Problem Pushing Printer Preferences through Group Policy

Most of the time, networked printers that we push through group policy preferences show up just fine on our clients (Windows 7). About 1 in 10 computers fail however, and it's driving me up the wall! The computer that fails is not consistent, meaning I can
reboot a computer and the printer then shows up correctly. It may not, however, a week later. Fairly random. Looking through the application event log, I uncovered this:
The user 'myprinter' preference item in the 'mygrouppolicy {7EDE8A14-773C-4E43-93AE-050240E0B204}' Group Policy object did not apply because it failed with error code '0x800706ba The RPC server is unavailable.' This error was suppressed.
Again, this error does not occur all the time, though if I reboot a large group of computers, it will definitely show up on 1 or 2 of them. At this point, I'm looking for any suggestions for a next step. Thanks!
-Peter

Hello Modab,
If you reboot server the printer is redeployed properly. It is possible that when the printer is deployed the network is still not prepared properly so the RPC error
is popped up.  Please try the following suggestions:
1. Disable Fast Logon feature
Enable the
[Computer Configuration \ Administrative Templates \ System \ Logon \ Always wait for the network at computer startup and logon]
group policy.
Logon Optimization
http://msdn.microsoft.com/en-us/library/aa374350(VS.85).aspx
Description of the Windows XP Professional Fast Logon Optimization feature
http://support.microsoft.com/kb/305293/en-us
2. Group policy application issue may occur because of Gigabit NIC. Please try the suggestions in the following steps and KB.
a.      
To prevent your network adapter from detecting the link state(For Windows Vista/7):
Run the following commands one by one:
netsh interface ipv4 set global dhcpmediasense=disabled
netsh interface ipv6 set global dhcpmediasense=disabled
For Windows XP, you can see
http://support.microsoft.com/kb/239924
b.     
Contact the vendor of the network card or visit their web site to obtain updated drivers for the Gigabit NIC.
Examples of NICs known to exhibit this issue:
- Broadcom Gigabit Adapter
- Intel Gigabit Ethernet PRO Adapter, Intel Pro/1000
- Intel 82544EI-based XT Gigabit Adapter (82540EM chipse)
- Compaq/HP NIC dual interface 10/100/1000 doing teaming (HP NC7170)
- Dell Inspiron laptops using an on-board Broadcom BCM4401 NIC
c.      
A sever may have a Dual Port NIC or multiple NIC's with one port or NIC set to Disabled. The disabled port or NIC should not be at the top of the binding order in the Network
Advance Properties.
1.      
Click Start, point to Settings, and then click "Network and Dial-up Connection".
2.      
On the Advanced menu, click "Advanced Settings".
3.      
On the "Adapters and Bindings" tab, in the connections list, select the NIC that the clients use to connect to the server and move it to the top of the list.
d.     
Turning off STP can cause issues in your network if a loop ever develops. If you are running a Cisco Series switch or any other switch that runs Spanning Tree, it is best to
leave spanning tree turned on, but enable PORTFAST on all the ports except uplink and fiber trunks.
326152 Cannot connect to domain controller and cannot apply Group Policy with Gigabit Ethernet devices
http://support.microsoft.com/default.aspx?scid=kb;EN-US;326152
3.
 Remove all of 3rd-party software such as firewall software.
4.  Set a registry value to delay the application of Group Policy.
http://support.microsoft.com/kb/2421599
      http://support.microsoft.com/kb/840669
Brent Hu,
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. ”

Similar Messages

  • How to disable print screen by group policy?

    I tried with below steps however its not working. Please assist me on this?.
    Step one:  Create a Reg_binary entry using the info below:
    (reg file: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layout]
    “Scancode Map”=hex:00,00,00,00,00,00,00,00,04,00,00,00,00,00,2a,e0,00,00,37,e0,\
    00,00,54,00,00,00,00,00)
    Step two: Link all OU sites to this new GPO policy
    Do one of the following:
    1. To link to a domain or an organizational unit, open Active Directory Users and Computers.
    2. In the console tree, right-click the site, domain, or organizational unit to which you want the Group Policy object to be linked.
    3. Click Properties, and then click the Group
    Policy tab.
    4. To add the Group Policy object to the Group Policy Object Links list, click Add. This opens the Add
    a Group Policy Object Link dialog box.
    5. Click the All tab, click the Group Policy object that you want, and then click OK.
    6. In the properties dialog box for the site, domain, or organizational unit, click OK.

    Hi Dinesh,
    To disable print screen, we can create a .reg file containing:
    Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layout]
    "Scancode Map"=hex:00,00,00,00,00,00,00,00,04,00,00,00,00,00,2a,e0,00,00,37,e0,\
     00,00,54,00,00,00,00,00
    Then, we can apply the registry setting through a startup script via group policy, or if our domain controllers is Windows Server 2008 or above, we can utilize Group Policy
    Preferences Registry extension to deploy the registry setting.
    Regarding this point, the following thread can be referred to for more information.
    To Disable Print Screen through Group Policy
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/03af5c6a-636a-43e4-95dd-183331c0d4ac/to-disable-print-screen-through-group-policy?forum=winserverGP
    Best regards,
    Frank Shen

  • Pushing Printers through Group Policy and Windows 8.1

    I'l looking for help with an issue our organization is having.  We are pushing out our printers through Group Policy on our Windows 2012 server.  We setup a printer security group, then setup the printer on the print server (not shared).  We
    then created a policy under User Configuration\Preferences\Control Panel Settings\Printers\ to then do item level targeting.  We then add that security group to the PC we want to get that printer.  This works with our Windows 7 systems.  Windows
    8.1 on the other hand just has a hard time getting these policies.  
    My question is, is there a certain way you have to deploy printers with Windows 8.1?  We would like to deploy printers going the user configuration route because that way the print jobs have to be pushed to the print server.  Deploying them though
    Computer Configuration doesn't give us that option.
    Any help is greatly appreciated!

    The security group for the printer has multiple computers added to it but only the Windows 7 systems seem to get the policy applied.  Attached is a screen shot(s) of how we currently have it setup.
    https://drive.google.com/file/d/0B3Z5p22SZgFlODJqVVFxOXFFUHM/view?usp=sharing

  • File and Printer sharing on Windows 7 Through Group Policy

    Hi,
    I was wondering how to enable File and Printer sharing on Windows 7 Through Group Policy. I have enabled the policy called: Allow inbound file and printer sharing exception.
    But when I go to advanced sharing settings, it's still turned off.
    Windows Server 2003 AD Domain, and I'm using the Group Policy Manager from my Windows 7 machine to edit the policy.
    Any ideas?

    Hi,
    Based on my knowledge, there is no Group Policy setting for enabling and disabling File and Printer sharing. To do this, you may need to write a script and you can go to our Scripting Forum for help.
    In addition, I would like to share the following with you:
    Enable or Disable File Sharing for a User or Group by Using Group Policy
    Network and Sharing Center Group Policy Settings
    Hope this helps. Thanks.
    Nicholas Li - MSFT

  • Flash 10 msi problems through Group Policy

    Here's the problem:
    We've signed up to Adobe to get there official corporate Flash and Shockwave msi's for network distribution.  They have been set in Group Policy and sent down to our machines.  It says its installing and when you check add\remove programs both are installed.  Some flash\shockwave sites are fine others say that flash 10 is not installed 'do we want to update' or we get this message "can't verify publisher.. swflash.cab".  If logged on as an administrator we can run the update and all is fine, this however defeats the purpose of the GP distribution.
    When the msi's are run manually on a machine they work perfectly, so the problem exists while being sent through Group Policy.  The clients\PC's are running XP and are fresh builds (there are no older versions of Flash on them).
    I've looked online for similar cases, but nothing.  Has anyone else encountered this issue?  or have any ideas why the install will not fully go down?

    Don't worry, I've sorted it.
    An ex employee had created a package with flash 8 installing alongside\inside another one (totally unrelated to what should have been going down).  Which meant the flash 10 was getting overwritten.  It's been removed, and everything works fine.
    Bye.

  • Deployment of software through Group policy does not work

    Hi all,
    I am trying to deploy a program through Group policy, specifically winrar, any client computer is able to install the program. Please find below the events from the workstation:
    Log Name:      Application
    Source:        Microsoft-Windows-WMI
    Date:          4/27/2014 10:06:01 PM
    Event ID:      10
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      IRCLIENT0001.corp.healthcareinnovation.com
    Description:
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because
    of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log Name:      System
    Source:        Microsoft-Windows-GroupPolicy
    Date:          4/27/2014 10:04:49 PM
    Event ID:      1085
    Task Category: None
    Level:         Warning
    Keywords:      
    User:          SYSTEM
    Computer:      IRCLIENT0001.corp.healthcareinnovation.com
    Description:
    Windows failed to apply the Software Installation settings. Software Installation settings might have its own log file. Please click on the "More information" link.
    Log Name:      System
    Source:        Application Management Group Policy
    Date:          4/27/2014 10:04:49 PM
    Event ID:      108
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          SYSTEM
    Computer:      IRCLIENT0001.corp.healthcareinnovation.com
    Description:
    Failed to apply changes to software installation settings.  Software changes could not be applied.  A previous log entry with details should exist.  The error was : %%1612
    Log Name:      System
    Source:        Application Management Group Policy
    Date:          4/27/2014 10:04:48 PM
    Event ID:      102
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          SYSTEM
    Computer:      IRCLIENT0001.corp.healthcareinnovation.com
    Description:
    The install of application WinRAR from policy Basic Computers GPO failed.  The error was : %%1612
    I am using windows server 2008 R2 and all my clients are running Windows 7 Enterprise and they are working over a domain, note that I am using VMware.
    Below there are a list of the troubleshooting steps that have been already applied:
    *Disable the the firewall both in the server and in the clients 
    *Grant read access to the folder where the the program is shared for installation, it was added the authenticated users and domain computers.
    *Group policy modifications: 
    -> User Account Control
    Policy Setting Winning GPO 
    - User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode Elevate without prompting Basic Computers GPO 
    - User Account Control: Detect application installations and prompt for elevation Disabled Basic Computers GPO 
    - User Account Control: Only elevate UIAccess applications that are installed in secure locations Disabled Basic Computers GPO 
    - User Account Control: Run all administrators in Admin Approval Mode Disabled Basic Computers GPO 
    --> System/Group Policy
    Policy Setting Winning GPO 
    - Startup policy processing wait time Enabled Basic Computers GPO 
    Amount of time to wait (in seconds): 120 
    --> System/Logon
    Policy Setting Winning GPO 
    - Always wait for the network at computer startup and logon Enabled Basic Computers GPO 
    Thank you very much for your time.

    Hi Marco,
    Based on your description, we can enable diagnostic logging of Group Policy Software Installation processing to troubleshoot the issue.
    Regarding this point, the following article can be referred to for more information.
    How to troubleshoot software installations by using Windows application management debug logging
    http://support.microsoft.com/kb/249621
    Once you get the log, you may upload it to OneDrive and provide us the download link.
    In addition, the following article provides a step-to-step guidance for deploying software via group policy and can be referred to for double check.
    How to use Group Policy to remotely install software in Windows Server 2008 and in Windows Server 2003
    http://support.microsoft.com/kb/816102
    Best regards,
    Frank Shen

  • Set a standard font for Outlook through group policy

    Dear All,
               We are using exchange 2010 and domain 2008 server in our company. For outlook we are using 2003, 2007, 2010 and 2013. Now we are plans to set a standard font and default font size for sending and replaying through
    outlook. We need to set this one through group policy.
            Your support will be highly appreciated  

    Hi,
    We can deploy default font for same version of Outlook, I haven’t found a way to change the font among different versions. The only way to achieve this is deploy font for each version of Outlook separately:
    Set default font for Outlook 2003, please refer:
    http://thommck.wordpress.com/2009/05/28/standardising-outlook-fonts-using-group-policy-preferences/
    To set default font for other versions of Outlook, please refer to the steps below:
    1. Set the font you want in one computer.
    Outlook 2007: click Tools > Options > Mail Format > Stationary and Fonts.
    Outlook 2010 and Outlook 2013: File > Options > Mail > Stationary and Fonts.
    2. Export the following registry key:
    HKEY_CURRENT_USER\Software\Microsoft\Office\XX.0\Common\MailSettings
    XX.0 is the version of your Office. 12.0 for Outlook 2007, 14.0 for Outlook 2010 and 15.0 for Outlook 2013.
    3. Distribute the .reg file via Group Policy.
    For more information, please refer to the following article and look at the “Changing Default Font for Outlook 2007” section:
    http://blogs.technet.com/b/odsupport/archive/2009/04/24/how-to-deploy-specific-fonts-in-office-2007.aspx
    Hope this helps.
    Regards,
    Steve Fan
    TechNet Community Support

  • How to restrict users working on Windows 7 clients from accessing Windows Explorer and other systems in the network through Group Policy with a domain controller running on Windows Server 2008 r2

    Dear All,
    We are having an infrastructure setup of around 500 client computers managed through group policy.
    Recently the domain controllers have been migrated from Windows Server 2003 to Server 2008 R2.
    Since this account requires extremely strict environment, we need to figure the solution for restricting the users from access anything locally.
    It would be great if you can assist me with the following query.
    How to restrict users logged on Windows 7 clients from accessing Windows Explorer and browsing other systems in the network through Group Policy with a domain controller running on Windows Server 2008 r2 ?
    Can we disable Network Tab on the left hand pane ?
    explorer.exe is blocked already, but users are able to enter the Windows Explorer by clicking on the name which is visible on the Start Menu.

    >   * explorer.exe is blocked already, but users are able to enter the
    >     Windows Explorer by clicking on the name which is visible on the
    >     Start Menu.
    You cannot block explorer.exe when you do not replace the shell - the
    desktop you see effectively IS explorer.exe...
    Your requirement sounds like you need a custom shell:
    http://gpsearch.azurewebsites.net/#2812
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • Remote Registry enabled through Group Policy

    I am working in a Win2011 SBS environment and trying to enable services (Automatic) through Group Policy on all workstations in the domain. I need the following settings enabled but not sure how to do it in SBS.  Any help is greatly appreciated.
    Policies for Windows Services
    Computer Configuration > Windows Settings > Security Settings > System Services
     Windows Management Instrumentation (WMI)
     Startup Type: Automatic
     Remote Registry
     Startup Type: Automatic
     Remote Procedure Call (RPC)
     Startup Type: Automatic
    Paul J. Page

    Hi,
    It should be quite similar to other OS.
    (Note: RPC services & WMI Service should be started by default. Remote Registry is manual and not started by default.)
    Policy Configuration :
    I would start with Creating a New GPO with the name "Automatic Service Policy"
    After that follow the default steps
    http://www.grouppolicy.biz/2010/08/how-to-use-group-policy-to-control-services/
    Do forget to Link the policy
    Gpupdate / force
    I am sure this will work.
    Binu Kumar - MCP, MCITP, MCTS , MBA - IT , Director Aarbin Technology Pvt Ltd - Please remember to mark the replies as answers if they help and unmark them if they provide no help.

  • Deploying Reader through Group Policy

    Hi,
    I have applied for and been granted a deployment license, and am trying to follow the instructions to deploy reader through group policy to computers on my network.
    The document adobe gives you says to put the computer name under security filtering in the OU GP that was created.  I have done this but it's clear the policy isn't getting applied.
    When I run group policy result, it's not even showing so I must have something wrong.  The document that adobe gives has several of the pictures out of place and is covering some text (at least when I display it - and yes I am using most current version of reader).
    Any ideas?
    Thanks,
    Allen

    Unless I'm misunderstanding your last reply, the GPO is working as intended, when you change it back.
    GPO = Applied to one specific OU
    Security Filtering = 1 specific PC
    Active Directory OU for intended GPO contains = 0 computers
    The PC you're applying the security filtering to must exist in the Active Directory OU you created for the GPO.
    E.G. I create a GPO called acc_sw for my Accounting dept called accounting.  3 PCs in accounting are called:
    Ed_PC
    Karen_PC
    Thomas_PC
    In the security filtering for the GPO I created, I have:
    Ed_PC
    Karen_PC
    Thomas_PC
    Now, in Active Directory Users & Computers, in the accounting OU I have 0 computers.
    The end result is no acc_sw being processed for:
    Ed_PC
    Karen_PC
    Thomas_PC
    They must exist in the target OU, or a suboordinate OU of the target OU, for the GPO to work.

  • Deploying office through group policy

    Hi people,
    English is not my mother language so i'll hope you'll understand me.
    I have a school project. Deploying office through group policy worked. But now my teacher has given me a command to give all OU's a different OFFICE packet when they logged in. So.. it will change the current installation when a different user from a different
    OU logged in. I'm out of options. Please can anybody help me:(:(

    No you don't misunderstand :p  My teacher first did it wit Office 2003 and know i must do it in office2010.. and i also thought it was a stupid idea.. But who am i... i have not much knowledge in IT.. i'm still learning.
    But i have 2 options
    To confince him that this is not a good idea... (and i dont know with wich argument)
    or find a way to do this... 
    Hmm, so, I think that kind of crazy was possible with very old versions of Office, which could be "advertised" via GPO to achieve per-user scenarios, but Office2007 and later versions, don't provide such different per-user options as part of setup.
    Office2007 and later, uses the MSPfile etc for customization, and that is per-machine (common to all users of that machine).
    You might be able to achieve something similar, by using AppLocker (e.g. AppLocker rules which deny excel.exe to be executed by GRP_Students).
    But this doesn't address the matter nicely, because the Students can see the Excel shortcut/icon/program, but are forbidden to execute it.
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • I need step by step guide to install MSI package through group policy

    I need step by step guide to install MSI package through group policy its about.
    I tried a lot using software deployment with GPO but its not happening may be I am doing mistake I am not getting.
    help.
    Thanks,
    Mohan

    Hi,
    Maybe we could refer to the following Microsoft KB article for 
    detailed information about how to use Group Policy to remotely install software.
    How to use Group Policy to remotely install software in Windows Server 2008 and in Windows Server 2003
    http://support.microsoft.com/kb/816102
    Hope this helps.
    Best Regards,
    Andy Qi
    Andy Qi
    TechNet Community Support

  • What is the differents between Policies and Preferences in Group policy Management Editor

    What is the differents between Policies and Preferences in Group policy Management Editor?

    Policies: If you delete a policy in GPO it deletes its registry files form the clients. Policies don't tattoo the registry. Policies Settings are permanent as long policy is in effect i.e. Desktop Backgrond. Policies are applied at Computer
    Startup, User logon and Manual and automatic refresh. Takes Precedence over Preferences.
    Preferences: Even if you delete a policy form Preferences tab the registry files will still available on the systems. Preferences tattooed the registry if you want to remove the registry entries you have to do it manually. Preferences exampl
    is i.e. mapped drive. Settings applied with preferences are not grayed out. Not available in Local GPO.
    Usefull for
    Desktop Icons/Shortcuts
    Url
    Drive Map
    File Copy, Update, delete
    Thanks

  • Problem with Printing Preferences Acrobat XI on Windows 7

    I just upgraded from Acrobat X Std to XI Pro on both my Windows 7 desktop and Windows 8 laptop.  The laptop works fine, but on the desktop I'm not able to print to the Adobe PDF printer from Word or Excel or Chrome.  I noticed that the Adobe PDF Printing Preferences do not display any options for Default Settings or Adobe PDF Security.  I did find the Standard.joboptions file in the C:\ProgramData\Adobe\Adobe PDF\Settings folder on both machines.  What could be the problem?

    No files appeared in C:\Users\Pavilion\AppData\Roaming\Adobe\Adobe PDF\Settings but they did appear in Distiller.
    I tried to copied them from C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Settings, but found they were already there.  I copied them by adding -COPY before .joboptions in the name.  Now they appeared in  Printing Preferences with the -COPY added.
    I tested a print from Word (using File / Print), but was not prompted for the filename or location.  I checked my entire system and couldn't find the PDF file anywhere.  I tried changing the Port to Desktop\*.pdf using Printer Properties, but that didn't work either.
    I was able to successfully use the Acrobat menu item in Word & Excel to create a PDF but it automatically created the file on the Desktop without an option to change the filename.
    After several days and hours, I gave up and installed Acrobat X on the W7 computer.  I can still use Acrobat XI on the W8 computer.  So be it!
    Thanks anyway for your attempts to help.

  • Prevent OL2010 PST creation through group policy; need menu number or policy ID

    Greetings all and thanks in advance,
    In a similar fashion as found here:  http://social.technet.microsoft.com/Forums/pl-PL/outlook/thread/76081525-71d8-459e-a0cf-39d80a4c6cc7,  I need to block the creation of Outlook Data files through this path:  File > Account Settings >
    Data Files (tab) > ADD
    What is the menu number or policy ID of this item so I use it to disable from Group Policy?
    Thanks,
    Willis

    I cannot find the specified command bar ID in the following link:
    http://support.microsoft.com/kb/173604
    However, we may prevent users from adding PSTs to Outlook profiles via GPO. The location is "gpedit.msc | Computer Configuration | User Configuration | Administrative Templates | Micrsoft Outlook 2010 | Miscellaneous | PST Settings | prevent users from adding
    PSTs to Outlook profiles..."
    Thanks.
    Tony Chen
    TechNet Community Support

Maybe you are looking for