PC Review


Reply
Thread Tools Rate Thread

2 machines under GP no longer lock down/screensaver

 
 
Taggert
Guest
Posts: n/a
 
      21st Sep 2006
I am getting ready for some audits, so I am verifying all my security
settings. FOr almost a year, we have had group policy settings that force
all machines inactive for 15 minutes to lock down, fire up the screensaver,
and force user to ctrl-alt-del and sign back in when they return.

Now I find 2 machines, 1 the CEO of course, that do not ever time out or
lock down. Nothing of any interest in the event logs, no errors of any
sort, the login.scr file is still available on both machines.

Any thought on finding or resolving the problem? I have logged off, logged
on, run gpupdate with no errors, and I'm just not finding a resolution.


Anyone?

Thanks


 
Reply With Quote
 
 
 
 
Vincent Xu [MSFT]
Guest
Posts: n/a
 
      22nd Sep 2006
Hi,

My understanding of your issue is: Group Policy are not applied to two
fixed computers.

1. Create a new OU for the two user (because I found the policy is set for
users. Correct me if I'm wrong)
2. Create a new GPO for this OU and set the lock down settings & screen
saver settings.
3. Reboot the two computers.
4. Run the following command on the client computer and let me know the GPO
name you use.

gpresult /z >c:\gp.txt

Note: Please send the gp.txt file to v-(E-Mail Removed).

Thanks.

Best regards,

Vincent Xu
Microsoft Online Partner Support

======================================================

Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================



--------------------
>>From: "Taggert" <(E-Mail Removed)>
>>Subject: 2 machines under GP no longer lock down/screensaver
>>Date: Thu, 21 Sep 2006 11:42:51 -0400
>>Lines: 18
>>X-Priority: 3
>>X-MSMail-Priority: Normal
>>X-Newsreader: Microsoft Outlook Express 6.00.2900.2869
>>X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2962
>>X-RFC2646: Format=Flowed; Original
>>Message-ID: <(E-Mail Removed)>
>>Newsgroups: microsoft.public.win2000.group_policy
>>NNTP-Posting-Host: adsl-070-147-109-164.sip.gnv.bellsouth.net

70.147.109.164
>>Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP03.phx.gbl
>>Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.win2000.group_policy:40932
>>X-Tomcat-NG: microsoft.public.win2000.group_policy
>>
>>I am getting ready for some audits, so I am verifying all my security
>>settings. FOr almost a year, we have had group policy settings that

force
>>all machines inactive for 15 minutes to lock down, fire up the

screensaver,
>>and force user to ctrl-alt-del and sign back in when they return.
>>
>>Now I find 2 machines, 1 the CEO of course, that do not ever time out or
>>lock down. Nothing of any interest in the event logs, no errors of any
>>sort, the login.scr file is still available on both machines.
>>
>>Any thought on finding or resolving the problem? I have logged off,

logged
>>on, run gpupdate with no errors, and I'm just not finding a resolution.
>>
>>
>>Anyone?
>>
>>Thanks
>>
>>
>>


 
Reply With Quote
 
Vincent Xu [MSFT]
Guest
Posts: n/a
 
      27th Sep 2006
Hi ,

something found from your log:

1. Only the GPO Default Domain Policy is applied. This GPO is applied at
domain level.

2. Applied Group Policy Objects
-----------------------------
Default Domain Policy
MAIN

the GPO MAIN is not exists even it should.

In the Default Domain Policy, there are 7 GP applied. Please let me know
which GPs are applied.

I'm not sure why MAIN is not applied, please also let me know which GPs in
MAIN are applied.

Thanks.


Best regards,

Vincent Xu
Microsoft Online Partner Support

======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================



--------------------
>>X-Tomcat-ID: 44160988
>>References: <(E-Mail Removed)>
>>MIME-Version: 1.0
>>Content-Type: text/plain
>>Content-Transfer-Encoding: 7bit
>>From: v-(E-Mail Removed) (Vincent Xu [MSFT])
>>Organization: Microsoft
>>Date: Fri, 22 Sep 2006 02:19:37 GMT
>>Subject: RE: 2 machines under GP no longer lock down/screensaver
>>X-Tomcat-NG: microsoft.public.win2000.group_policy
>>Message-ID: <(E-Mail Removed)>
>>Newsgroups: microsoft.public.win2000.group_policy
>>Lines: 65
>>Path: TK2MSFTNGXA01.phx.gbl
>>Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.win2000.group_policy:40933
>>NNTP-Posting-Host: TOMCATIMPORT1 10.201.218.122
>>
>>Hi,
>>
>>My understanding of your issue is: Group Policy are not applied to two
>>fixed computers.
>>
>>1. Create a new OU for the two user (because I found the policy is set

for
>>users. Correct me if I'm wrong)
>>2. Create a new GPO for this OU and set the lock down settings & screen
>>saver settings.
>>3. Reboot the two computers.
>>4. Run the following command on the client computer and let me know the

GPO
>>name you use.
>>
>>gpresult /z >c:\gp.txt
>>
>>Note: Please send the gp.txt file to v-(E-Mail Removed).
>>
>>Thanks.
>>
>>Best regards,
>>
>>Vincent Xu
>>Microsoft Online Partner Support
>>
>>======================================================
>>
>>Get Secure! - www.microsoft.com/security
>>======================================================
>>When responding to posts, please "Reply to Group" via your newsreader so
>>that others
>>may learn and benefit from this issue.
>>======================================================
>>This posting is provided "AS IS" with no warranties,and confers no

rights.
>>======================================================
>>
>>
>>
>>--------------------
>>>>From: "Taggert" <(E-Mail Removed)>
>>>>Subject: 2 machines under GP no longer lock down/screensaver
>>>>Date: Thu, 21 Sep 2006 11:42:51 -0400
>>>>Lines: 18
>>>>X-Priority: 3
>>>>X-MSMail-Priority: Normal
>>>>X-Newsreader: Microsoft Outlook Express 6.00.2900.2869
>>>>X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2962
>>>>X-RFC2646: Format=Flowed; Original
>>>>Message-ID: <(E-Mail Removed)>
>>>>Newsgroups: microsoft.public.win2000.group_policy
>>>>NNTP-Posting-Host: adsl-070-147-109-164.sip.gnv.bellsouth.net

>>70.147.109.164
>>>>Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP03.phx.gbl
>>>>Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.win2000.group_policy:40932
>>>>X-Tomcat-NG: microsoft.public.win2000.group_policy
>>>>
>>>>I am getting ready for some audits, so I am verifying all my security
>>>>settings. FOr almost a year, we have had group policy settings that

>>force
>>>>all machines inactive for 15 minutes to lock down, fire up the

>>screensaver,
>>>>and force user to ctrl-alt-del and sign back in when they return.
>>>>
>>>>Now I find 2 machines, 1 the CEO of course, that do not ever time out

or
>>>>lock down. Nothing of any interest in the event logs, no errors of any
>>>>sort, the login.scr file is still available on both machines.
>>>>
>>>>Any thought on finding or resolving the problem? I have logged off,

>>logged
>>>>on, run gpupdate with no errors, and I'm just not finding a resolution.
>>>>
>>>>
>>>>Anyone?
>>>>
>>>>Thanks
>>>>
>>>>
>>>>

>>
>>


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
XP Screensaver lock =?Utf-8?B?Qm9iQw==?= Windows XP Security 0 9th Aug 2005 08:24 PM
Screensaver will not lock =?Utf-8?B?Q2hyaXM=?= Microsoft Windows 2000 1 13th May 2005 12:10 AM
Lock down certain machines =?Utf-8?B?R2lubw==?= Microsoft Windows 2000 Group Policy 1 19th Jan 2005 12:33 AM
Win XP no longer able to access LAN with win 98SE machines =?Utf-8?B?VG9tb3Jyb3dzX1RlY2hub2xvZ3k=?= Windows XP Networking 10 20th Sep 2004 04:52 PM
XP Pro machines no longer see each other =?Utf-8?B?U3RldmU=?= Windows XP Networking 0 29th Jun 2004 10:10 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 12:42 PM.