Recommended Posts

I have never seen this before and I'm waiting to hear from the company that does our imaging software, as well.

 

We have a blocked inheritance OU for a temporary location during imaging to stop policies from interfering with anything, then they're moved to an OU with basic policies until moved to their final location.  This have worked fine for 2 years.  I have one cart that started out as two laptops that had issues.  I re-imaged them and everything was fine.  I needed to do the whole care anyway, so re-imaged those.  I held back 3 to finish updates and all 3 of them exhibit the same issue.  I can DM the files to someone if the want to see them. 

 

Basically, in the bad one, it has this:D

Quote

 

uring last computer policy refresh on 10/23/2018 2:00:52 PM

 

No Errors Detected

A fast link was detected More information...

Inheritance is blocking all non-enforced GPOs linked above local.domain/ComputersENGL

 During last user policy refresh on 10/23/2018 1:57:18 PM

 

No Errors Detected

Computer was set to process policy in Replace mode More information...

A fast link was detected More information...

 

 

The good one this:

Quote

 

During last computer policy refresh on 10/23/2018 2:00:51 PM

 

No Errors Detected

A fast link was detected More information...

 During last user policy refresh on 10/23/2018 12:19:11 PM

 

No Errors Detected

A fast link was detected More information...

 

 

They are not in that OU any longer, so I don't know why it not pulling the GPOs.  It's actually pulling computer GPO, but not User GPOs.

 

I have tried removing/adding computers to the domain, but nothing changes.  I tried deleting the security database from machine and did a GPUDATE /FORCE and nothing changes.

 

Also:

Quote

 

Computer name DOMAIN\HS-MOB03-STU25

Domain  local.domain

SiteDefault-First-Site-Name

Organizational Unit local.domain/Workstations/Mobile/HS_MS/HSCart03

Block Inheritance local.domainComputersENGL

 

The Block Inheritance flag is only difference in GPRESULT in that section.

Link to comment
https://www.neowin.net/forum/topic/1375681-group-policy-issue/
Share on other sites

So the OU is set to block inheritance

The PC resides in the OU that is set to block inheritance

 

Did you verify where that computer object is located?  Did it move in the domain structure or given an new name that would cause it to move out?  I never liked carpet bombing entire OU's....I use security group membership to identify what users or computers can get that policy.  If it isn't a member of that security group it won't get the policy (yes you can add computers to security groups).

The OU is set to Block Inheritance during imaging.  Once imaging is complete, it is moved to a different OU.  Both OUs are in the root of our domain, so they're at the same lever.

 

The PCs reside in a Workstations folder that has basic machine policies with building and such below it.

 

I verified the computer location.  I check the Attributes on the object to verify it's OU, also.  

 

I actually never realized machines could be added to groups.  I will look into that to see if I can get around my issue temporarily, but probably not.

 

If I manually delete the workstation object BEFORE a re-image, the policies work fine.  I can dis-join, reboot, run GPUPDATE /FORCE /BOOT, delete object, reboot, re-join, reboot, and it will eventually get the right policies, or I can force a GPUPDATE.  We're using LAPS, so that's not really feasible.  I just plan on doing our labs for now, and our laptop carts over Thanksgiving week.

 

I tried several tutorials involving deleting registry keys and/or security databases, but none have work so far.  The only working solutions are the two above.  

 

We plan on setting all our machines to PXE boot, anyway, but were going to wait until next year.   We'll just expedite the process.  Was just hoping someone had an idea of what is happening and a better/easier fix.  I have ticket in with our imaging software people, but I'm sure they'll say it's a Windows issue.  Is funny, in the latest Windows Cumulative Update for 1803, it says that there is a fix for GPO with GPRESULT and RSOP, but it says the policies are applying, they just LOOK like they aren't.  Our policies are NOT applying for sure.

  • 2 weeks later...

Honestly, without seeing it and troubleshooting myself all I can do is shoot in the dark with solutions.  

 

You will have to run different tools to see what is going on as well as checking the event viewer.   

 

gpresult/r in an admin prompt will show you what is supposed to get applied at time of running the command, you can see if they are disabled for some reason.  If you want I can help with it if you want/can have remote support.  

 

gpresult/h at an admin prompt can help identify if there are other policies that are overriding your policy that you are trying to push down.  

 

Also the group policy management console can help too if you the group policy results wizard.  I rarely ever have group policies apply to entire OU, they are usually filtered via security groups....they can be computer security groups or user security groups.....To add a computer to a security group, open the security group in ADUC, go to the Members tab, choose Add, Click the Object Types Button, check off Computers and hit OK, search for your computers you want to add and add them in.  Doing it this way, you do not have to add them to a restricted OU first, then move them out.  You simply have to add them to whatever group you want when you want them to apply the GPO.  I do this with WSUS, dymanic VLANS, wireless, software installs, printer installs, and other policies that I want to be applied to specific groups of user computers.

I figured out the issue finally.  I had created a policy with Loopback Processing.  I didn't realize that would block all the policies.  I had read about loopback before, but didn't fully understand the downside, until now.  I explained everything rather well.  I ran the Modeling Wizard and it was fine.  Thanks for all the other information and the offer to help.  If I run into more issues later, I'll post back.  Once I removed the loopback policy, everything seems to be returning to normal regarding processing.  I just couldn't figure out why it was affecting some and not others until I read that certain article.

 

I definitely like the idea of using Security Groups for computers.  I had never heard that.  Thanks again for the help.

 

 

This topic is now closed to further replies.
  • Posts

    • If you actually used it instead of responding like a petulant child you might be surprised. I switched from Google some time ago and have been very satisfied.
    • I am one of the first people to use the DXVK technology. In the channel below you can see some videos that I have made using this technology, including Assassin's Creed Odyssey. https://www.youtube.com/@nahum7995/videos Assassin's Creed Odyssey experienced several bugs and technical issues during its first months after release. It launched with its own fair share of funny but frustrating glitches. I ran it on DXVK 9 days after its release and I played it for many hours but didn't see a single significant bug on Linux. Assassin's Creed Odyssey is widely celebrated for pushing the franchise in bold new directions and specifically for nailing several elements better than any other title in the AC series: Player Choice & Branching Narrative, The Mercenary & Cultist System, Mythological Integration, Overpowered Combat Abilities, Open World Exploration But what I'm trying to point out is that this game wasn't quite playable on most windows systems, until a few months after its release when most of the bugs were fixed. However, on Linux it ran completely flawless from day one, although DXVK had seen little development and refinement at the time. What do you think the situation will be in 2026 now that most bugs and glitches of DXVK have been completely eliminated? This is information from Google about these situations that I am quoting. In many cases, using DXVK (a translation layer that converts DirectX 9, 10, or 11 into Vulkan) can result in more stable frame times and higher performance than native Windows rendering. This happens primarily by bypassing driver overhead and multithreading draw calls that were previously restricted to a single CPU core. Older APIs (like DirectX 9 and 11) are largely single-threaded on the CPU side. DXVK translates these calls to Vulkan, which is highly multi-threaded. This reduces CPU-bound stuttering on weaker processors. In certain cases, GPU manufacturers (especially AMD) have significantly better and more modern Vulkan drivers than they do for legacy DirectX. Vulkan gives developers—and in this case, the translation layer—closer control over how resources are held in VRAM. This can prevent micro-stutters and sudden frame drops during chaotic gameplay. Yes, certain games, particularly older DirectX 9 to 11 titles, can run with fewer crashes on DXVK than on native Windows. By intercepting DirectX draw calls and translating them into the modern, highly efficient Vulkan API, DXVK bypasses the limitations and poor driver support that cause instability in aging game engines. PlayStation 1, PlayStation 2 and PlayStation 3 can be easily and perfectly emulated on Linux. In fact, modern Linux emulators offer high-performance upscaling, widescreen patches, and automatic controller mapping out of the box.                                                                                                                                                                                                                                                                                                                                 PlayStation 1/2/3 games look drastically better on Linux thanks to resolution upscaling. Furthermore, it is also a fact that you cannot play many fun games on Windows either, isn't it? - The Nintendo Switch has an extensive library of exclusive games. - PlayStation has an extensive library of exclusive games - Android has "mobile-exclusive" games, meaning they are exclusive to mobile devices (iOS and Android) and aren't available on PC or consoles. And finally, it is also the case that in the next five years there will be games that millions of people will say you absolutely must play and that they want to play this specific game that released a few days ago. However, the other side of this story is that currently, absolutely no one cares that they cannot play these upcoming games right now.
    • Flameshot 14.0 RC3 by Razvan Serea Flameshot is a free and open-source, cross-platform tool to take screenshots with many built-in features to save you time. Using Flameshot is as simple as launching, dragging the selection box to cover the area you want to capture, making annotations as needed in on-screen and saving the shot to your computer, all with a very simple and straightforward interface. Flameshot allows users to simply upload their screenshots directly to the cloud in order to easily share it with others. You can upload your image directly to Imgur with a single click and share the URL with others. In-app screenshot editing - You can choose to add an arrow mark, highlight text, blur a section (blur or pixelate an area), add a text, draw something, add a rectangular/circular shaped border, add an incrementing counter number, and add a solid color box with Flameshot's built-in editing tools. Command-line interface (CLI) - Flameshot has several commands you can use in the terminal without launching the GUI via a command line interface. The command line interface lets you script Flameshot and use it as the subject of key binds. Flameshot 14.0 RC3 changelog: Translations update from Hosted Weblate by @weblate in #4612 Translations update from Hosted Weblate by @weblate in #4619 Fix pin position on Windows for scaled screen by @ElTh0r0 in #4614 Cmake Analyzers by @ElTh0r0 in #4613 Translations update from Hosted Weblate by @weblate in #4632 fix(macos): prevent config tab content from rendering behind tab bar by @Mitnitsky in #4627 fix(macos): use CGRequestScreenCaptureAccess instead of grabWindow for permission request by @Mitnitsky in #4617 Fix KDE Plasma keyboard shortcut config file by @ElTh0r0 in #4637 fix(macos): fix clipboard copy failing from tray and GUI by @Mitnitsky in #4629 feature(macos): show dock icon when config window is open by @Mitnitsky in #4628 Option to disable tray icon on Windows by @ElTh0r0 in #4634 Translations update from Hosted Weblate by @weblate in #4642 fix(macos): make fullscreen capture overlay configurable by @Mitnitsky in #4622 Update GH actions using Node.js 24 by @ElTh0r0 in #4660 fix issue with screen selection in non interactive mode by @borgmanJeremy in #4667 Uniformize both spec files + ninja build openSUSE by @QuentiumYT in #4658 screengrabber: pass non-empty parent_window to xdg-desktop-portal by @artefaktor93 in #4664 Allow multiple flameshot GUI instances (fix for #3177) by @ElTh0r0 in #4680 Unify Linux ARM CI into Linux CI (also drop QEMU) by @theofficialgman in #4702 respect system proxy settings by @borgmanJeremy in #4674 Replace ifdef LINUX with UNIX to include BSD systems by @ElTh0r0 in #4700 Download: Flameshot 14.0 RC3 | 18.1 MB (Open Source) Download: Flameshot Portable | 53.0 MB Links: Flameshot Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • I found that stability back then was really down to the motherboard manufacturer. Back then i stuck with Microstar motherboards and VIA chipsets as they were ultra reliable. Most stuff was done with jumpers and left little room for user created problems 👍
  • Recent Achievements

    • One Month Later
      nothanks earned a badge
      One Month Later
    • One Month Later
      B2Proxy earned a badge
      One Month Later
    • One Year In
      MadMung0 earned a badge
      One Year In
    • Week One Done
      jefred earned a badge
      Week One Done
    • Apprentice
      JoeyNeo went up a rank
      Apprentice
  • Popular Contributors

    1. 1
      +primortal
      490
    2. 2
      PsYcHoKiLLa
      232
    3. 3
      Skyfrog
      78
    4. 4
      FloatingFatMan
      68
    5. 5
      Michael Scrip
      58
  • Tell a friend

    Love Neowin? Tell a friend!