GPO Tattooing? OLD GPOS still applying to the local workstations


Recommended Posts

Scenario:

NEW DC with Server 2003 replaces OLD server 2000

The workstations have been removed and added to the new domain however some of the OLD GPO settings are still set in the workstations. We have of course applied gpupdate /force on all the workstations and rebooted numerous times. However when we log in to the machine I am seeing the settings in the local workstation GPEDIT.MSC are the same in the local security policy even after being added to the new DC.

Any ideas how I can flush this old stuff from the workstations? Ive been reading on tattooing and ADMs and this is kinda a new problem.

This problem has stemed from the users home directories not syncing correctly. In fact only one user can sync their home directory when they log off.

Any ideas?

Thanks

As far as I remember, new policies will overwrite old ones only if they are configured. Any individual settings set to "not configured" will not be defaulted, so if they were set previously they will remain. You can delete the user profile on the local machines so that new user policies will be downloaded on next login. Workstation policies are a bit different, you may have to manually go through the policies and change "not configured" ones to the setting that is applicable to what you're trying to do.

Of course, I am pretty tired right now, so that information could be a red herring :p

that is true if you have not made a change to the new policy that will over write the old, the old will stay. dc policy is above local policy, so anything that the dc pushes out will over write anything in the local policy.

Well my DC policy is kinda loose at this point where as the local is pretty strict. I plan on locking it down more tight. Im wondering if its set to "NON CONFIGURED" on the DC and its set to configured on the local will it revert to the DC policy"

Thanks

technically no, if it is not configured on the dc the local policy will take over. but I would configure it on the dc using groups so that you can have different pc's/users using different policies if that is what you need.

it is really sloppy the way you are doing it. one pc may have a policy that the other doesn't, you don't have a way to tell what policy is on what pc easily, you have no way of undoing the policy based on logon, etc.

when doing gpos on a domain try to have one policy do one thing. for instance one policy to lock the taskbar and another to set classic start menu. doing it granular like this allows you to know easily what each policy is doing at a glance and to be able to add the groups that need to have this policy applied.

Edited by sc302

The DC policy will only overwrite a local policy if it has a setting other than 'Not Configured', otherwise there would be no point in having anything but a DC policy without worrying about the application sequence regarding policies.

What you might want to do is check the Resultant Set of Policy.

I also did a quick search online and found someone suggesting the following steps on techrepublic

Create a test gpo and link it to an existing OU for testing purposes(idealy affecting the problem workstation(s)). Put the changes you want in this test gpo. Now enable, enforce, link the gpo and check off block inheritance.

Next go to users and computers (on the server) and make a user(with the problem WS) in the above test OU a member of Administrators.

Run gpudate /force on server.

Go to the users' workstation(as above) and run gpupdate /force or reboot.

Vuala, you should see the changes.

Let us know how it worked out.

P.S. Once the gpo issue is resolved, remove the user from being member of Admin grp

technically no, if it is not configured on the dc the local policy will take over. but I would configure it on the dc using groups so that you can have different pc's/users using different policies if that is what you need.

it is really sloppy the way you are doing it. one pc may have a policy that the other doesn't, you don't have a way to tell what policy is on what pc easily, you have no way of undoing the policy based on logon, etc.

when doing gpos on a domain try to have one policy do one thing. for instance one policy to lock the taskbar and another to set classic start menu. doing it granular like this allows you to know easily what each policy is doing at a glance and to be able to add the groups that need to have this policy applied.

I have numerous polcies, I dont ever stick with just one policy. Ive written numerous policies for numerous tasks. The policies I am writting work on a Computer configuration rather than a user configuration. I will work on enforcing the new policies I have in place to re-write the old. It could be the previous policies were written on a user logon level rather that a computer level and we may have some issues there. I just need to look at it. Unfortunetly there is no way to see the old GPO written by the previous staff as the OLD DC has been removed.

I appreciate that help.

Thanks

Some policies are user only, some are computer only. I have been using groups to assign policies to computers or users, depending on what is needed, you can put computers in global and/or security groups as well as users. you can assign groups to group policies to help make life a little easier. you can't have folder redirection applied to computers, it is not a computer policy it is a user policy; you can't have windows update as a user policy as it is a computer policy. Everything in the User section gets applied to users, everything in the computer section gets applied to computers. I hope that makes sense. Quite possibly why your policies aren't getting assigned properly.

I know GP and I appreciate the resources. The local workstations are not accepting the new GP's over their old. Its referred to Tattoing. So I am troubleshooting why the old group policy is still tattooing or lingering around on the machines after they have been added to the new domain and forced to do group policy updates. Usually this doesnt happen so Im wondering whats lingering. I have a check list of things to look over to see why its not propagating over the network.

Thanks

Proph

What's the RSOP say? Have you checked in the event viewer for any errors relating to GP?

Well RSOP indicates all of my GPOS that I have written are being applied. However I am not seeing all the changes. I am still working on it. I need to to see if there is a GPO which affects Home Directory Syncing.

the only option that I can recall that would have anything to do with any type of syncing would be offline folders. and that has nothing to do with one particular mapped drive or another. also just to note, pst files do not get synced, so if your pst file is stored on your "home drive" then it will not work.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • My experience in the past with older Windows 11 builds was not great on unsupported machines but I recently used Rufus to put the latest build on a older 5th Gen Core Thinkpad T that we upgraded with a SATA SSD and 8GB of RAM four years ago when hardware was reasonable and it seemed pretty fast and solid. Customer is very happy with the performance and will probably get four more years out of that venerable laptop that he loves so much. Another customer just retired his Dell Studio laptop from 2009 running Windows 10. It got an SSD over 10 years ago and did everything he needed it to for 17 years but he also retired last year and is happy doing everything on his iPad now.
    • Apple's newest AirTag 2 gets first big discount by Taras Buria In late January 2026, Apple introduced its second-generation AirTag trackers, bringing a refresh to the old model that has been on the market for half a decade. Now, you can get these new trackers at an all-time low price, thanks to the first big discount that brought the price down by 17% on Amazon. While the second-generation AirTag looks identical to its predecessor, it packs meaningful upgrades inside. The second-gen ultrawideband chip works 50% farther than the original AirTag, allowing you to detect lost items in a wider range. In addition, the second-generation AirTag features an upgraded Bluetooth chip for extended range and a significantly louder speaker (up to 50%) so that you can hear it better when locating a lost item. Note that the second-gen AirTag only works with iPhones and iPads that run iOS/iPadOS 26 and newer, so you need a compatible device to use the tracker. Like the original AirTag, the AirTag 2 is available in two packs: one and four pieces. Both are now available at a notable discount on Amazon, and you can purchase them using the links below. Apple AirTag 2 tracker - $24 | 17% off on Amazon Apple AirTag 2 tracker (four-pack) - $89 | 10% off on Amazon Good to know This Amazon deal is U.S.- specific and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • I've been on Deezer for over a decade, but glad that Tidal joined them in fighting AI slop. Can't stand such takes as Spotify's: "Spotify's CEO recently pushed back against listeners who call AI music "slop," urging people to stop using the term and instead embrace the creative potential of AI music."
    • “Could” … in the IS the healthcare is run by insurance companies that make indecent profits denying basic treatments to people that are paying money for nothing. Besides, where are all the Trump epigones who were stating that the tariffs were going to paid by foreign companies and not the US citizens? …
    • Microsoft Teams gets smarter at spotting sneaky meeting bots by Usama Jawad Microsoft Teams is set to receive a couple of new features soon, including a dedicated Recap app and a rather controversial location tracking functionality. The Redmond tech giant has also explained how it has made online communication and collaboration a lot more performant this year. Now, the company has detailed more secure bot admission mechanisms, as first reported by us in March 2026, and now available in Teams. As the use of AI has expanded across enterprise environments, Microsoft has begun allowing users to integrate bots into their meetings for various tasks, such as note-taking. While this has a tangible productivity benefit for users, Microsoft has highlighted how misconfiguration has allowed bots to join meetings that they shouldn't. This has created security and privacy risks, which Microsoft is now combating using a new Teams admin policy that allows organizers to control how external bots access meetings. Admins can leverage a policy called Manage external bots and their access to meetings. The default configuration is "When detected, require approval before joining", which places detected bots in a lobby before they are explicitly admitted into the meeting. The other option disables the experience. Microsoft has also requested admins to only allow organizers and co-organizers to manage access to a meeting, so that other people don't randomly allow bots into meetings. Teams will now be able to leverage infrastructure signals to intelligently detect and distinguish between bots and humans. Microsoft will soon also trial a registration experience for independent software vendors (ISVs) to build a system that registers a bot with Microsoft, so it is marked as a "known" bot. Teams will also categorize bots as trusted and suspected threats so that organizers can quickly identify which bots they want to allow into a meeting. Additional safeguards to block accidental admission of a bot into a meeting include: No one-click Admit option for identified bots Confirmation prompts when admitting participants that include bots Warnings when organizers choose Admit all, and bots are included Microsoft has begun rolling out this experience, and it will be retiring the current CAPTCHA verification implementation. In the future, the company plans to roll out new capabilities like allow-lists, organization-wide policies, admin reports, audit logs, and more granular controls.
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      538
    2. 2
      +Edouard
      266
    3. 3
      PsYcHoKiLLa
      151
    4. 4
      Steven P.
      98
    5. 5
      macoman
      66
  • Tell a friend

    Love Neowin? Tell a friend!