GPOS and removing stale settings via GPO


Recommended Posts

Current Situation. New DC replacing old DC which is GONE no access to it what so ever.

So users have an old GPO setting for Folder Redirection. So the paths are now different on the new server. So create a new GPO it should take presidence and life should be good right? As long as your setting is not set to "not" configured it should be fine. Well when these users log off their old GPO setting with folder redirection and File syncing is still in place. So they get an error that states path cannot be found.

Besides going to each machine what way do you guys think I can force the machines to inherit policies from the new machine and not use the old.

One other google resource stated that I should just simply create a GPO that disables folder redirection and syncing have all users update then go back after this happens and force a new GPO that enables the correct path and it should remove the old tattooing.

Second situation is this weird NumLock issue.

Some Dell machines have NUMlock Enabled in the bios but when they get to windows no numlock when they go to log in. After they log in I have created a script that enables numlock but it doesnt apply till after they login. Since they use strong alpha numeric passwords they want the NUMlock enabled before they login.

Any ideas?

you are going to have to play with gpupdate on the pc's and use your rsop to be able to verify gpo changes.

to use gpupdate:

start

run

cmd

gpupdate

to force gpupdate:

start

run

cmd

gpupdate /force

to use rsop:

start

run

mmc

file

add/remove snap ins

add

resultant set of policy

right click resultant set of policy

generate rsop data

you are going to have to play with gpupdate on the pc's and use your rsop to be able to verify gpo changes.

to use gpupdate:

start

run

cmd

gpupdate

to force gpupdate:

start

run

cmd

gpupdate /force

to use rsop:

start

run

mmc

file

add/remove snap ins

add

resultant set of policy

right click resultant set of policy

generate rsop data

come on SC302 I got all these commands bud.. This is actually a known issue with folder redirect. The old ones stay stale. Im trying to find a way to remove it. The whole tattooing issue..

I ll see if I can come up with a work around.

do the new gpo's work on new computers? I apologize for that not being helpful, but if you are applying a new gpo it should show up in there. Esp if you are micromanaging your gpo's and not using 1 or 2 gpo's for everything (like putting everything in your default domain gpo).

My gpo structure is broken down like this:

default domain controller gpo

disable microsoft firewall gpo

redirect users folder gpo

push adobe acrobat gpo

push antivirus gpo

lock taskbar gpo

user logon script gpo

enable logoff in start menu gpo

You get the idea with that. I don't use 1 gpo to do all of that, it is broken up. If I make a change to the folder redirect I can delete the gpo, and create a new one and verify that the pc's then take the new one. I do not have the issue you do with this.

Edit: Also remember gpo's get applied top down when using in conjunction with ou's.

Edited by sc302
Why not? And then why not just name the new one the same name as the old?

Joel, Lots of Red tape. We had no access to the old dc. It was removed when we walked in and due to the other company managing the previous DC they wouldnt allow us to access it.. Bunch of BS.

SC302

Im with you, I always split up the GPO's, I usually have at least 10 on each server. Its just where the machines have some retained info in the reg poiting to an old method. The whole "tattooing" is what I keep coming across in Google.

The recent trouble I just had with folder redirection is that the machines want the old folder as a reference point to move FROM. You could always push the registry entries back to the defaults.

Back to my original question; why not just name the new machine and domain the same as the old? You don't need the old server to accomplish that. I can think of a host of GUID issues you may get, but it doesn't hurt to try as a step of solving your redirection problem.

  • 3 months later...
Wont the old ones be removed if you just goto the machine, make a local admin, remove its connection to AD by switching it to workgroup mode. Then just rejoin the new domain?

that is a lot of work (in comparison to other methods), and really not the best way to go around it. You are better off deleting the pointers in the registry.

HKLM->Software->Policies

HKLM->Software->Microsoft->Windows->CurrentVersion->Policies

HKCU->Software->Polcies

HKCU->Software->Microsoft->Windows->CurrentVersion->Policies

and if any exist delete the policies in here

%windir%\System32\GroupPolicy

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Not sure there is good value here.... the only real choice is 2GB w/ Controller since 1. 512GB would disappear fast based on today's PC game installs 2. Controller is back ordered until 2027. The appeal of playing PC games on TV (along with PS5) sounds interesting, but I am not too lazy to fire up the huge PC either. Not really sure this would be "worth" it.
    • This might work, but the boot menu F12 only shows hdd and dvd+/- and Niks In the bios all usb are enabled. the usb stick is in place and in the boot menu it does not show up in the bios boot order.
    • Because we were never offered a UFC game to review it in the past. Sometimes it's not a conspiracy, the reviewer does not even live in the U.S. and didn't ask for it.
    • Apple releases iOS 27 Beta 2 for developers and power users by Aditya Tiwari It's been a couple of weeks since Apple previewed the iOS 27 update during the WWDC official keynote. The upcoming iOS version will bring even more refinements to the Liquid Glass design language, an upgraded Siri AI assistant, and several new Apple Intelligence features. Interestingly, the latest WWDC keynote was different than previous years. Apple has released the iOS 27 beta 2 (build 24A5370h) for developers who want to test the new features being baked for the iPhone and optimize their apps. If you're interested in downloading the latest beta, go to Settings > General > Software Update > beta Updates, then choose iOS 27 Developer Beta. You can download the latest iOS 27 beta on more than 30 supported iPhones. Make sure you know what you are doing since developer betas can be unstable and unexpected at times. If you want to be on the safer side, you can wait for the public beta, which will arrive next month. It's been a while since Apple discontinued its AirPort router lineup. Now, the company said in the iOS 27 beta 2 release notes that the AirPort Utility is deprecated and won't be available for new downloads from the App Store. Apple added that if you previously downloaded the app, you can re-download it. However, the functionality isn't guaranteed when using the AirPort Utility on iOS 27 or later. Speaking of known issues, Apple said that the Portrait mode blur effect might render incorrectly for photos; you may be unable to stop an alarm from the lock screen without unlocking your iPhone; the "Add a Control" button in Control Center edit mode might appear small or clipped. There are several new features in iOS 27 beta 2 as well. It comes with Neural Engine improvements for Apple Intelligence, including better performance when loading large models over 1GB. HomeKit Secure Video recordings are processed on-device and through Private Cloud Compute for video descriptions and search, when Apple Intelligence is enabled in the Home app. That said, you can also download the second betas of macOS 27 Golden Gate, iPadOS 27, watchOS 27, and other Apple operating systems.
  • Recent Achievements

    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      500
    2. 2
      +Edouard
      203
    3. 3
      PsYcHoKiLLa
      98
    4. 4
      Michael Scrip
      81
    5. 5
      neufuse
      67
  • Tell a friend

    Love Neowin? Tell a friend!