Parts of GPO not working.



Hello all,

Here is the problem I am having. I have a domain with 2 - 2003 domain
controllers and a number of XP and 2000 workstations. I have a GPO
that I need to have applied to some lab computers, most of which are
2000. I have a request that all of those computers not have Internet
access.

Problem I am having is that when the policy applies, I get the proxy
applied but cannot get to local and exempted websites. Tempermental it
is, because it also will not take away the connection page like I have
told it to.

- I have created an OU and put the computers into it and applied the
GPO to the OU.
- I have created a security group and put the computers into the group
and put the group into the security filtering under the Scope tab of
the GPO.
- I have tried to put just the GPO with Authenticated users into the
Scope and apply it to the OU that the computers are in.

I am not sure what else I can do to get this to work. I have included
the GPO settings so that way you can tell me if I have included
something I shouldn't have or need to put something in there I
haven't.

I have created an OU to test this on and will apply it to production
OUs once I have confirmed it works right.


Blocked_Web
Data collected on: 8/27/2008 2:56:38 PM hide all

Generalhide
Detailshide
Domain CIN.domain.com
Owner CIN\Domain Admins
Created 8/13/2008 2:35:06 PM
Modified 8/27/2008 2:56:28 PM
User Revisions 27 (AD), 27 (sysvol)
Computer Revisions 19 (AD), 19 (sysvol)
Unique ID {62CCD47D-ACEE-4F81-AA65-08875ED13CDC}
GPO Status Enabled

Linkshide
Location Enforced Link Status Path
Internet Blocked No Enabled CIN.domain.com/DOMAIN COMPUTERS/Internet
Blocked

This list only includes links in the domain of the GPO.
Security Filteringhide
The settings in this GPO can only apply to the following groups,
users, and computers:Name
CIN\BlockInternet
S-1-5-21-28014860-978782709-526660263-8115

WMI Filteringhide
WMI Filter Name None
Description Not applicable

Delegationhide
These groups and users have the specified permission for this GPOName
Allowed Permissions Inherited
CIN\BlockInternet Read (from Security Filtering) No
CIN\Domain Admins Edit settings, delete, modify security No
CIN\Enterprise Admins Edit settings, delete, modify security No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS Read No
NT AUTHORITY\SYSTEM Edit settings, delete, modify security No
S-1-5-21-28014860-978782709-526660263-8115 Read (from Security
Filtering) No

Computer Configuration (Enabled)hide
Administrative Templateshide
System/Group Policyhide
Policy Setting
Group Policy refresh interval for computers Enabled
This setting allows you to customize how often Group Policy is
applied
to computers. The range is 0 to 64800 minutes (45 days).
Minutes: 0

This is a random time added to the refresh interval to prevent
all clients from requesting Group Policy at the same time.
The range is 0 to 1440 minutes (24 hours)
Minutes: 0

Policy Setting
Internet Explorer Maintenance policy processing Enabled
Allow processing across a slow network connection Disabled
Do not apply during periodic background processing Disabled
Process even if the Group Policy objects have not changed Enabled

Policy Setting
User Group Policy loopback processing mode Enabled
Mode: Replace


Windows Components/Internet Explorerhide
Policy Setting
Make proxy settings per-machine (rather than per-user) Enabled

User Configuration (Enabled)hide
Windows Settingshide
Internet Explorer Maintenancehide
Connection/Automatic Browser Configurationhide
Policy Setting
Automatically detect configuration settings Enabled
Automatic Browser Configuration Not configured


Connection/Proxy Settingshide
Enable proxy settings
Protocol Server Port
HTTP 0.0.0.0 80
Secure 0.0.0.0 80
FTP 0.0.0.0 80
Gopher 0.0.0.0 80
Socks 0.0.0.0 80

Exceptions: Do not use proxy server for addresses beginning with
http://*.singledomain.com, http://x3.domain.com/login.cmms, http://home,
Do not use proxy server for local (intranet) addresses Enabled

Administrative Templateshide
Windows Components/Internet Explorer/Internet Control Panelhide
Policy Setting
Disable the Connections page Enabled

Thank you all in advance for your help and support.

I work 7-1630 EST.

Scott
.



Relevant Pages

  • RE: Remote Assistance not working
    ... I have tried these settings you recommend with no results. ... I have yet to get the offer remote assistance to work when launched from the ... The Group Policy on the computer of the novice user must be configured ... Start the Microsoft Management Console Group Policy snap-in. ...
    (microsoft.public.windows.server.sbs)
  • Re: Automated logoff using Winexit.scr
    ... New OU - New Policy ... Settings: Configure this key then Propogate inheritable permissions to ... Permissions granted: Authenticated Users: Read/Special ... test GPO linked to it trying to accomplish that and move a couple computers ...
    (microsoft.public.windows.group_policy)
  • RE: Group Policy Connundrum - Stick with it, its confusing!!!
    ... Group Policy Connundrum - Stick with it, ... Small Business Server Internet Connection Firewall ... Import the current Content Ratings Settings: ...
    (Security-Basics)
  • Re: Parts of GPO not working.
    ... If your users use other browsers like firefox from an usb stick/drive or whatever medium your policy will not help. ... I have a request that all of those computers not have Internet ... The settings in this GPO can only apply to the following groups, ... Group Policy refresh interval for computers Enabled ...
    (microsoft.public.windows.server.active_directory)
  • Re: How do I enable a locked screensaver policy through Windows 2000 Active Directory
    ... Screen Saver Group Policy settings are User settings, not Computer settings, ... Group Policies will have no affect at all on Windows NT 4 client computers ...
    (microsoft.public.win2000.general)