Quantcast
Channel: Group Policy forum
Viewing all 19997 articles
Browse latest View live

8.1 drive mapping

$
0
0

Before upgrading to 8.1 from 8.0pro I managed to network an external drive to my pc for backup purposes. After upgrading to 8.1 however, I'm no longer able to access or network the drive. It is a Seagate goflex 3tb network drive.

In 8.0 I ran the Seagate software and mapped the drive using windows. from that point on I didn't need the Seagate program as I just pulled it up in explorer. Now that I installed 8.1 the procedure I used to map the drive no longer works. Can someone help me. TIA


OUTLOOK PST FILE LIMIT IS 1.93GB

$
0
0

Dear,

I am working as a Network administrator and i need to the Point answer of my question...

I have extract emails from Microsoft email server through Ex-Merge tool provided by Microsoft and the file size limitation is 1.93GB if i exceed this limit  i am assuming that if i Extract Emails just like 5GB .pst extension so why outlook not support after limitation file size is 1.93GB ..

Q-1  Why Microsoft limited 1.93GB

Q-2   How i can Increase this Limit

Thanks

Noor uz Zaman

Unable to edit

$
0
0

Hi,

What do steps do I need to take in order to enable the checkboxes in  "audit logon events properties" dialog under

Group Policy Project Editor \ Local Computer Policy \ Computer Configuration \ Windows Settings \ Security Settings \ Local Policy \ Audit Policy?

I have running Server 2008 64 bit with SP2. It is my third domain controller. 

Printer is deleted at Log Off

$
0
0

I have Win 2008r2 on an HP DL360 server. The server is used as a Micros BO Point of Sale Server. There are no remote or network users only two administrators who work directly at the server. There is USB printer connected directly to the server. Every time one of the 2 admins logs off the one and only/default printer "goes away" and must be re-installed at next log on. Any ideas where the problem may be?

Thank you

Home Drive Disappears / Is Not Mapped When Users Go Off Network

$
0
0

Hi Technet,

I've recently deployed Windows 7 Enterprise x64 in my environment and am seeing behavior that I don't understand and would like some clarification on.

I'm running Active Directory with a DFL of 2008 R2.  All users have a Home Folder mapped via the profile tab in Active Directory that connects to an SMB Share specific to their user account, for example:  \\bbcfileserver\users\johndoe

The issues that I'm seeing are best described as follows:

1 - If a user is on the network at the office, and then puts their laptop to sleep / shuts down and goes home (or to any other location), then wakes up their laptop - their mapped drive disappears completely when the computer wakes up and they log in.  It's not just there but disconnected  with a red x - it's totally gone.

2 - If a user is on the network and puts their laptop to sleep /shuts down and then logs back in later via cached credentials before their network adapter can initialize, their home drive is not mapped at all, and is not available until they wait for the network adapter to connect, log out, and log back in after connecting.

I understand in either case that the drive is not mapping because the user has no network connection - but my question is why it's simply not mapped and unavailable until they do connect to the network.  Is there a GP setting I can put in place to make it so the mapping is persistent?  Would using folder redirection accomplish this persistent mapping perhaps?  My users have VPN connectivity via third party software and often want to work remotely - but have issues with losing their home drive, and it's also troubling to have them log in and out multiple times at the office during the day just to gain access to their home drive.

Any clarification or suggestions on how I can make this better / easier would be greatly appreciated.

Thanks as always!

-Keith

can't edit default domain controllers policy on windows 8 or server 2012

$
0
0
I have found that I can't edit the "Default Domain Controllers Policy" from a Windows 8 or Server 2012 machine.  I can edit and save changes fine from a Windows 7 machine.  The domain controllers are running Windows 2012 Standard upgraded from Windows 2008 R2.  Is there a security setting I am missing?

Uninstall Lync 2010 client, Install Lync 2013 using Group Policy/VB/MS Customisation Tool

$
0
0

Hi, I am using Group Policy/vb/Lync customization tools to deploy 2013 and remove 2010. The machines have Office 2010. The vb script is as below:

Dim objShell 'As Object
Dim objFSO 'As FileSystemObject

'------------------------------------------------------------------------------'
'-- SET OBJECTS
'------------------------------------------------------------------------------'

Set objFSO = CreateObject("Scripting.FileSystemObject")
Set objShell = CreateObject("WScript.Shell")
strComputerName = objShell.ExpandEnvironmentStrings("%COMPUTERNAME%")
Dim WshNetwork : Set WshNetwork = WScript.CreateObject("WScript.Network")


objShell.Run """\\xxxxxxxxx - Do not Remove\Lync Install 2013 2010\Lync 2013 Outlook 2010\setup.exe"""

I have amended the OCT with relevant settings, Lync 2013 installs but Lync 2010 does not uninstall. Here is how i have it set:

In the Office Customization Tool - Set-up - Add Installation and Run Programs,

In target - pointing to the Lync2010 exe file (on above share)

In Arguments - /silent /uninstall

Is this correct?

Also, i would have thought that, Remove Previous Installations, it would have an option to remove Lync2010?

Anyway..pulling my hair out here!

Hope you can help.


Shared printers offline on VPN initialization

$
0
0


Network printer (deployed with group policy on shared printer) = OK

Network printer (manually added with IP) + VPN = OK

Network printer (manually added with share path) + VPN = OK

Network printer (deployed with group policy via share) + VPN = Printer Offline

Disconnecting VPN session = Printer back online

Restarting print spooler while VPN on = Printer back online

Tried editing the hosts file to associate IP with share

Set static route to bypass VPN connection 

VPN is not the default gateway


Compatibility View settings missing

$
0
0

Windows Server 2008 R2

Trying to force certain websites to show in compatibility view for clients running Windows 7 with either IE 9 or IE 10. The Group Policy setting is:Computer or User Configuration-> Policies-> Administrative Templates-> Windows Components ->Internet Explorer -> Compatibility View.

However, the "Compatibility View" folder does not exist. How can I fix this? Thanks.

Group Policy and shortcuts

$
0
0
ok imagine there is a company "x" that has a group policy which allows certain softwares to be executed  . In one department of this company , employs uses a certain program called "y" . One employ create a shortcut of this program on the desktop and when he tries to open it , a error message comes out which tell him that a policy which allows certain softwares is in use . Can someone explain to me what happened ? I know the group policy which allows certain softwares is in use but if he can use the program why he cant use the shortcut ? :/ 

Grace Period before I turn on fine-grained password policy? How to implement both?

$
0
0

I work in a company that users haven't had to change passwords for at least 8 years. We're about to turn on a fine grained password policy modeled after http://akrameleyan.wordpress.com/2013/01/06/why-and-how-to-use-fine-grained-password-policies/ and I am hesitant to do so because there will be no warning and all the users passwords that are older than a year will automatically expire.

I have a PowerShell script that emails users 30 days before their password expires and gives them directions to change their passwords - but this obviously won't work the first time the policy is turned on. I would like to turn on the password policy but make it not take effect for 15 days as a grace period and to have our PowerShell script kick off emails to help them change password.

What am I missing here?

GPO for Folder Redirection to HomePath fails

$
0
0

For all of our Students, we have setup their Home Folder to 

   Map Drive [ S ] to ....... \\File-SRV\FSStudentsHome$\GradeYear\StudentID

Example: So for a Student ID [7890] who will graduate in 2015, his home path will be:

   \\File-SRV\FSStudentsHome$\2015\7890

We have Windows 2008 R2 DC and I have created a GPO for Folder Redirection

   User Configuration -> Policies -> Windows Settings -> Documents

I have tried the [Basic - Redirect]  and set the Target to [Redirect to the User's Home Directory] ... Didn't work

Then set the Target to [Redirect to the following location] ......

   Set Root Path -> \\File-SRV\FSStudentsHome$\%homepath%Documents   ..... Didn't work

Each time I log as Student [7890] to the computer [Win7] under the OU linked to the above GPO and do a gpupdate /force

In the Event Viewer, I get the following Folder Redirection error

   Event ID 502

   Failed to apply policy and redirect folder "Documents" to "\\File-SRV\FSStudentsHome$\2015\7890"

   Redirecton options = 0x1211

   The following error occurred: "Can not create folder "\\File-SRV\FSStudentsHome$\2015\7890"

   Error details" "this security may not be assigned as the owner of this object."

Any ideas how to troubleshoot that issue ???

Thanks,

Reda

GPO to add Korean Language to Computers in OU

$
0
0

We have  30 computers in a School Lab that need Korean Language installed ...

How can we create a GPO that will push the Korean Language so the Students can toggle between EN & KR ???

Appreciate your help ...

Thanks,

Can I force Windows Update to "receive updates for windows and other products" using group a policy?

$
0
0

I would like to force Windows Update to "receive updates for windows and other products" using group a policy. Is that possible?

I am not using WSUS.

I would like the policy to apply to Win7 / 2008 R2 and newer.

Alternately: Is there another way in which I might force this?

RSOP access deny - Windows 2003

$
0
0
Hi all,

     I have configured a GP for System Services. I linked this GP fro a specific OU only. the system in that OU has successfulyl applied the GP settings with no errors, but when I run gpresult or RSOP.msc the error is Access denied. the actual error displayed is give below,

GPRESULT:

ERROR: Logon Failure: Uknown user name or Bad password

RSOP.msc:

Group Policy Error: You do not have permission to perform this operation

In event viewer when I run GPUPDATE the operation was succeeded;

"Security policy in the Group policy objects has been applied successfully" Event id: 1704

following this event there were 1 other error event;

"Windows couldn't log the RSoP (Resultant Set of Policies) session status. An attempt to connect to WMI failed. No more RSoP logging will be done for this application of policy." Event id: 1090

Can anyone help me to resolve this. I know I am missing on security permissions, but what is it and wht I was missing?

Regards
Hari Vidya Sankar

GPO for firewall inbound connections still allows change from "Block (Default)" to "Block all connections"

$
0
0

Hello,

I found an interesting issue where I set a GPO to control the firewall policy to "Block (default)" the inbound connections, however that setting is not completely enforced. It still allows an administrator to alter it from "Block (default)" to "Block all connections". Why is the GPO not forcing the setting I provided?

In more detail:

The settings i'm referring to are in:

  1. Go to Windows Advanced Firewall
  2. Right click on properties
  3. Under any profile tab, in my case Doman Profile
  4. State > Inbound Connections

The GPO is set explicitly to "Block (default)", however this option can still be changed once the GPO is applied.

GPO Setting:

GPO result on server where the policy is applied:

Thanks,

Paul

%username% and %LogonUser% variables not working for shortcut

$
0
0
So here is my issue really basic. We don't have a logon script. We map drives via GPO. When users connect to our network via VPN they need a way to access our shares easily. We have a GPO that places shortcuts on their desktop. One is \\servername\public and the other is for their user drive which is \\servername\userdata\username. However the user share won't work if I use %username% or if I use %LogonUser% such as \\servername\userdata\%username%.

Automatic Timeout GP not working

$
0
0

Hi All,

I have an issue with a wkst where a GP is not applying even though it is showing when you run the gpresult.

The gpupdate is not showing any error message, the workstation is in the right OU and the GP applies to all the other computers successfully.

Tried to log in with domain admin, local admin and regular user but still not working.

Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft
Corporation.  All rights reserved.

C:\Users\****>gpupdate
/target:user
Updating Policy...

User Policy update has
completed successfully.


C:\Users\****>gpupdate
/target:computer
Updating Policy...

Computer Policy update
has completed successfully.

Result of the gpresult

C:\Users\****>gpresult/r  /scope:computer

Applied Group Policy Objects
    -----------------------------
       
Windows SBS Client - Windows Vista Policy
        Windows SBS Client
Policy
        DCentral Agent Install
        Workstation Auto
Lock
        Default Domain Policy
        Update Services Client
Computers Policy
        Update Services Common Settings Policy
       
Workstation Auto Lock

Any idea ? 

Why there is only "New folder" option when I right click on "Windows\System32" folder ?

$
0
0

Hi,

someone can explain me why when I right click on some specific folders, I only have the right to create new folder but not to create new document or new text file ? 

Is there a way to add more options when I right click on those folders ?

Thank you

Is there a way to save the default or last user account on UAC prompt ?

$
0
0

Hello

I have UAC enabled and configured to prompt when I need to elevate my privileges.

I would like to know if there is a way to save a specific login (or the last one) ?

Indeed, I am logged with a no admin account and so I am prompted quite often to enter my admin and password account; so it should be nice if the login will already be filled.

Thank you

Viewing all 19997 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>