Local group policy filtering problem

G

Guest

I don't quite understand what's hapenning with Local Group Policy

I have a domain GPO linked at the top of the domain. I have a number of OU's beneath it. If I go into Computer Configuration/Windows Settings/Local Policies/Security Options under the domain GPO and change a setting it is not reflected at the workstation. Why and where is it filtered out?

Gpresults are

Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.
Copyright (C) Microsoft Corp. 1981-200

Created On 5/19/2004 at 1:27:45 P


RSOP results for HQ\testuser on TESTUSER-LT : Logging Mod
------------------------------------------------------------

OS Type: Microsoft Windows XP Professiona
OS Configuration: Member Workstatio
OS Version: 5.1.260
Domain Name: H
Domain Type: Windows 200
Site Name: Default-First-Site-Nam
Roaming Profile:
Local Profile: C:\Documents and Settings\testuse
Connected over a slow link?: N

COMPUTER SETTING
-----------------
CN=TESTUSER-LT,OU=Account Services,DC=hq,DC=MY-COMPANY,DC=co
Last time Group Policy was applied: 5/19/2004 at 12:42:07 P
Group Policy was applied from: wulfgar.hq.mycompany.co
Group Policy slow link threshold: 500 kbp

Applied Group Policy Object
----------------------------
N/

The following GPOs were not applied because they were filtered ou
------------------------------------------------------------------
Local Group Polic
Filtering: Not Applied (Empty

The computer is a part of the following security groups
-------------------------------------------------------
BUILTIN\Administrator
Everyon
BUILTIN\User
TESTUSER-LT
Domain Computer
NT AUTHORITY\NETWOR
NT AUTHORITY\Authenticated User

Resultant Set Of Policies for Computer
---------------------------------------

Software Installation
---------------------
N/

Startup Script
--------------
N/

Shutdown Script
---------------
N/

Account Policie
---------------
N/

Audit Polic
-----------
N/

User Right
----------
N/

Security Option
---------------
N/

Event Log Setting
-----------------
N/

Restricted Group
----------------
N/

System Service
--------------
N/

Registry Setting
----------------
N/

File System Setting
 
D

Derek Melber [MVP]

Very possible the ACL of the GPO is not applying this to the computer. Was
the ACL changed?

--
Derek Melber
BrainCore.Net
(e-mail address removed)
Bill said:
I don't quite understand what's hapenning with Local Group Policy.

I have a domain GPO linked at the top of the domain. I have a number of
OU's beneath it. If I go into Computer Configuration/Windows Settings/Local
Policies/Security Options under the domain GPO and change a setting it is
not reflected at the workstation. Why and where is it filtered out?
 
G

Guest

Here's a little more data on the same user/workstation

Denied GPO
Name Link Location Reason Denied
Local Group Policy Local Empty
{31B2F340-016D-11D2-945F-00C04FB984F9} hq.mycompany.com Inaccessible
 
D

Derek Melber [MVP]

I am 99% sure your ACL is wrong.

Make sure that the Authenticated Users group has both Read and Apply Group
Policy permission allowed. There should be NO denied entries on the GPO ACL.

--
Derek Melber
BrainCore.Net
(e-mail address removed)
Bill said:
Here's a little more data on the same user/workstation.

Denied GPOs
Name Link
Location Reason Denied
 
G

Guest

That appears to have been it - although I can't remember ever removing those privileges from the Auth User account.

Thanks.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top