Re: GPO Problem

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Danny - Please clarify how this applies to my problem?


To add to my existing problem description, I found on a couple other
machines I ran rsop.msc the new WSUS policy was not even listed, and the old
SUS policy was still in place. These machines got the following error
message:

ADMINISTRATIVE TEMPLATES
The latest versions of the ADM files below are not available. This can be
due to insufficient permissions or unavailable network resources. The local
copy of these ADM files will be used.

Details:
wuau.adm
Location - \\domain name.com\Sysvol\domain name.com\Policies\{16B31360-.....
Error - Access is denied
conf.adm
Location - \\domain name.com\Sysvol\domain name.com\Policies\{16B31360-.....
Error - Access is denied



"Danny Sanders" wrote:

I recently noticed some users were able to set passwords that did not meet
the "Default Domain Policy" minimum requirements applied to their OU.

Account policies are one to a domain. You apply them at the domain level.
Account policies applied at the OU level only take affect when logging in
locally to a computer in that OU.


"john d" <johnd@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:A75454DC-9E65-4010-AEF8-44EB9C60ECBE@xxxxxxxxxxxxxxxx
I recently noticed some users were able to set passwords that did not meet
the "Default Domain Policy" minimum requirements applied to their OU. In
addition, I recently removed a policy outlining the SUS settings for all
employee computers and replaced it with a new WSUS policy. When I run
RSOP.msc on an employee machine, I can see that the pc is pulling down the
"Default Domain Policy" and the newly applied WSUS policy, however the
settings being passed down are from teh old SUS policy.

With that being said, I noticed the following Events in the application
log
of the employee machines:


Event id: 1043
Windows cannot access the registry information at \\domain
name.com\sysvol\domina
name.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\registry.pol.
(Access is denied. ).

Event id: 1096
Windows cannot access the registry policy file, \\domain
name.com\sysvol\domain
name.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\registry.pol.
(Access is denied. ).

Event ID: 1030
Windows cannot query for the list of Group Policy Objects. A message that
describes the reason for this was previously logged by the policy engine.


As per the following article,
http://technet2.microsoft.com/WindowsServer/en/library/0c73a3d4-4f93-4490-80f1-299eea89177f1033.mspx?mfr=true,
I have verified that replication between the domain controllers is
working,
as the registry.pol file exists on all 5 Domain Controller machines. This
leads me to believe that the "Default Domain Policy" is corrupt. How do I
go
about confirming this and resolving the issue?





.



Relevant Pages

  • Re: Restricted Groups Not Working
    ... 2:Please bear in mind that 90% of the policy is applying it only seems to be the restricted groups section that isnt taking effect and 'allow to load and unload device drivers' which also doesnt seem to be working. ... Also all machines are running SP2 and with the latest hotfixes as provided by our SUS server. ... When adding users to the "Administrators" group, remember that you can't browse for that group, you have to type "Administrators". ... In the "Members of this group", browse for the "Global Security Group" created in Step 1. ...
    (microsoft.public.windows.group_policy)
  • Re: EventID 1054 from Userenv for startup script
    ... So if you said "some machines don't have full access to the network ... at startup" the GPO's seems not to apply correct. ... startup script policy. ...
    (microsoft.public.windows.group_policy)
  • Re: foreign language gpo
    ... Part of my issue was that I added a policy to allow power users the rights ... power users group on a french OS is spelt different than from an English OS ... (most machines are win2k, Policy editing machine is Win XP with GPMC). ... It happens because the foreign language ADM files are newer than yours ...
    (microsoft.public.windows.group_policy)
  • Re: Restricted Groups Not Working
    ... Have you tried running the GPMC's "Group Policy ... Also all machines are running SP2 and with the latest hotfixes as ... are all the machines (desktops and laptops) running XP ...
    (microsoft.public.windows.group_policy)
  • Re: GPO not being applied
    ... They used to be in a workgroup and this SBS domain was the ... machines relative to the removeable media settings. ... Remember Local Policy is ... SBS has an OU with all users and I have a custom GPO bound to ...
    (microsoft.public.windows.server.sbs)