WSUS GPO not applying on server restart
At first I thought this was limited to a single SBS 2008 server but I have now seen this behavior on another SBS2008 and SBS2011 server. Basically what happens is I patch the server, I restart the server but... somehow the GPO for WSUS does not apply
and leaves the server Windows update settings set on Download automatically and install at 3am when it should be the Standard "Download and Notify for install"
I can open a command prompt and perform a gpupdate /force and the the correct policy immediately applies.
Has anyone seen this behavior? Is it possible a windows patch that has caused this issue. It must be something common amongst all three different instances of SBS. I do not see any errors in event logs regarding group policy.
Please Help
Hi skahlam,
Does this issue always occur when you reboot the server?
If yes, to verify if this issue is related to the updates, please try to remove the updates installed recently.
If issue persists after removing the updates, please try to run the gpresult /h C:\report.html
to check the detailed information about the GPO.
Note: This procedure needs the privilege of the Administrator.
Best Regards.
Steven Lee Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]
Similar Messages
-
GPO not applied at all with build 9926
Hello,
I have a Samba 4 Active Directory Domain controler. My LAN is composed of XP and 7 computers ; everything works well.
I also have tested previous builds of Windows 10, and had no particular problem with Group Policies.
With build 9926, my GPOs are not applied at all. It seems there is a big change making Group Policies not applied / not reloaded when users log in. Here are step by steps what I have noticed :
0) At the very first log in, when I do a gpresult /V, i have a message saying something like "no rsop data for this user"
1) I performed a gpupdate /force
2) I performed another gpresult /V and then I got information about my GPO
3) I logged out and logged in with same user --> my GPO is applied
4) I modified my GPO to set new policy
5) I loggged out and in again --> old policies are applied but new policy is not applied
6) I performed gpresult /V --> new policy is not displayed
7) I performed a gpupdate /force and then a gpresult /V --> new policy appears
8) I loggged out and in again --> All policies, including the new one are applied
So it seems the GPOs are not automatically updated and applied when logging in, and I have to force them manually.
The good question is : WHY ? :)
Thanks
WillHi Will799114,
I tested this in my environment, it seems a restart would apply group policy successfully, but a sign out and sign in would not trigger this procedure.
Here I would suggest you post your feedback directly to our Feedback channel:
http://windows.microsoft.com/en-in/windows/preview-how-to#how-to=tab7
Alex Zhao
TechNet Community Support -
HI All,
I have a OU for Computers and OU for USers.
Create the FolderRedirect GPO for User configuration ( Folder Redirection) for One Security Group (OLGroup) of people only.
I have applied to users but this policy not applying? Do i need Computers and Users in same OU?
ASGPO delegation to Sub OU is the same as the domain OU?
any conflicting GPOs that you think that might cause the problem?
or check the GPO inheritance and precedence:
Group Policy settings are processed in the following order:
Local Group Policy object—Each computer has exactly one Group Policy object that is stored locally. This processes for both computer and user Group Policy processing.
Site—Any GPOs that have been linked to the site that the computer belongs to are processed next. Processing is in the order that is specified by the administrator, on the Linked Group Policy Objects tab for the
site in Group Policy Management Console (GPMC). The GPO with the lowest link order is processed last, and therefore has the highest precedence.
Domain—Processing of multiple domain-linked GPOs is in the order specified by the administrator, on the Linked Group Policy Objects tab for the domain in GPMC. The GPO with the lowest link order is
processed last, and therefore has the highest precedence.
Organizational units—GPOs that are linked to the organizational unit that is highest in the Active Directory hierarchy are processed first, then GPOs that are linked to its child organizational unit, and so on. Finally, the GPOs that are
linked to the organizational unit that contains the user or computer are processed.
At the level of each organizational unit in the Active Directory hierarchy, one, many, or no GPOs can be linked. If several GPOs are linked to an organizational unit, their processing is in the order that is specified by the administrator, on the Linked
Group Policy Objects tab for the organizational unit in GPMC. The GPO with the lowest link order is processed last, and therefore has the highest precedence.
This order means that the local GPO is processed first, and GPOs that are linked to the organizational unit of which the computer or user
is a direct member are processed last, which overwrites settings in the earlier GPOs if there are conflicts. (If there are no conflicts, then the earlier and later settings are merely aggregated.)
from this link: http://technet.microsoft.com/en-us/library/cc785665(v=ws.10).aspx -
EAR project not starting after server restart.
Hello all,
I have made a plain EAR project that contains a WAR file which again contains some servelets and static stuff like images and JavaScript files. The project does not use any SAP specific functionality and is hence a regular J2EE EAR project that in theory could run on all compliant J2EE servers.
The problem is that when the server restarts the project does not start (not even lazily, that is upon a request being made to it). In other words I have to start it manually by using Visual Administrator or redeploying. Naturally this approach is not a long term solution.
In the application-j2ee-engine.xml file of the EAR project I have tried to set the parameter start-up to always with no luck as documented here:
[http://help.sap.com/saphelp_nw04s/helpdata/en/25/0c08f3981343609d4045f8acaa0a76/frameset.htm]
The server is a 7.0 sp 14.
I have succesfully deployed the project on older servers with no problems.
Any ideas?Hi,
Undeploy your application from SAP AS Java, e.g. via Visual Admin, and then redeploy it. If it does not start automatically, start it manually from VA. Check if you restart the server, the application is also started up correctly.
Besides that, does your application depends on another application, library, or service? (i.e. uses another appllication, library or service)
If so, did you explicitly declared this relation via the reference tag in application-j2ee-engine.xml ?
Kind regards,
Tsvetomir -
I have just started at a new company and trying to to setup some new GPO's
We have all the users in a root OU called Accounts
We have all the computers in a root OU Company\Workstations
There are a number of GPO assigned to the "Workstations" OU for both Users and Computer Policy's
I would like to add some new GPO's to the Users OU for Uses settings but they will not apply or appear.
I have run a Group Policy Results on a few workstations and I can see the GPO being applied from the Workstations OU but none from the Users OU. However if I set the GPO to run off the Workstations OU it appears.
> GPO's in the Workstations OU and if there are any users settings I will
> have to create a new GPO in for the Accounts' OU for any user settings
> before I disabled the Loopback GPO?
Basically "yes". Alternatively change Loopback "replace" to Loopback
"merge".
Martin
Mal ein
GUTES Buch über GPOs lesen?
NO THEY ARE NOT EVIL, if you know what you are doing:
Good or bad GPOs?
And if IT bothers me - coke bottle design refreshment :)) -
WSUS updates not applying to Office 2013 Home and Business OEM version
Hi
For some reason I cannot get WSUS updates to automatically install on clients running Office 2013 Home and Business OEM version.
For example
If user opens any of the office 2013 apps e.g. Outlook , word etc, it prompts a message at the top under the ribbon toolbar; UPDATE NOW.
All other updates for OS are downloading and installing just fine from our WSUS server.
What could this be?
I dont have this issue with clients running office 2003First thing you need to do is be absolutely certain which edition of Office you have installed.
There are five editions of "Office 365" and these days, almost anything that is "OEM" is almost certainly Office 365:
Office 365 Home
Office 365 Personal
Office 365 Small Business
Office 365 Small Business Premium
Office 365 Midsize Business
Office 365 ships with an activation code for an online management account, and authorizes the installation of the software on up to five devices. Office 365 is updated via the WEB .. ONLY.
In addition there are three editions of Office 2013:
Office Home & Student
Office Home & Business
Office Professional
If you have one of these three editions, you should also have a DVD and a Product Activation Code for the SINGLE-PC installation which is licensed for these editions provided by the vendor of your computers. Office 2013 can be updated using WSUS.
Since you're getting a prompt IN THE APPLICATION to "Update Now", I believe you're looking at instances of Office 365, not Office 2013. Office 2013 (desktop) does not provide in-product prompts for updates/upgrades.
Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
SolarWinds Head Geek
Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
http://www.solarwinds.com/gotmicrosoft
The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds. -
PIN sign-in GPO not applying to workstations
I am currently testing Windows server 2012 R2 with Windows 8.1 tablets and cannot get PIN sign-in to work on the client machines, I have disabled local policy processing and all of the management is coming from GP, however when I manually apply the policy
setting using gpedit.msc it works, does anyone of a way to have it read from GPO in domain?Hi,
Before going further, the setting Turn on PIN sign-in allows users to set up and sign in with PIN. As Don suggested we could check the registry key to confirm if the policy
setting was enabled successfully. If yes, to use PIN sign-in option,
users need to create a PIN for themselves. After a PIN is created, users should be able to choose to sign in with PIN sign-in option when they log on. After we enabled the turn on PIN sign-in setting, user also need to set the password for sign-in account.
After reset the account, user can use sign-in when user re-logon.
We can follow the steps below to set account password: to create a PIN, the following steps can be referred to as reference:
Step 1: Swipe in from the right edge of the screen, and then tap Settings.
(If you're using a mouse, point to the upper-right corner of the screen, move the mouse pointer down, and then click Settings.)
Step 2: Tap or click Change PC settings, and then tap or click Accounts.
Step 3: Tap or click Sign-in options, and under PIN, tap or click Add.
If you don't have a password on your account, you'll need to create a password before you can create a PIN.
Step 4: Confirm your current password and then you can create a PIN.
If there is any question, don’t hesitate to let us know.
Best Regards,
Erin -
GPO not applying to all users in the same security groups
If Elaine logs in on Angie's PC does it work?
Using Windows Server 2008 R1. I have a single domain with two DCs (both Server 2008 R1). Both DCs seem to be communicating without issues, as changes on one DC are replicating normally to the other for all services.I have a group policy set up to set drive mapping for my users. However when I run the GP modeling wizard only a few of the users receive the proper mappings. In this specific instance I have two users, Elaine and Angie. 1. Both are members of the Domain Users security group and another security group I created called Staff2. Neither user is a member of any other security groups.3. My group policy Security Filtering setting is set to apply the policy ONLY to the Staff security group4. When running the GP Results Wizard, Elaine's computer successfully processes the policy, but Angie's does not, and returns "Access Denied...
This topic first appeared in the Spiceworks Community -
Cross Forest User GPOs not applying
I know I've read a ton of forums concerning this issue and most were resolved but nothing read so far has helped and I'm really hoping there are a few ideas out there that I have missed.
We have two forests: a new 2012 forest and an 2008 at an 2003 forest level with two way forest trust.
We are able to login to computers in the 2012 forest regardless of domain with any user in the 2008 forest. However we are setting up our workstation environment in the 2012 forest which requires us applying user policies. All users are in the
2008 forest. We have enabled the allow cross forest policy and the loopback processing applied to the OU where the client machines are located in Active Directory. We have verified the trust on both sides and tested DNS using nslookup on both sides.
The DCs for both forest are located in the same physical building but two different subnets. The WAN guy has assured us that there are no ACLs involved. The firewall has been shut off on all DCs and all workstations. I see no LSA errors
on the DCs. Each forest has a stub DNS zone to the other forest zones. I've been able to successfully setup computer gpos to map drives to the users when they login to 2012 clients.
I'm completely lost for what else we need to be looking at to solve this problem. Any suggestion would be most welcome.Hi,
Before going further, what settings have we configured? Which Loopback mode have we chosen, Merger or Replace? What are operating systems of our clients?
For further troubleshooting, we can follow the following article to collect Gpsvc.log file.
How to enable GPO logging on windows 7 /2008 r2 ?
http://blogs.technet.com/b/csstwplatform/archive/2010/11/09/how-to-enable-gpo-logging-on-windows-7-2008-r2.aspx
After getting the log, you may upload it to OneDrive and provide us the download link.
Besides, we can try using netmon.exe to further trace network to see if this is caused by network traffic.
Microsoft Network Monitor 3.4
http://www.microsoft.com/en-in/download/details.aspx?id=4865
How to use Network Monitor to capture network traffic
http://support.microsoft.com/kb/812953/en-us
TechNet Subscriber Support
If you are TechNet Subscription user and have any feedback on our support quality, please send your feedback here.
Best regards,
Frank Shen -
OC4J 9.0.4 standalone : webapp not bound after server restart
Hello,
A strange thing happened to an OC4J 9.0.4 instance on AIX 5.2:
- I started the instance.
- I deployed an application using:
java -jar ${OC4J_HOME}/admin.jar ormi://localhost admin <pwd> -deploy -file cfj.ear -deploymentName cfj
java -jar ${OC4J_HOME}/admin.jar ormi://localhost admin <pwd> -bindWebApp cfj webcfj http-web-site /cfj
- I tested the application: no problem.
- Then I stopped the instance.
- The day after, I restarted my instance.
The problem is that the application was no more bound to /cfj, although everything was fine in http-web-site.xml.
I ran the "-bindWebApp" admin.jar stuff, and the application was ok again.
Did anyone have such a problem ? It is the first time for me, and it happend on a production system ! Any idea on how to fix it ?
Thanks in advance for any advice/information,
Pierre LarocheHello Glin,
It happened again with another application named but, which is now the last application listed in http-web-site.xml instead of cfj. Here are some excerpt from the xml files:
server.xml
<application name="bep" path="../applications/bep.ear" auto-start="true" />
<application name="ccl" path="../applications/ccl.ear" auto-start="true" />
<application name="cmt" path="../applications/cmt.ear" auto-start="true" />
<application name="eau" path="../applications/eau.ear" auto-start="true" />
<application name="eee" path="../applications/eee.ear" auto-start="true" />
<application name="erp" path="../applications/erp.ear" auto-start="true" />
<application name="tsc" path="../applications/tsc.ear" auto-start="true" />
<application name="zou" path="../applications/zou.ear" auto-start="true" />
<application name="sms" path="../applications/sms.ear" auto-start="true" />
<application name="eir" path="../applications/eir.ear" auto-start="true" />
<application name="cfj" path="../applications/cfj.ear" auto-start="true" />
<application name="but" path="../applications/but.ear" auto-start="true" />
http-web-site.xml
<default-web-app application="default" name="defaultWebApp" />
<web-app application="default" name="dms0" root="/dms0" />
<web-app application="default" name="dms" root="/dmsoc4j" />
<web-app application="default" name="init" load-on-startup="true" root="/init" />
<web-app application="bep" name="webbep" load-on-startup="true" root="/bep" />
<web-app application="ccl" name="webccl" load-on-startup="true" root="/ccl" />
<web-app application="cmt" name="webcmt" load-on-startup="true" root="/cmt" />
<web-app application="eau" name="webeau" load-on-startup="true" root="/eau" />
<web-app application="eee" name="webeee" load-on-startup="true" root="/eee" />
<web-app application="erp" name="weberp" load-on-startup="true" root="/erp" />
<web-app application="tsc" name="webtsc" load-on-startup="true" root="/tsc" />
<web-app application="zou" name="webzou" load-on-startup="true" root="/zou" />
<web-app application="sms" name="websms" load-on-startup="true" root="/sms" />
<web-app application="eir" name="webeir" load-on-startup="true" root="/eir" />
<web-app application="cfj" name="webcfj" load-on-startup="true" root="/cfj" />
<web-app application="but" name="webbut" load-on-startup="true" root="/but" />
<access-log path="../log/http-web-access.log" />
It seems correct to me. Any idea ?
Thanks,
Pierre -
Hi everyone
I am using WSUS in my internal network.
When i am trying to deploy GPO, The GPO seems to be applying on the computer but the
GPO settings are not being applied.
I am getting error An error occured while checking for updates for your computer
and in Windows update change settings, i can see it is grayed out with the option
Download updates but let me choose wheter to install them(some settings are managed by your system administrator)
I have disabled windows firewall when i was using Windows XP computers, Is any settings of windows firewall creating issues?
I have created a computer group in WSUS say TESTGroup
In GPO I have assigned the following settings(Please correct me if i am going wrong with the settings)
Configure Automatic updates : 3-Auto download and notify for install
Specify Intranet microsoft update service location: http://mywsus (here should it be mywsus or mywsus:8530)
Enable Client Side targeting : TestGroup ( I have OU in active directory with Computers)
Do not display install updates and shutdown option : Enabled
Automatic Updates detection frequency : 2 hours
Allow Non administrators to receive update notification : Enabled
Allow Automatic updates immedidate installation : Enabled
Turn of recommended updates via automatic updates : Enabled
Reschedule automatic udpates scheduled installation : 10 min
I have approved few updats in WSUS console to install on TestGroup
On Client Computer ihave used the command
wuauclt /detectnow and wuauclt /reportnow
Please guide meI have installed the updates KB2720211 KB2530678 KB2530709 KB2734608 on WSUS Server
My GPO settings are
Configure Automatic updates : 3-Auto download and notify for install
Allow signed updates from an intranet microsoft update service location : Enabled(i am using internal WSUS server exporting updates from internet connected WSUS to internal WSUS)
GPO is applying but settings are not being applied.
please do refer the client logs & attachment.
Triggering AU detection through DetectNow API
START ## AU: Search for updates
<<## SUBMITTED ## AU: Search for updates [CallId = {A52428A8-E7EC-4CAB-9842-0B66F6969382}]
** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
Agent *********
* Online = Yes; Ignore download priority = No
* Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
* ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
Agent * Search Scope = {Machine}
Setup Checking for agent SelfUpdate
Setup Client version: Core: 7.6.7600.320 Aux: 7.6.7600.320
Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab with dwProvFlags 0x00000080:
Microsoft signed: NA
Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\TMP8FF3.tmp with dwProvFlags 0x00000080:
Triggering AU detection through DetectNow API
Piggybacking on an AU detection already in progress
Microsoft signed: NA
Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab with dwProvFlags 0x00000080:
Microsoft signed: NA
Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab with dwProvFlags 0x00000080:
Microsoft signed: NA
Setup Determining whether a new setup handler needs to be downloaded
Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\Handler\WuSetupV.exe with dwProvFlags 0x00000080:
Microsoft signed: NA
Setup SelfUpdate handler update NOT required: Current version: 7.6.7600.320, required version: 7.6.7600.320
Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.6.7600.320"
Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.6.7600.320" is already installed.
Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.320"
Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.320" is already installed.
Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~x86~~7.6.7600.320"
Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~x86~~7.6.7600.320" is already installed.
SelfUpdate check completed. SelfUpdate is NOT required.
+++++++++++ PT: Synchronizing server updates +++++++++++
+ ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://MYWSUSServer/ClientWebService/client.asmx
WARNING: GetConfig failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404
WARNING: PTError: 0x80244019
WARNING: GetConfig_WithRecovery failed: 0x80244019
WARNING: RefreshConfig failed: 0x80244019
WARNING: RefreshPTState failed: 0x80244019
WARNING: Sync of Updates: 0x80244019
WARNING: SyncServerUpdatesInternal failed: 0x80244019
* WARNING: Failed to synchronize, error = 0x80244019
* WARNING: Exit code = 0x80244019
** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
Agent *************
WARNING: WU client failed Searching for update with error 0x80244019
>>## RESUMED ## AU: Search for updates [CallId = {A52428A8-E7EC-4CAB-9842-0B66F6969382}]
# WARNING: Search callback failed, result = 0x80244019
# WARNING: Failed to find updates with error code 80244019
## END ## AU: Search for updates [CallId = {A52428A8-E7EC-4CAB-9842-0B66F6969382}]
Need to show Unable to Detect notification
Successfully wrote event for AU health state:1
AU setting next detection timeout to 2015-03-20 20:18:22
Successfully wrote event for AU health state:1
Successfully wrote event for AU health state:1
Report REPORT EVENT: {5BCEA64A-0FEB-4B01-9509-CE94AFE0D04A}
2015-03-20 21:19:59:003+0300 1
148 101
{00000000-0000-AutomaticUpdates Failure
Software Synchronization Windows Update Client failed to detect with error 0x80244019.
CWERReporter::HandleEvents - WER report upload completed with status 0x8
WER Report sent: 7.6.7600.320 0x80244019 00000000-0000-0000-0000-000000000000 Scan 101 Managed
Report CWERReporter finishing event handling. (00000000)
WARNING: GetConfig failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404
WARNING: PTError: 0x80244019
WARNING: GetConfig_WithRecovery failed: 0x80244019
WARNING: RefreshConfig failed: 0x80244019
WARNING: RefreshPTState failed: 0x80244019
WARNING: PTError: 0x80244019
WARNING: Reporter failed to upload events with hr = 80244019.
WARNING: GetConfig failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404
WARNING: PTError: 0x80244019
WARNING: GetConfig_WithRecovery failed: 0x80244019
WARNING: RefreshConfig failed: 0x80244019
WARNING: RefreshPTState failed: 0x80244019
WARNING: PTError: 0x80244019
WARNING: Reporter failed to upload events with hr = 80244019. -
Group Policy Pref - Mapped Drives Not Applying to One User
Hi All,
I’m new to this list, so please excuse any etiquette slip ups.
I have three users at a site. All their machines are running Windows XP Service Pack 3 and have client side extensions installed. I created a group policy to map their default drives using GP User Preferences.
Each of the drives is set to "update".
As an example of the policy created XML is as follows:
<Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="H:" status="H:"
image="2" changed="2009-11-25 05:13:58"
uid="{8A44D2F4-AAE5-4F43-AEEC-D36F08EA619C}" desc="Maps the users H drive to
ServerName\users$\%username%" bypassErrors="1"><Properties action="U"
thisDrive="NOCHANGE" allDrives="NOCHANGE" userName=""
path="\\ServerName\users$\%username%" label="Home (ServerName)"
persistent="1" useLetter="1" letter="H"/></Drive>
and
<Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="J:" status="J:"
image="0" changed="2009-11-30 03:52:58"
uid="{535CD462-A45D-4363-ADA1-2316D5ECC703}" desc="Maps J drive for users to
\\ServerName\apps" bypassErrors="1"><Properties action="C"
thisDrive="NOCHANGE" allDrives="NOCHANGE" userName=""
path="\\ServerName\Apps" label="Apps (ServerName)" persistent="1"
useLetter="1" letter="J"/></Drive>
The group policy is applied to an OU for that site.
All three users are in the same OU.
All three users are also in the same “xxsitecode Users” group.
2 of the users log into their pc and get the mapped drives with no issue, but one user doesn’t.
There are no other login scripts and the user has no manually mapped drives.
He does have a H drive mapped using the profile field in his AD object as a temp measure. But every 90 mins any other manually mapped drives are removed by the policy.
We don’t use roaming profiles
To trouble shoot I have tried
- Reinstalling client side extensions
- Re-joining the pc to the domain
- Running gpupdate from the command prompt to see if any event logs are generated (none are)
- Manually mapping the drives to make sure there is network access etc – I can manually map them/he can access them.
- Creating the user a new account, when he logs in using that account he gets his mapped drives on all PC’s
- Getting the user to log into a different pc, when he does this he doesn’t get his drives – so it’s not his machine or profile
- Manually checking the security on the user object in AD against one of the users who gets their drives mapped
I'm sure the GP is fine because it works for two other users and the testing isolates his user account as the issue.
The Policy I’m having issues with is xxxx Mapped Drives/ Printers
I have posted this issue on the tech net GP discussion groups page, but haven’t had any replies.
Any suggestions would be appreciated.
SimoneWhat's interesting is that I applied a new GP to users - it has one policy setting and one preferences setting. He only gets the policy setting.. aka he gets the wallpaper but not the homepage.
Also, Jorke asked me to post the gpresult /z .
Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001
Created On 10/02/2010 at 2:19:34 PM
RSOP results for DOMAIN\USER on MACHINENAME : Logging Mode
OS Type: Microsoft Windows XP Professional
OS Configuration: Member Workstation
OS Version: 5.1.2600
Domain Name: DOMAIN
Domain Type: Windows 2000
Site Name: SITECODE
Roaming Profile:
Local Profile: C:\Documents and Settings\USER.DOMAIN
Connected over a slow link?: No
COMPUTER SETTINGS
CN=MACHINENAME,OU=Laptops,OU=SITECODE,DC=DOMAIN,DC=com,DC=au
Last time Group Policy was applied: 10/02/2010 at 1:06:38 PM
Group Policy was applied from: XXXXXADC.DOMAIN.com.au
Group Policy slow link threshold: 500 kbps
Applied Group Policy Objects
Allow Remote Assistance
au-mdwsus
Default Domain Policy
Legal Notice
Proxy Settings
Logon as service, operating system
AU-WSUS
Desktop Background & Home Page
Reg Permissions for default desktop
Local Admin & Local Power Users
The following GPOs were not applied because they were filtered out
SITECODE Mapped Drives/ Printers
Filtering: Not Applied (Empty)
Local Group Policy
Filtering: Not Applied (Empty)
AVD Rollout
Filtering: Disabled (GPO)
The computer is a part of the following security groups:
BUILTIN\Administrators
Everyone
Debugger Users
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
MACHINENAME$
Domain Computers
CERTSVC_DCOM_ACCESS
Resultant Set Of Policies for Computer:
Software Installations
N/A
Startup Scripts
GPO: Desktop Background & Home Page
Name: image.bat
Parameters:
LastExecuted: 7:55:34 PM
Name: swiftdesktop.vbs
Parameters:
LastExecuted: 7:55:35 PM
Shutdown Scripts
N/A
Account Policies
Audit Policy
User Rights
Security Options
Event Log Settings
Restricted Groups
System Services
Registry Settings
File System Settings
Public Key Policies
N/A
Administrative Templates
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services
State: Enabled
GPO: AU-WSUS
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List
State: Enabled
GPO: AU-WSUS
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit
State: Enabled
GPO: AU-WSUS
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services
State: Enabled
GPO: au-mdwsus
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit
State: Enabled
GPO: au-mdwsus
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\CurrentVersion\Winlogon
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List
State: Enabled
GPO: AU-WSUS
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications
State: Enabled
GPO: AU-WSUS
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled
GPO: au-mdwsus
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services
State: Enabled
GPO: Desktop Background & Home Page
Setting: Software\Policies\Microsoft\Internet Explorer\Security
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services
State: Enabled
GPO: AU-WSUS
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled
GPO: AU-WSUS
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services
State: Enabled
GPO: AU-WSUS
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled
GPO: au-mdwsus
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled
GPO: AU-WSUS
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit
State: Enabled
GPO: au-mdwsus
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List
State: Enabled
GPO: Allow Remote Assistance
Setting: Software\policies\Microsoft\Windows NT\Terminal Services
State: Enabled
USER SETTINGS
CN=Matthew Luhrs,OU=Users,OU=SITECODE,DC=DOMAIN,DC=com,DC=au
Last time Group Policy was applied: 10/02/2010 at 1:54:53 PM
Group Policy was applied from: XXXXXADC.DOMAIN.com.au
Group Policy slow link threshold: 500 kbps
Applied Group Policy Objects
Allow Remote Assistance
**** SITECODE Mapped Drives/ Printers - has Gp Pref's that should apply
Default Domain Policy
Proxy Settings
**** Desktop Background & Home Page - has Gp Pref's that should apply
Local Admin & Local Power Users
The following GPOs were not applied because they were filtered out
AU-WSUS
Filtering: Not Applied (Empty)
Legal Notice
Filtering: Disabled (GPO)
Reg Permissions for default desktop
Filtering: Not Applied (Empty)
Logon as service, operating system
Filtering: Not Applied (Empty)
Local Group Policy
Filtering: Not Applied (Empty)
au-mdwsus
Filtering: Not Applied (Empty)
AVD Rollout
Filtering: Disabled (GPO)
The user is a part of the following security groups:
Domain Users
Everyone
Offer Remote Assistance Helpers
BUILTIN\Administrators
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
LOCAL
Computer Account Operators
Internet Users
SITECODE Users
DOMAIN-Public Folders Administrators
All Email Users
DOMAINSWIFTEMAIL
Domain Admins
Offer Remote Assistance Helpers
WSUS Administrators
DHCP Administrators
CERTSVC_DCOM_ACCESS
Resultant Set Of Policies for User:
Software Installations
N/A
Public Key Policies
N/A
Administrative Templates
N/A
Folder Redirection
N/A
Internet Explorer Browser User Interface
GPO: Proxy Settings
Large Animated Bitmap Name: N/A
Large Custom Logo Bitmap Name: N/A
Title BarText: N/A
UserAgent Text: N/A
Delete existing toolbar buttons: No
Internet Explorer Connection
HTTP Proxy Server: Proxy:port
Secure Proxy Server: Proxy:port
FTP Proxy Server: Proxy:port
Gopher Proxy Server: Proxy:port
Socks Proxy Server: Proxy:port
Auto Config Enable: Yes
Enable Proxy: Yes
Use same Proxy: Yes
Internet Explorer URLs
GPO: Proxy Settings
Home page URL: N/A
Search page URL: N/A
Online support page URL: N/A
Internet Explorer Security
Always Viewable Sites: N/A
Password Override Enabled: False
GPO: Proxy Settings
Import the current Content Ratings Settings: No
Import the current Security Zones Settings: No
Import current Authenticode Security Information: No
Enable trusted publisher lockdown: No
Internet Explorer Programs
GPO: Proxy Settings
Import the current Program Settings: No -
JNDI - rebind required after server restart
We are using a third party JMS Provider (we have to use this provider implementation as opposed to WLS Provider), which requires a JNDI implementation. We can use the Sun File JNDI implementation, but seeing as WLS is in the environment, binding the JNDI names into WLS seemed the natural thing to do. This works great, except that we have to bind after each server start up (as the WLS JNDI naming is not persistent across server restart).
I was wondering if anyone had any 'neat' tricks or ideas around this, aside from startup class.JMS has a ForeignJMSProvider config option to do this I believe. 9.0 will also support this more generally.
-
Windows Server 2012 GPO setting are not apply on windows Xp clients
Hi
I am create GPO on windows server 2012. 300 clients on domain are working fine, GPO setting apply on all windows 7, 8 clients. But 200 clients of windows XP are not working. GPO setting are not applies on XP. I am trying to Group Policy
Preference Client Side Extensions for Windows XP (KB943729) on one window XP client, all GPO servers 2012 setting is working fine. But is not solution. I have 200 clients of windows XP, Please provide batter solution on one click command and apply all 200
XP clients.
Thanks.Dear,
I have Windows server 2012 , i have install ADDS with Forest functional level 2008 & Domain functional level 2008 .
I have applied GPO to particular OU, when i login to domain user on Windows 7 PC all GPO working fine but when i login on Windows Xp SP3 PC its not applied on XP.
I am facing issue on windows XP clients it is true. Please see this URL address:
http://blogs.technet.com/b/grouppolicy/archive/2009/03/27/group-policy-preferences-not-applying-on-some-clients-client-side-extension-xmllite.aspx
Please provide batter solution on one click command
Thanks. -
Why WSUS installation on WS2012 R2 fails with message indicating server restart required?
Dear all,
I've trying to install WSUS server role on WS 2012 R2 standard. Server is domain joined, and local SQL server (SQL Server 2008 R2 with SP3) installed. This SQL server is to host the WSUS database.
WS 2012 R2 is fully patched. Nothing else is installed on this server except SQL server mentioned above. I initiate WSUS role installation, specify that WIS is not required, rather WSUS database is required, database connection to locally installed SQL server
is established; which succeeds without any problem, but when wizard starts WSUS role installation it continues to fail over and over. It indicates in server manager task view that role installation failed because the server require restart.
I restarted server several times, repeated the process but this continues to behave like this.
Why WSUS installation on server fails repeatedly?
Why log should be examined or any other dependency is missing here?
Please advise.
Regards,Hello Steven,
Thanks for the input, in fact I did mention server name to pick SQL server instance from, since the only instance configured is default instance locally on the server where I'm trying to install WSUS on.
When Add Roles/Features selection wizard gets to WSUS configuration; it asks for location where updates will be stored, next it asks to connect to SQL server to use for SUS database; that's where I specify local server's host name (in my case HQCAS) and
click "Check connection" this succeeds without any error.
All these steps proceed without any problem, but later on, WSUS role installation fails. I also checked CBS.log file; but it didn't give any specific clues? The only message I receive is that role installation requires server restart.
I reboot server; start all over, but the behavior remains the same. Since WSUS role did not get install in the first place, it won't be possible to check event viewer for WSUS related events. Moreover...wsusutil.exe tool will also be not available until
after successful install.
I couldn't reach any post deployment. Had a look at that link you forwarded, the
update mentioned in below area also doesn't apply since I specify the local server's host name and then click "Check connection". This steps goes without any error. Any other insight would be greatly appreciated.
Regards,
Shahzad
Maybe you are looking for
-
I have a new movie rental in my iTunes account on my Mac Book Pro but does not show up on Apple TV. All my other purchased movies are in there OK. Any suggestions?
-
Mount vhdx file from Windows Server Backup 2012
We have a 2012 server with a network share that other servers backup to using Windows Server Backup. To view the files from a windows 2008 r2 backup .vhd file all I have to do is open it in windows explorer and it mounts as a drive and opens. When
-
How do you use these packages?
I have the files cldc_1_0_src_palm_overlay.zip and cldc_1_0_src_winsol.zip, which I was told is required for running this code: import java.util.*; import javax.microedition.io.*; import java.io.*; import com.sun.kjava.*; import com.sun.cldc.io.palm.
-
Ihave bought songs from itunes, I synced my iphone to my computer, but now some of my songs are gone, also I'm trying to burn a disc
-
Dreamweaver Template use and Seo
Hi, I am using dreamweaver templates for my online java training website http://www.javatutoronline.com . My doubt is will using dreamweaver template positively or negatively affect seo for my website.