Group Policy Shortcuts

I am trying to use the Shortcuts extension in the Computer Configurations section to create some links, but any File System Object shortcuts fail with:
The computer '<Name> preference item in the '<Policy> {GUID}' Group Policy object did not apply because it failed with error code '0x80070002 The system cannot find the file specified.' This error was suppressed.
For troubleshooting, I tried the following:
Action: Update
Name: Explorer
Type: File System Object
Location: All Users Desktop
Target: %SystemRoot%\Explorer.exe
Args: <Blank>
Start In: %SystemDrive%
Shortcut: None
Run: Normal Window
Comment: <Blank>
Icon File: <Blank>
Icon Index: <Blank>
None of the "Common" items are configured, so I am not sure what file it is failing to find.  Shortcuts fail to be processed on all Windows Servers 2008 RTM systems that the GPO applies to.

Hi,
No, it should not be an expected behavior that system variables are not set by default. I have verified this on cleanly installed Windows Server 2008 computers.
So, could you let me know the following?
1.    Is it a cleanly installed Windows Server 2008 system, or a
2.    Did you check system variables immediately after the installation?
3.    By the way, the echo command may not be accurate. So, do the shortcut policy settings (with "%WINDOWSDIR% and %SYSTEMDIR%" variables) still work there on your computers?

Similar Messages

  • Group Policy Shortcut Fails to Get Created

    I get the following error in the Event Log.
    Log Name:      Application
    Source:        Group Policy Shortcuts
    Date:          2/28/2014 4:55:55 PM
    Event ID:      4098
    Task Category: (2)
    Level:         Warning
    Keywords:      Classic
    User:          SYSTEM
    Description:
    The user 'Receiver' preference item in the 'Startup Items {48A48B27-F3CE-464F-AE8F-E303263707B9}' Group Policy object did not apply because it failed with error code '0x80070002 The system cannot find the file specified.' This error was suppressed.
    I was trying to put "C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfService.exe" into the startup folder for members of a specific group. That file exists, it's there, I've put the short cut to it manually into Startup and it works. This
    makes no rational sense at all. The file is most certainly there, why doesn't it see the file? 
    All other shortcuts from GPP work fine.  Here are the properties below:
    Target type
    File system object
    Shortcut path
    %StartUpDir%\Citrix Receiver
    Target path
    "C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfService.exe"
    Start in
    "C:\Program Files (x86)\Citrix\SelfServicePlugin\"
    Shortcut key
    None
    Run
    Normal window
    Arguments --showAppPicker
    Options
    Stop processing items on this extension if an error occurs on this item
    No
    Run in logged-on user's security context (user policy option)
    Yes
    Remove this item when it is no longer applied
    Yes

    Hi,
    Based on my knowledge, this event is most likely related to permissions. We need to make sure that users can access the shortcut file. 
    Besides, which startup folder do we use?
    As stated in the following thread by Darien, Windows has two Startup folders:
    Windows has two Startup folders.
    One located in
    c:\users\xxxx\appdata\roaming\microsoft\windows\start menu\programs\startup.  This one is owned and controlled by the interactive user; therefore, he or she can write to this folder.
    The other one is located at
    c:\programdata\microsoft\windows\start menu\programs\startup.  This folder is a system folder in which interactive users must provided elevated credentials.
    Startup Folder
    http://social.technet.microsoft.com/Forums/windows/en-US/76520783-6667-4f38-8ab9-cdefab3bd4aa/startup-folder?forum=w7itproui
    Hope it helps.
    Best regards,
    Frank Shen

  • The Group Policy Client Side Extension Group Policy Shortcuts may have caused th e Group Policy Service to terminate unexpectedly.

    Hi all,
    Having an issue with the shortcuts Group Policy extension applying to our Windows 7 machines. It was working until last Wednesday and since then users get a Group Policy Client service error when logging in.
    We have narrowed it down to the shortcuts extension, if the extension is disabled then a user can log in, if enabled and empty then the following error comes up. With all the investigation we have done so far it seems as though something on the client is
    making this happen.
    We have –
    Copied the original policy
    Exported and imported the policy
    Deleted all the shortcuts
    Deleted all the shortcuts and created a brand new shortcut
    And the same thing happens. Only if you right click on the Shortcut Extension and select disable then the user can log in
    When running Gpupdate /force we get the following error 
    The Group Policy Client Side Extension Group Policy Shortcuts may have caused the Group Policy Service to terminate unexpectedly. To prevent further failures inthe
    Group Policy Service, this extension has been temporarily disabled until after the next system restart. Group Policy settings managed by this extension may no
    longer be enforced until the system is restarted. The vendor of this extension should be contacted if this issue recurs.
    The Group Policy Client Side Extension Group Policy Internet Settings may have caused the Group Polcy Service to terminate unexpectedly. To prevent further failures
    in the Group Policy Service, this extension has been temporarily disabled until after the next system restart. Group Policy settings managed by this extension
    may no longer be enforced until the system is restarted. The vendor of this extension should be contacted if this issue recurs.
    Has anyone come across this before?
    Thanks

    Hi Dejul,
    How is the issue going? Does this issue happen to all Windows 7 clients? I am not sure this can be helpful but we can give it a try to install the following hotfix.
    Some Group Policy preferences are not applied successfully on computers that are running Windows Vista, Windows Server 2008, Windows 7 or Windows Server 2008 R2
    http://support.microsoft.com/kb/979731
    Besides, please make sure that our clients are patched or updated to the latest.
    An enterprise hotfix rollup is available for Windows 7 SP1 and Windows Server 2008 R2 SP1
    http://support.microsoft.com/kb/2775511
    TechNet Subscriber Support
    If you are TechNet Subscription user and have any feedback on our support quality, please send your feedback here.
    Best regards,
    Frank Shen

  • Group Policy Shortcuts Fail: The system cannot find the path specified.

    The executable I'm pointing to is under C:\Foldername\file.exe
    I know it's there, I tested it, I pasted the very same path into the run dialog, it works. The path is correct, so why can't group policy find it?
    I even tried putting the exe in the root of C:\ and pointing the shortcut there, it can't even see it there. Is it blind? I can see it. I'm looking right at it.

    I fixed it myself. Turns out Microsoft's error messages are obnoxiously non-helpful. The error was referring to the icon path not the target file path.  I had to select programs from the drop down list and then set the path.
    It would help if Microsoft would document this a lot better, and perhaps enhance their event log errors so that they don't send people on confusing wild goose chases that drive people insane.

  • Group Policy Shortcut Error

    Hi All
    I am trying to create a shortcut via GP to point to our print server, so people can connect to optional printers. we have the following settings set in the policy.
    Action Create
    Type: File System Object
    Path: Desktop
    Target: "\\server"
    Icon Path: C:\Windows\System32\imageres.dll
    Icon index: 48
    Shortcut Key: none
    Run: normal window
    But this is not working and is throwing the following error in a gpresult: Result: Failure (Error Code: 0x80070002)
    Does anyone have any ideas why this is happening?
    Thanks,
    Richard

    Please edit the policy as a "Shell Object". 
    http://technet.microsoft.com/en-us/library/cc753580.aspx
    Alper YAZGAN *

  • Group Policy Preferences Shortcut issues ( event ID 1085 )

    I am hoping someone will be able to help me with a problem that is causing our users a headache
    We have a Windows 2008 SP2 terminal server farm ( 1 gateway, 2 Terminal servers TS1 and TS2 ), we also use Group Policy Preferences to deliver app shortcuts to different AD user groups.
    TS1 and TS2 were built from the same image.  On TS1 users logon and get all the icons they are entitled to, on TS2 it is random to whether they get their shortcuts or not.   
    Both TS are rebooted daily and I have scripted removing any local profiles incase it was something left behind.
    Checking the event Logs on TS2 I see several errors that appear to relate to Group Policy and correspond to when users have connected in.
    any help with this issue would be appreciated.
    Here is the information from the System log:
    Log Name:      System
    Source:        Microsoft-Windows-GroupPolicy
    Date:          05/12/2014 15:32:26
    Event ID:      1085
    Task Category: None
    Level:         Warning
    Keywords:      
    User:          Username
    Computer:      TerminalServer
    Description:
    Windows failed to apply the Group Policy Shortcuts settings. Group Policy Shortcuts settings might have its own log file. Please click on the "More information" link.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-GroupPolicy" Guid="{aea1b4fa-97d1-45f2-a64c-4d69fffd92c9}" />
     <EventID>1085</EventID>
        <Version>0</Version>
        <Level>3</Level>
        <Task>0</Task>
        <Opcode>1</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2014-12-05T15:32:26.450Z" />
        <EventRecordID>478778</EventRecordID>
        <Correlation ActivityID="{CCB45268-E6F8-4127-97C8-A8544829F2DE}" />
        <Execution ProcessID="344" ThreadID="11212" />
        <Channel>System</Channel>
        <Computer>TerminalServer</Computer>
        <Security UserID="S-1-5-21" />
      </System>
      <EventData>
        <Data Name="SupportInfo1">1</Data>
        <Data Name="SupportInfo2">3892</Data>
        <Data Name="ProcessingMode">1</Data>
        <Data Name="ProcessingTimeInMilliseconds">6047</Data>
        <Data Name="ErrorCode">2147942413</Data>
        <Data Name="ErrorDescription">The data is invalid. </Data>
        <Data Name="DCName”>\\OurDomain</Data>
        <Data Name="ExtensionName">Group Policy Shortcuts</Data>
        <Data Name="ExtensionId">{C418DD9D-0D14-4efb-8FBF-CFE535C8FAC7}</Data>
      </EventData>
    </Event>

    >      <Data Name="ErrorDescription">The data is invalid. </Data>
    Delete the history XML.
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • Place Outlook shortcut on All Users' desktops via Group policy

    Hello I am looking for a way to deploy a desktop shortcut to all of our Windows 7 machines for Microsoft Outlook. The difficulty I am running into is that we have x86 and x64 versions of Microsoft Office installed on the machines, and no easy way to identify
    which is which.
    Does anyone have a suggestion of how to create a single Group Policy that could place an Outlook shortcut on the public desktop which would work regardless of what version is installed?

    If all of Office suite (e.g. Office 15) installed in default path, please deploy the following script and run it locally:
    Set objShell = WScript.CreateObject("WScript.Shell")
    strDesktopFolder = objShell.SpecialFolders("Desktop")
    Set objShortCut = objShell.CreateShortcut(strDesktopFolder & _
    "\Outlook.lnk")
    objShortCut.TargetPath = chr(34) & "%ProgramFiles%\Microsoft Office 15\root\office15\OUTLOOK.EXE" & chr(34)
    ObjShortCut.IconLocation = "%ProgramFiles%\Microsoft Office 15\root\office15\OUTLOOK.EXE, 0"
    objShortCut.Save
    The following application path is also ok in this vbs
    %ProgramData%\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Outlook 2013.lnk
    Thanks.
    Tony Chen
    TechNet Community Support

  • Disable Reply All button via Group Policy without disabling keyboard shortcut

    At my organization, we've used Group Policy to disable the Reply to All button in Outlook 2007 and Outlook 2010. When you use the setting in the ADM files for the respective versions of Office to disable a Command bar ID, the Reply to All button is disabled,
    however they keyboard shortcut (Ctrl + Shift + R) is still active. This forces our users to think a bit more before using the Reply All function.
    The keyboard shortcut continues to work, because there's a separate setting to disable the keyboard shortcuts. The same is true for Office 2013's GP templates, however, it does not function as expected.
    When I use the Office 2013 admin templates and disable command bar ID 355 (Reply All), it disables the button as expected, however it also disables the keyboard shortcut for Reply All without actually setting it as disabled in the disable shortcut keys.
    Has anyone had success disabling a command bar ID without disabling the associated shortcut keys? If so, how did you do it?

    Hi,
    This issue has been fixed by this hotfix:
    Hotfix 2881040 for Outlook 2013 June 10, 2014 (Outlook-x-none.msp)
    http://support.microsoft.com/kb/2881040
    Thanks,
    Steve Fan
    Forum Support
    Come back and mark the replies as answers if they help and unmark them if they provide no help.
    If you have any feedback on our support, please click
    here

  • Adding Internet shortcut favourites using Server 2012 R2 Group Policy Manager

    Hi there,
    I wonder could someone help me!
    Up on to recently we have been using the User Policies/Windows Settings/Internet Explorer Maintenance/URLs/Favourites and Links Group policy in Windows Server 2008 R2 but now within Server 2012 R2 that option doesn’t seem to be available.
    If I however click on the GPO that is currently in place that has favourites specified and click on the Setting tab it generates the report showing the old /Internet Explorer Maintenance/URLs/Favourites and Links Group policy but with I click Edit on the
    GPO it doesn’t show me the /Internet Explorer Maintenance/URLs/Favourites and Links Group policy to allow me to add more favourites.
    From reading online I see that that /Internet Explorer Maintenance/URLs/Favourites and Links Group policy has been dropped in Server 2012 with the IEAK but this seems to need to be downloaded and installed I assume on a DC which I’m reluctant to do.
    I notice there something called the Policy Preferences Administrators tool that should allow me to set favourites but I’m not sure how to use that or even where to get it – it is a feature in Server 2012?
    Sorry for all of the info above!  All I want to do is within Server 2012 R2 edit an existing Windows 2008 R2 group policy and add new shortcuts to that policy so they are pushed out.
    Any help or guidance would be greatly appreciated!
    Thanks,
    Bonemister  

    Hi Frank,
    Thanks very much for your reply!
    Ok, method 1 seems to be a good way for what I am looking to achieve in terms of providing shortcuts, however, could you clarify a couple of things for me please: -
    Does method 1 create a shortcut within Internet Explorer that is accessible by all users when they click on the favourites tab or is it a desktop shortcut?
    At present there are no shortcuts specified within User Configuration -> Preferences -> Windows Settings -> Shortcuts so I presume the current shortcuts are currently still being delivered via the settings within IEM. 
    If that is the case I don’t then want to remove the IEM from the GP reporting tools. The question is, can I keep the current policy that seems to be delivering our shortcuts and just use
    User Configuration -> Preferences -> Windows Settings -> Shortcuts to add any new shortcuts that we need – would there be any issue with having both GPOs operating or would there be any issues introducing shortcuts alongside the IEM
    settings?
    Thanks again for your help!
    Bonemister
    Method #1, is more of a problem-fix, rather than a solution-for-how-to-do-it-from-now-on. This method would only really be needed, if you have a dysfunctional IEM-GPO, causing issues.
    GPP is the way you need to adopt, because even Windows7 is affected by the IEM-removal if you upgrade IE to IE10 or newer (regardless of the Windows Server version you are using).
    The recommendation is that you create some new GPOs for transitioning away from IEM over to GPP, test those, and then deploy those and remove your older GPOs that were using IEM, this would complete your transition away from IEM.
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • Group policy using to create Chome shortcuts

    Hi all,
    I require assistance please with a webpage to open in Chrome and to be on all users desktop to stop kids deleting.
    Currently I have the following in group policy but it fails to work the url is http://thirdspacelearning.com/user/login
    Name: Thirdspacelearning shortcut
    Target type: File System
    Object Location: All Users Desktop
    Target path: "C:\Program Files\Google\Chrome\Application\chrome.exe" http://thirdspacelearning.com/user/login
    Start in: "C:\Program Files\Google\Chrome\Application"
    Shortcut key: None
    Run: Normal Window

    Hi, 
    Based on my test, the shortcut setting you post could work correct.
    First we should confirm that the client that user login has installed the chrome. If chrome has not been installed on the client, the shortcut will not appear in the client.
    Besides, we could use the
    gpresult /h GPReport.html command to generate a Resultant Set of Policy (RSoP) report. We could check if the GPO and the shortcut setting applied from the report.
    Best Regards,
    Erin

  • Apply Network shortcuts via group Policy

    I learned of a very special kind of shortcut in Mark Minasi's "Mastering Windows Server 2012 R2" (pg 966) that allows you to create a "network folder" which is termed "Add a network Location" when you actually create the shortcut
    in File Explorer.
    I want to use AD group policy to deploy such shortcuts, but I am not seeing a way. I am [somewhat] familiar with creating shortcuts using GP Preferences, but that does not seem to be applicable for creating Network Folders.

    Hi,
    You can achieve your requirement using either GP Preferences or logon script.
    But comparing the two techniques GP Preferences is recommended. 
    This is because logon scripts increases the loading time during logon and may not load properly at random times.
    To map the network folder using Preferences, open GPMC console -> Edit the GPO assigned to the desired scope of users -> click the ‘User Configuration’ folder, then click the ‘Preferences’ folder. You can see all of the user-relevant options you can set
    in Preferences. Find Drive Maps under ‘Windows Settings'.
    Checkout the below link on configuring Drive Maps using Preferences, 
    http://technet.microsoft.com/en-us/library/cc770902.aspx
    Checkout the below thread on similar discussion,
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/71c19111-75b0-412c-889f-79154857d685/deploy-network-drive-gpo
    Regards,
    Gopi
    www.jijitechnologies.com

  • Group Policy and shortcuts

    ok imagine there is a company "x" that has a group policy which allows certain softwares to be executed  . In one department of this company , employs uses a certain program called "y" . One employ create a shortcut of this program
    on the desktop and when he tries to open it , a error message comes out which tell him that a policy which allows certain softwares is in use . Can someone explain to me what happened ? I know the group policy which allows certain softwares is in use but if
    he can use the program why he cant use the shortcut ? :/ 

    Am 04.02.2014 11:47, schrieb KristAlbania:
    > One employ create a shortcut of this program on the desktop and when he
    > tries to open it , a error message comes out which tell him that a
    > policy which allows certain softwares is in use .
    AppLocker or SRP? AppLocker has an event log that will tell you what
    exactly was blocked...
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • RDS 2012 R2 - How do I lockdown access to Local Computer Management and Windows Backup via Group Policy

    Greetings all,
    I am needing assistance in how to lockdown access to Local Computer Management and Windows Backup via Group Policy for users that access RDS service. I have followed this awesome guide - h t t p://w w w.it.ltsoy.com/windows/lock-down-remote-desktop-services-server-2012/
      - but it is missing two important resources that I would like to lock down.Currently, I have successfully locked down Control Panel for users via Group Policy, but I cannot find any group policy or guide on how to restrict user access
    to Computer Management (different to Server Manager). When using Win-X shortcut to open the 'Administrator's shortcuts' near the windows icon, I have locked down everything except Computer Management. Computer Management gives direct access to Disk Management,
    Shares etc, which are locked down for users. But Windows Server Backup is still accessible. Can someone please guide me on how to restrict access to both Computer Management and Windows Server Backup.
    Thanks in advance.
    Terry.

    Prevent running of Windows Server Backup
    Computer Configuration\Policies\Windows Settings\Security Settings\File System
    Right click on File System - Add File - Drill down to \System32\wbadmin.msc
    On the Database Security ACL that pops up - Remove Creator Owner, Remove Users and check Adminstrators have Full Access.
    On the Object window - choose Propagate inheritable permissions to all... (Default)

  • Group Policy Deployment Acrobat Standard XI Version 11

    I was able to successfully create a Windows 2008 R2 SP1 Group Policy that would be able to distribute the Adobe Reader Application using the Adobe Customization Wizard XI. I tried to use the same procedure from the Adobe Acrobat Standard 11 download from the adobe licensing site and was unable to get the Group Policy to work. The error message that I am getting is...
    The install of application Adobe Acrobat XI Standard 11.0 from policy  Deploy Adobe Acrobat 11 failed. The error was : %%1603
    This is the procedure that I created for deployment of Adobe Acrobat XI using Group Policy.
    How to create a group policy deployment of Adobe Acrobat XI
    Overview:
    This procedure covers the steps needed to create a group policy that will deploy the Adobe Acrobat installation.
    Requirements
    •    Windows 2008 Group Policy
    •    Adobe Acrobat Customization Wizard
         o    ftp://ftp.adobe.com/pub/adobe/acrobat/win/11.x/11.0.00/misc/CustWiz11000_en_US.exe
    •    Adobe Acrobat XI (Version 11)
         o    download from adobe account
    Procedure:
    1.    Download the Adobe Acrobat XI package.
    2.    Extract the contents of the Adobe Acrobat XI package.
    a.    Type msiexec.exe /a AcroStan.msi
    b.    Click Next
    c.    Put in the Network Location Share where everyone can extract the installation.
    d.    Click Install
    e.    The package will then extract to the network location as indicated above.
    f.    Click Finish, once the installation has completed.
    g.    Open the Adobe Customization XI Wizard, and customize the package by selecting the AcroStan.msi file. 
    h.    Customize the AcroStan.MSI installation file   
    i.    Default viewer of PDF files: Make Acrobat the Default PDF Viewer
    ii.    Remove previous versions of Acrobat
    iii.    Run Installation: Silently
    iv.    If reboot is required at the end of installation: Suppress reboot
    i.    Shortcuts: Remove the desktop Shortcut
    j.    Online and Adobe Services: Disable Product Improvement Program: checked.
    k.   Generate Transform File
    i.    Click Transform > Generate Transform File
    ii.   Create an Setup.Ini file in the folder of the Distribution Package.
    iii.  Name the Transform File something useful like “CompanyConfigs”.
    3.    Create a Group Policy to deploy the software package. It is usually best to have a group policy for each software installation package.
    a.    Update the Domain Default Policy with Always install with elevated privileges. This will allow all software deployment packages to install. 
    i.    Computer Configuration > Policies > Windows Settings > Administrative Templates > Windows Components > Windows Installer > Always install with elevated privileges : Enabled.
    b.  Create a Group Policy to enable Windows 7 Verbose Mode
    i.    Computer Configuration > Policies > Administrative Templates > System > Verbose vs normal status messages : Enabled.
    c.    Create a Group Policy for the Software Installation
    i.     Computer Configuration > Policies > Software Settings
    ii.    Right click and select New > Package
    iii.   Click the AcroRead.msi
    iv.   Click Advanced
    v.    Click the Modifications Tab and click Add
    vi.   Optional: Click the Uninstall this application when it falls out of the scope of management.
    Note: This setting can be used to uninstall the application if the group policy ever changes in that the application should be removed.
    vii.    The package is now created …
    4.    Test the Client in a Virtual Machine
    a.    Go to a windows client and run “gpupdate /force”.
    b.    The system will then respond that it needs to restart the computer.
    c.    Type Yes, and allow the computer to reboot.
    d.    If Group Policy is not setup to allow for verbose messages in Windows 7 then the user will just see “Please wait…”, if verbose message is enabled the user will see “Installing Adobe Acrobat…”.
    Can someone please tell me what I am missing to get the group policy deployed? It has the same permissions as the Adobe Reader folder and I have done everything exactly the same, except that Adobe Standard has the license number, and owner information included in the Transform file (.mst).
    Thank you.

    Your case isn't unique. We've heard this a lot. While Acrobat has a small, very small percentage of settings available in the ADMX files,
    in case you don't know, PolicyPak software has a solution to manipulate, basically, near 100% of the settings in Acrobat Reader and Professional.
    You're welcome to check out how it works. These videos are for Acrobat X, but there is also tempaltes in the download for XI.
    Here are links to the pages with full how-to videos:
    http://www.policypak.com/products/manage-acrobat-reader-with-group-policy.html
    and
    http://www.policypak.com/products/manage-acrobat-x-pro-and-acrobat-x-standard-using-group- policy.html
    You can be up and running in 20 minutes, but note, it's NOT a template.. PolicyPak is full application management and lockdown system.

  • W7 client machine stuck on startup "Group Policy Files Policy"

    we have some w7 machine getting stuck on boot up before ctrl-alt-del, once verbose message was turned on for troubleshooting, we noticed they were stuck at "applying group policy files policy".
    we had let it wait for more than 60 minutes at time and it would still be stuck. (thou mouse / kb still responsive)
    this problem however, is not re-produceable on demand, if we power off the machine, it boots back up with no issues.
    checking the group policy log, we didn't find anything weird, but was not sure if that's the right place to look thou.
    we do have two group policy preferences pushing out host files as well as desktop shortcuts, might that be the culprit?
    thanks!

    > we do have two group policy preferences pushing out host files as well
    > as desktop shortcuts, might that be the culprit?
    My recommendation: Use Group Policy Preferences as you like, but do NOT
    use the "Files" extension.
    Why? GP Processing at Boot/Logon is a synchronous foreground process
    that cannot be interrupted (as you are already experiencing ;-)).
    Replace GPP Files with a script that runs some robocopy commands. Start
    this script through a scheduled task at boot or logon, so that it can
    run asynchronously in the background, not disturbing the user experience.
    regards, Martin
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    Wenn meine Antwort hilfreich war, freue ich mich über eine Bewertung! If my answer was helpful, I'm glad about a rating!

Maybe you are looking for