Quantcast
Channel: Group Policy forum
Viewing all 19997 articles
Browse latest View live

Unable to edit existing Group Policy-The process cannot access the file because it is being used by another process

$
0
0

I have a domain at Forest Functional Level: Windows Server 2008 R2. Two domain controllers, both up to date with MS patches and both rebooted today.

I am trying to edit a Group Policy directly on the PDC emulator and I am getting this error:"The process cannot access the file because it is being used by another process"

I have followed this thread-> http: //social.technet.microsoft.com/Forums/windowsserver/en-US/6b49da66-5e51-43de-b774-eb824fb801cb/the-process-cannot-access-the-file-because-it-is-being-used-by-another-process?forum=winserverGP and the policy is already set to use any available domain controller.

We are using System Center Endpoint Protection and I have disabled Real-Time protection to test with no change.

I cannot seem to find a locked file using ProcessMon.exe, although that may just be my inability to use ProcessMon.

Using the AD Replication Status Tool I find no replication errors.

I think I have searched through the basics but I am getting nowhere. Where can I start looking next? Any tips?


Windows 8, set default application for example adobe reader, customize the start screen

$
0
0

I have two questions, Im going to deploy Windows 8 to our company, but have 2 big issues.

1) I need to customize the start screen, but cant find anywhere in the gpo´s? How can I do this without sysprepping etc (deploying with SCCM2012 SP1)
2) I need to set the default programs for adobe reader, mspaint etc, how can I do this? It doesnt work with the GPP and folder options, anyone have done this?

Thanks in advance

New Folder Redirection Group Policy is not working

$
0
0

Recently installed a new server on an older network:

Old network server: SBS 2003

New network server: Server 2012 STD

The network is working well and all computers are able to communicate with each other. I have already mapped a few network drives to folders that are located on the server. The owner wants to implement the same Folder Redirection of their Documents folder (Mixture of WIN7 PCs and WINXP) that their old server provided. I used the following Document to create the Folder Redirection:

http://technet.microsoft.com/en-us/library/jj649078.aspx

I then went to each computer and performed a gpupdate /force on each computer than logged off the profile. When I logged off, the sync window (folder redirection?) popped up and still showed that it was trying to transfer/sync with the old server that is no longer on the network. I also logged into the server and the shared folder that I selected for Folder Redirection does not have any data in it.

Is there something else that I am missing. Is there some sort of configuration on the clients themselves that I need to look for such as some Target Path?

I can provide more information upon request.

How can we implement WSUS Group Policy to Computers not on Users

$
0
0

Hi All,

How I can implement a WSUS patches update policy through Group Policy to all the computers. I don't want to implement to Users.

Thanks

Mukesh


Mukesh Bisht

The processing of Group Policy failed

$
0
0

Dear Support,

I am using windows server 2003 as our domain controller, and having 2 more ADC on branches,

we are already using GPO for our network, but when i try to do some changes it is not applied on win 7 and win 8,

when i try to do gpupdate /force , it is going me following error

---------------

C:\Users\xxxxxxxx>gpupdate /force
Updating Policy...

User policy could not be updated successfully. The following errors were encount
ered:

The processing of Group Policy failed. Windows attempted to read the file \\xxxxxx\SysVol\hqdom.dom\Policies\{1A63FDF6-582A-49C3-9CEF-945F6D50BAA4}\gpt.ini f
rom a domain controller and was not successful. Group Policy settings may not be
 applied until this event is resolved. This issue may be transient and could be
caused by one or more of the following:
a) Name Resolution/Network Connectivity to the current domain controller.
b) File Replication Service Latency (a file created on another domain controller
 has not replicated to the current domain controller).
c) The Distributed File System (DFS) client has been disabled.
Computer policy could not be updated successfully. The following errors were enc
ountered:

The processing of Group Policy failed. Windows attempted to read the file \\xxxxxx\SysVol\hqdom.dom\Policies\{1A63FDF6-582A-49C3-9CEF-945F6D50BAA4}\gpt.ini f
rom a domain controller and was not successful. Group Policy settings may not be
 applied until this event is resolved. This issue may be transient and could be
caused by one or more of the following:
a) Name Resolution/Network Connectivity to the current domain controller.
b) File Replication Service Latency (a file created on another domain controller
 has not replicated to the current domain controller).
c) The Distributed File System (DFS) client has been disabled.

To diagnose the failure, review the event log or run GPRESULT /H GPReport.html f
rom the command line to access information about Group Policy results.


Ali SJ -MCITP 2008-

Alternate way to copy .ini files to certain OU's.

$
0
0

Hello All

     I was wondering if there was an alternate way of copying an .ini file into certain OU's.  Current AD OU setup is:

                               Class
                                     --- Classroom1
                                     --- Classroom2
                                     --- Classroom3
                                     --- Classroom3
                               Students

     Student accounts of course are in the Student OU.  In each classroom OU's are the workstations computer objects.  A standard GPO with basic settings is under the Class OU.  There was two ways I could have done it.

      #1  Modify the standard GPO. Loopback policy enabled. The .ini file is copied via the user preferences with item targeting with the specific OU Classroom1 and Classroom2

      #2  Create a separate GPO for the .ini file let say "SOFTWARE1" GPO. Loopback policy enabled.  The .ini file is copied via the users preferences but with NO item targeting enabled.  The "SOFTWARE1" GPO is linked to Classroom 1 and Classroom2.

   I picked #1 and in my test environment had no problems.  Is there a better way that I am missing here?  Maybe I am over thinking things but not sure I should put 7 OU's in the item targeting section.  Note that I have no rights to the Students OU.  Any suggested would be appreciated.

Thanks

JohnH

Can I safely overwrite existing ADMX templates?

$
0
0

I recently changed the storage for ADMX files into sysvol\domain\Policies\PolicyDefinitions and downloaded Administrative Templates (.admx) for Windows 8.1 and Windows Server 2012 R2 fromhttp://www.microsoft.com/en-us/download/details.aspx?id=41193

Now I wonder if I can:

  • overwrite the existing ADMX templates with the new ones? Server is a 2008 Standard.
  • Will this affect Group Policies in use or work as before?

Thanks in advance.

change default reading order to right to left gpo

$
0
0

Hello

I am trying to display a message in my native language to clients but since the reading order is ( Arabic right to left) it shows the message in left ro right order. is there any way to change this via gpo?

Also the "legal Notice" is not work for me because of unicode characters.

Thank you


//policy1375.rssing.com/chan-5816113/article4169-live.html

$
0
0

Hi There,
Kindly let me know how to make a dialog box appears to insist that the user change the password When a user logs on to the desktop inside Domain with an account whose password has expired.

In our current AD environment when a users are logging in to their Desktops before the password is expired, it notifies to reset the password.

But in sitiuations where the password is already expired and they login after 2 or 3 days after the expiration, it does not allow the user to login and says your password is expired and the users will call the Internal service desk and gets their password reset done through AD.

Instead, We are looking for the option where the users who comes from vacation for example and their password is already expired and when they login to the desktop which is inside domain it should prompt the user with Current password, Change password, Confirm password screen.

Please help on the same.

GPO for Windows 8 users "Connect Automatically"?

$
0
0

Hello,

We have a number of Windows 8 and 8.1 tablets that use 3G to connect to our corp network.  We would like to make sure this connection has the "Connect Automatically" setting enabled.  I am using the Group Policy Manager on a Windows 2012 server and can't see that it can be changed, but does anyone know the registry path for this as I can then use the GPO to replace this setting?

I'm tried using procmon (real-time registry viewer tool) to see if it shows up what registry key is changed, but so much information comes in I can see what it might be.

Windows 2012 & 8.1 ADMX with Windows 7 System

$
0
0

Hello,

We are a Windows 2008R2 & Windows 7 Ent Shop with System Center 2012 R2 & PKI Servers.

We need to deploy 30 Windows 8.1 Enterprise Lenovo Tablets to the field.

Would all our Windows 7 GPO still work if we upgrade/update our Central Store with Windows 2012 & 8.1 Definitions?

Can any problem occur that we should be prepared for?

Thanks!


Event 4098 Group Policy Printers, Printers intermittently don't deploy

$
0
0
 Hi,

On a similar vein to this topic We also deploy printers Via the Server 2008 group policy preferences. All our PC's are Vista Business 32bit SP1. The problem we are having is that intermittently the printer will not install at logon. If you logoff and back on again it is there. On one particular PC I found this event in the Applications log.

Log Name:      Application
Source:        Group Policy Printers
Date:          13/01/2009 4:07:48 PM
Event ID:      4098
Task Category: (2)
Level:         Warning
Keywords:      Classic
User:          SYSTEM
Computer:      E-HSS.cygnet.library.uwa.edu.au
Description:
The user 'HSSClient1' preference item in the 'Client Vista Domain Policy SP1 {A85CA6F0-874B-467F-B50A-939E64932884}' Group Policy object did not apply because it failed with error code '0x80070709 The printer name is invalid.' This error was suppressed.
Event Xml:

  <System>
    <Provider Name="Group Policy Printers" />
    <EventID Qualifiers="34305">4098</EventID>
    <Level>3</Level>
    <Task>2</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2009-01-13T07:07:48.000Z" />
    <EventRecordID>37184</EventRecordID>
    <Channel>Application</Channel>
    <Computer>E-HSS.cygnet.library.uwa.edu.au</Computer>
    <Security UserID="S-1-5-18" />
 
Now if this error happened every time we would change the name of the printer to be something more "Valid" but it doesn't and we can logon again and the printer installs fine. Can someone explain to me why it thinks HSSClient1 is invalid intermittently?

From this thread I investigated the print processor of one of our printer queues and found is was not set to 'WinPrint' So on HSSClient1 I set the print processor to 'WinPrint'.  Do all printers managed/deployed by Group Policy preferences need to have their processor set to WinPrint?

Regards

Jason Langoulant
UWA Library I.T.

GPO - java update policy... its possible ?

$
0
0

Hi guys,




My users keep getting prompted to allow Java updates, but needs admin priviledges. Is there a way to allow that program to update without the users having to have me ok the update? I Have GPO - distribute JAVA, but i want GPO policy, which distribute new java updates for my domain users... 

Its possible or not ? 

Thank you.

Tom

Shared printers offline on VPN initialization

$
0
0


Network printer (deployed with group policy on shared printer) = OK

Network printer (manually added with IP) + VPN = OK

Network printer (manually added with share path) + VPN = OK

Network printer (deployed with group policy via share) + VPN = Printer Offline

Disconnecting VPN session = Printer back online

Restarting print spooler while VPN on = Printer back online

Tried editing the hosts file to associate IP with share

Set static route to bypass VPN connection 

VPN is not the default gateway

I’m having some trouble with Group Policy Preference Item Level Targeting for printers’ deployment

$
0
0

Hi there,

I have OU with all users and all Windows 8.1 computers. I have created new Company Printers GPO and link it to this OU. Some printers are common for everyone but other are not. Since all users are members of a different AD group…, it kind of make sense (in my case anyway) to target printers deployment based by AD group user belong to. From what I can see so far - all shared common printers have been successfully deployed, but all printers with “Item Level Targeting” (check if user belong to a particular AD group) are not present on clients’ machines?! What did I missed?!

Thank in advance


go daddy domain

$
0
0
  Hello and I need some help i have a go daddy domain name   and i want to bring it to my  web server  IIS.  i have IIS working as in connecting to localhost.  thats all i know please help. Thank you for your time in advance

Group Policy setting greyed out.

$
0
0

Hello Experts, We have 2 proxy servers 10.1.1.1. and 10.1.1.5 .I have applied proxy IP address as 10.1.1.1 in group Policy (Windows 2008) and all my clients are getting as 10.1.1.1 but users are able to change it to 10.1.1.5 (which is other proxy server). (How come some group policy settings are editable)

I applied other group policy of IE settings (as mentioned below) and it's greyed out.that's how it should work.



My Questions are:

1. Why some group policy IE settings are editable by users ?

2. If i want users to change the setting (Attached Image) what i need to do.?

3. All users are part of local admin group.

Thanks


Senior System Engineer.

Unable to edit existing Group Policy-The process cannot access the file because it is being used by another process

$
0
0

I have a domain at Forest Functional Level: Windows Server 2008 R2. Two domain controllers, both up to date with MS patches and both rebooted today.

I am trying to edit a Group Policy directly on the PDC emulator and I am getting this error:"The process cannot access the file because it is being used by another process"

I have followed this thread-> http: //social.technet.microsoft.com/Forums/windowsserver/en-US/6b49da66-5e51-43de-b774-eb824fb801cb/the-process-cannot-access-the-file-because-it-is-being-used-by-another-process?forum=winserverGP and the policy is already set to use any available domain controller.

We are using System Center Endpoint Protection and I have disabled Real-Time protection to test with no change.

I cannot seem to find a locked file using ProcessMon.exe, although that may just be my inability to use ProcessMon.

Using the AD Replication Status Tool I find no replication errors.

I think I have searched through the basics but I am getting nowhere. Where can I start looking next? Any tips?

group policy

$
0
0

hi all,

          i have a  PDC domain 2008 r2 & 20 systems are connected to it as client.

I have been trying to apply my company logo as desktop background to all users in domain & it is not at all working.

I have seen all possible ways like installing a hotfix,reading the answers in forums,etc...

It there anything else i have to install to make it work.

this will work only if the PDC is server 2000??

assume i have created a gpo for computers at OU level

$
0
0

assume i have created a gpo for computers at OU level so by default all authenticated users are selected after creating users so policy will apply to users during that time?


sccmghost@hotmail.com

Viewing all 19997 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>