Recommended Posts

I have never seen this before and I'm waiting to hear from the company that does our imaging software, as well.

 

We have a blocked inheritance OU for a temporary location during imaging to stop policies from interfering with anything, then they're moved to an OU with basic policies until moved to their final location.  This have worked fine for 2 years.  I have one cart that started out as two laptops that had issues.  I re-imaged them and everything was fine.  I needed to do the whole care anyway, so re-imaged those.  I held back 3 to finish updates and all 3 of them exhibit the same issue.  I can DM the files to someone if the want to see them. 

 

Basically, in the bad one, it has this:D

Quote

 

uring last computer policy refresh on 10/23/2018 2:00:52 PM

 

No Errors Detected

A fast link was detected More information...

Inheritance is blocking all non-enforced GPOs linked above local.domain/ComputersENGL

 During last user policy refresh on 10/23/2018 1:57:18 PM

 

No Errors Detected

Computer was set to process policy in Replace mode More information...

A fast link was detected More information...

 

 

The good one this:

Quote

 

During last computer policy refresh on 10/23/2018 2:00:51 PM

 

No Errors Detected

A fast link was detected More information...

 During last user policy refresh on 10/23/2018 12:19:11 PM

 

No Errors Detected

A fast link was detected More information...

 

 

They are not in that OU any longer, so I don't know why it not pulling the GPOs.  It's actually pulling computer GPO, but not User GPOs.

 

I have tried removing/adding computers to the domain, but nothing changes.  I tried deleting the security database from machine and did a GPUDATE /FORCE and nothing changes.

 

Also:

Quote

 

Computer name DOMAIN\HS-MOB03-STU25

Domain  local.domain

SiteDefault-First-Site-Name

Organizational Unit local.domain/Workstations/Mobile/HS_MS/HSCart03

Block Inheritance local.domainComputersENGL

 

The Block Inheritance flag is only difference in GPRESULT in that section.

Link to comment
https://www.neowin.net/forum/topic/1375681-group-policy-issue/
Share on other sites

So the OU is set to block inheritance

The PC resides in the OU that is set to block inheritance

 

Did you verify where that computer object is located?  Did it move in the domain structure or given an new name that would cause it to move out?  I never liked carpet bombing entire OU's....I use security group membership to identify what users or computers can get that policy.  If it isn't a member of that security group it won't get the policy (yes you can add computers to security groups).

The OU is set to Block Inheritance during imaging.  Once imaging is complete, it is moved to a different OU.  Both OUs are in the root of our domain, so they're at the same lever.

 

The PCs reside in a Workstations folder that has basic machine policies with building and such below it.

 

I verified the computer location.  I check the Attributes on the object to verify it's OU, also.  

 

I actually never realized machines could be added to groups.  I will look into that to see if I can get around my issue temporarily, but probably not.

 

If I manually delete the workstation object BEFORE a re-image, the policies work fine.  I can dis-join, reboot, run GPUPDATE /FORCE /BOOT, delete object, reboot, re-join, reboot, and it will eventually get the right policies, or I can force a GPUPDATE.  We're using LAPS, so that's not really feasible.  I just plan on doing our labs for now, and our laptop carts over Thanksgiving week.

 

I tried several tutorials involving deleting registry keys and/or security databases, but none have work so far.  The only working solutions are the two above.  

 

We plan on setting all our machines to PXE boot, anyway, but were going to wait until next year.   We'll just expedite the process.  Was just hoping someone had an idea of what is happening and a better/easier fix.  I have ticket in with our imaging software people, but I'm sure they'll say it's a Windows issue.  Is funny, in the latest Windows Cumulative Update for 1803, it says that there is a fix for GPO with GPRESULT and RSOP, but it says the policies are applying, they just LOOK like they aren't.  Our policies are NOT applying for sure.

  • 2 weeks later...

Honestly, without seeing it and troubleshooting myself all I can do is shoot in the dark with solutions.  

 

You will have to run different tools to see what is going on as well as checking the event viewer.   

 

gpresult/r in an admin prompt will show you what is supposed to get applied at time of running the command, you can see if they are disabled for some reason.  If you want I can help with it if you want/can have remote support.  

 

gpresult/h at an admin prompt can help identify if there are other policies that are overriding your policy that you are trying to push down.  

 

Also the group policy management console can help too if you the group policy results wizard.  I rarely ever have group policies apply to entire OU, they are usually filtered via security groups....they can be computer security groups or user security groups.....To add a computer to a security group, open the security group in ADUC, go to the Members tab, choose Add, Click the Object Types Button, check off Computers and hit OK, search for your computers you want to add and add them in.  Doing it this way, you do not have to add them to a restricted OU first, then move them out.  You simply have to add them to whatever group you want when you want them to apply the GPO.  I do this with WSUS, dymanic VLANS, wireless, software installs, printer installs, and other policies that I want to be applied to specific groups of user computers.

I figured out the issue finally.  I had created a policy with Loopback Processing.  I didn't realize that would block all the policies.  I had read about loopback before, but didn't fully understand the downside, until now.  I explained everything rather well.  I ran the Modeling Wizard and it was fine.  Thanks for all the other information and the offer to help.  If I run into more issues later, I'll post back.  Once I removed the loopback policy, everything seems to be returning to normal regarding processing.  I just couldn't figure out why it was affecting some and not others until I read that certain article.

 

I definitely like the idea of using Security Groups for computers.  I had never heard that.  Thanks again for the help.

 

 

This topic is now closed to further replies.
  • Posts

    • Chrome has history of being the browser everyone uses because Internet Explorer sucks, not realizing that Edge changed that, but people got into the habit of using Chrome. I use Brave and I've never been happier with a browser. It does what it is meant to do and gets out of the way.
    • Wino Mail -> Microsoft Outlook (the new one). Just sayin.
    • Microsoft launches Godot Sample to streamline Xbox PC game development on the engine by Pulasthi Ariyasinghe Microsoft today announced a new endeavor that aims to make it simpler for Godot developers to get their products into the Xbox PC ecosystem. Dubbed the "XBOX Godot Sample," this is a new public reference for developers using the open-source engine. This is set to serve as an example of how Microsoft GDK, Xbox Services, and PlayFab can be integrated into their projects. The sample is available now on GitHub as a working example. This covers key features in gaming projects that developers may need to release their projects on Xbox PC, with everything from matchmaking and game sign-in to gamepad compatibility with Godot being covered. This release is being called the first step in giving Godot developers the tools to bring their games over to Xbox PC, with more changes to come based on feedback and issue reports. However, the company was clear that this is not related to bringing Godot projects to Xbox consoles. The engine's open development model stops it from accessing console SDKs due to the requirement of NDAs and legal contracts. Here's how it explained this Godot sample project's focus: This is a source-only sample, not a product. It's MIT-licensed at the wrapper layer; the GDK and PlayFab dependencies still require their own installs and license acceptance, consistent with our other XBOX samples. There is no set update cadence for support or maintenance. We’ll watch the repo, monitor issues, and iterate where it makes sense, but this isn't a commercial release. That said, we’re excited to hear your feedback and see any community PRs, as we evolve this together. This is the first step in bringing Godot for XBOX on PC. We plan to evolve it over time based on what the community tells us is most valuable. This sample is built specifically for XBOX on PC. It doesn’t include support for XBOX Series X|S or XBOX One. If you’re already building for XBOX Series X|S or XBOX One, please talk with your XBOX representative. If not, you can get started by signing up here. Game developers can find the XBOX Godot Sample by heading to GitHub over here. Documentation on how to get started with Godot for building an Xbox PC project can be seen here.
    • I don't understand the vision. Do people really want to buy a new computer from Dell with 6 browsers installed? We all keep asking for Microsoft to stop having so much junk on their OS, and adding a bunch of browsers seems to go against that. Ideally, we would just be asked what browser we want during OOBE but Google is just going to pay Dell a bunch of money to include Chrome. Additionally, would you want your phones to start including all the browsers too when you get them? The only thing I ever wanted was to be able to uninstall IE or edge and I believe you are now able to. I do agree that microsoft needs to chill with their "are you sure you don't want to try edge before you install chrome" ads when going to download chrome.
  • Recent Achievements

    • Collaborator
      Asgardi earned a badge
      Collaborator
    • Conversation Starter
      mobandz earned a badge
      Conversation Starter
    • Apprentice
      fernan99 went up a rank
      Apprentice
    • One Month Later
      nothanks earned a badge
      One Month Later
    • One Month Later
      B2Proxy earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      469
    2. 2
      PsYcHoKiLLa
      243
    3. 3
      Skyfrog
      79
    4. 4
      FloatingFatMan
      73
    5. 5
      Michael Scrip
      60
  • Tell a friend

    Love Neowin? Tell a friend!