Group Policy in Windows ... PLEASE NOTE the newsgroup SECURE CODE and PASSWORD were ...
    (microsoft.public.windows.server.sbs)
  • Re: Windows cannot query for the list of Group Policy Objects Event log ID 1030
    ... One of the most common group policy problems which produces hidden policies ... or inconsistent results is when SYSVOL may not be replicating correctly. ... The utility will report all "Policies OK" if all Domain Controllers SYSVOLS ...
    (microsoft.public.windows.group_policy)
  • Re: Policies partially apply
    ... Group Policy problems are often caused by dns misconfiguration ... > clients which apply the computer policies from an AD Windows 2000 Server ...
    (microsoft.public.windows.group_policy)