GPOS and removing stale settings via GPO


Recommended Posts

Current Situation. New DC replacing old DC which is GONE no access to it what so ever.

So users have an old GPO setting for Folder Redirection. So the paths are now different on the new server. So create a new GPO it should take presidence and life should be good right? As long as your setting is not set to "not" configured it should be fine. Well when these users log off their old GPO setting with folder redirection and File syncing is still in place. So they get an error that states path cannot be found.

Besides going to each machine what way do you guys think I can force the machines to inherit policies from the new machine and not use the old.

One other google resource stated that I should just simply create a GPO that disables folder redirection and syncing have all users update then go back after this happens and force a new GPO that enables the correct path and it should remove the old tattooing.

Second situation is this weird NumLock issue.

Some Dell machines have NUMlock Enabled in the bios but when they get to windows no numlock when they go to log in. After they log in I have created a script that enables numlock but it doesnt apply till after they login. Since they use strong alpha numeric passwords they want the NUMlock enabled before they login.

Any ideas?

you are going to have to play with gpupdate on the pc's and use your rsop to be able to verify gpo changes.

to use gpupdate:

start

run

cmd

gpupdate

to force gpupdate:

start

run

cmd

gpupdate /force

to use rsop:

start

run

mmc

file

add/remove snap ins

add

resultant set of policy

right click resultant set of policy

generate rsop data

you are going to have to play with gpupdate on the pc's and use your rsop to be able to verify gpo changes.

to use gpupdate:

start

run

cmd

gpupdate

to force gpupdate:

start

run

cmd

gpupdate /force

to use rsop:

start

run

mmc

file

add/remove snap ins

add

resultant set of policy

right click resultant set of policy

generate rsop data

come on SC302 I got all these commands bud.. This is actually a known issue with folder redirect. The old ones stay stale. Im trying to find a way to remove it. The whole tattooing issue..

I ll see if I can come up with a work around.

do the new gpo's work on new computers? I apologize for that not being helpful, but if you are applying a new gpo it should show up in there. Esp if you are micromanaging your gpo's and not using 1 or 2 gpo's for everything (like putting everything in your default domain gpo).

My gpo structure is broken down like this:

default domain controller gpo

disable microsoft firewall gpo

redirect users folder gpo

push adobe acrobat gpo

push antivirus gpo

lock taskbar gpo

user logon script gpo

enable logoff in start menu gpo

You get the idea with that. I don't use 1 gpo to do all of that, it is broken up. If I make a change to the folder redirect I can delete the gpo, and create a new one and verify that the pc's then take the new one. I do not have the issue you do with this.

Edit: Also remember gpo's get applied top down when using in conjunction with ou's.

Edited by sc302
Why not? And then why not just name the new one the same name as the old?

Joel, Lots of Red tape. We had no access to the old dc. It was removed when we walked in and due to the other company managing the previous DC they wouldnt allow us to access it.. Bunch of BS.

SC302

Im with you, I always split up the GPO's, I usually have at least 10 on each server. Its just where the machines have some retained info in the reg poiting to an old method. The whole "tattooing" is what I keep coming across in Google.

The recent trouble I just had with folder redirection is that the machines want the old folder as a reference point to move FROM. You could always push the registry entries back to the defaults.

Back to my original question; why not just name the new machine and domain the same as the old? You don't need the old server to accomplish that. I can think of a host of GUID issues you may get, but it doesn't hurt to try as a step of solving your redirection problem.

  • 3 months later...
Wont the old ones be removed if you just goto the machine, make a local admin, remove its connection to AD by switching it to workgroup mode. Then just rejoin the new domain?

that is a lot of work (in comparison to other methods), and really not the best way to go around it. You are better off deleting the pointers in the registry.

HKLM->Software->Policies

HKLM->Software->Microsoft->Windows->CurrentVersion->Policies

HKCU->Software->Polcies

HKCU->Software->Microsoft->Windows->CurrentVersion->Policies

and if any exist delete the policies in here

%windir%\System32\GroupPolicy

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Just the price of doing business. The scamble to pull as much from the web as possible is happening, and it's happening before a case like this changes how or what is legal do to with AI in terms of data harvesting. But even then as we've seen with the likes of Google who ignore cookie requests and just accept the fact they'll get fined, it's built into their business price model now. AI is here, its not going away. Their reward if any from the court case would be best suited to trying to incorprate AI or licence their end points as authentic human verified content. The problem is, as we've seen these same news papers are using AI themselves.
    • Which finger's fingernail are we talking about? I can see how not having this info can lead to massive differences in interpretation.
    • This Chinese company is reportedly developing a feature Apple and Samsung can only dream of by Hamid Ganji While companies like Apple and Samsung have been relatively conservative with their devices’ battery capacities in recent years, Chinese manufacturers have taken the competition to the next level by introducing significantly larger batteries. However, the latest report from China suggests that a local company may already be developing a smartphone with a whopping 14,000mAh battery. Chinese leaker Digital Chat Station claimed on Weibo that a smartphone maker is developing a device with a 14,000mAh battery. If true, it would be the largest battery ever used in a smartphone and could, in theory, provide up to a week of battery life on a single charge. The leaker did not reveal the name of the company behind the device, but there are some clues. This week, HONOR unveiled the X80 Pro Max in China with an 11,000mAh battery and 90W wired charging support. The company also launched the Honor Win in January, which packs a 10,000mAh battery. HONOR, a former subsidiary of Huawei, has a proven track record of developing smartphones with unusually large batteries. However, other Chinese brands, including Xiaomi, have also launched devices such as the Xiaomi 17 Pro Max with 7,500mAh batteries. Though Chinese users on Weibo also believe the company behind the new battery is HONOR. Interestingly, Digital Chat Station said the device with the 14,000mAh battery weighs around 220 grams, making it lighter than the Apple iPhone 17 Pro Max (233 grams) and slightly heavier than the Samsung Galaxy S26 Ultra (214 grams). The iPhone 17 Pro Max currently packs a 5,088mAh battery in eSIM-only versions, while the Galaxy S26 Ultra features a 5,000mAh battery. Neither device is expected to see a dramatic increase in battery capacity in its next-generation successor. So when it comes to battery comparison, Chinese brands are unbeaten. HONOR smartphones are currently available in the EU, but the Chinese brand has no official presence in the United States due to restrictions imposed by the U.S. government.
  • Recent Achievements

    • First Post
      kinowa earned a badge
      First Post
    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
    • Dedicated
      Scoobystu earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      461
    2. 2
      +Edouard
      172
    3. 3
      PsYcHoKiLLa
      137
    4. 4
      Michael Scrip
      78
    5. 5
      Xenon
      77
  • Tell a friend

    Love Neowin? Tell a friend!