Quantcast
Channel: Group Policy forum
Viewing all 19997 articles
Browse latest View live

GroupPolicy Event 1006 ErrorCode 49

$
0
0
Once a day or so I get the event id 1006 with error code 49 from the GroupPolicy client (Windows 8.1 and Server 2012 R2).

Event ID 1006 means "The processing of Group Policy failed. Windows could not authenticate to the Active Directory service on a domain controller. (LDAP Bind function call failed). Look in the details tab for error code and description."

And ErroCode 49 is "Invalid Credentials".

The account listed is sometimes the computers SYSTEM account and sometimes my useraccount. The same second or about a second after Event ID 1006 another Event is logged, ID 1500 or 1501 which means succesful processing of the Group Policy, again using the same useraccount.

Why does the client think my credentials are bad from time to time? Should I worry or is this just a "feature" to ignore?

Sharing Folder

$
0
0

Hi!

I am a Student in Israel in John Bryce institute.

i am now studying MCSE 2012R2 and i have some questions.

Let's point out a few things:

I have 2 DC's running 2012R2.

aprox 1400 users, 10 departments, two sites.

i need to share a folder, lets say "Documents", and i want it to be shared as Net drive per user. 

every user will see he's own "Documents" folder on "Z" Drive.

what is the best way to perform this action?

and i need one more drive "Y", to be per user but a folder that will be viewed to all users.

that means, two drives per user.

i've tried to do it via folder redirection, login script and gpo policy. 

i had more than a few issues with, so i am asking for your help.

Thank, Pavel.

Missing GP object "Public Key Policies"

$
0
0

I manage two domains (separate forests).  One, our DMZ, is fine.  The other, our primary domain, is missing the following group policy object:

Computer Configuration | Windows Settings | Security Settings | Public Key Policies

There are a lot of other contents in the "Security Settings" location, but the one I need is missing.  Both domains are running on (4) 2008 R2 domain controllers and at a 2008 R2 Functional Level.  I've tried running GPE from multiple machines (DCs and workstations) and it still is not shown.  I have Domain Admin rights as well so unless it needs Enterprise admin rights, that shouldn't be an issue.

Chris

Need Script -

$
0
0

Requirement: Need to update 3 exe file that i need to update from share folder to client desktop, laptop

@ c:\prgram files\XXXX\

I tried with vbs script via group policybut its updating very slow on client side.

24 location and each location have 1 2003 server Domain controller.

Need expert suggestion.

*this exe is allready in client side, due to latest update we have to push the latest update to all client

Hope i am clear, please write if require more information.

Piyush

Cannot install SQL Server 2005 Service Pack 2: Unable to install windows installer msi file

$
0
0

Here is the error message from the summary.txt file:

Product Installation Status
Product                   : Setup Support Files
Product Version (Previous): 2047
Product Version (Final)   :
Status                    : Failure
Log File                  : C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\LOG\Hotfix\Redist9_Hotfix_KB921896_SqlSupport.msi.log
Error Number              : 1260
Error Description         : MSP Error: 1260  Windows cannot open this program because it has been prevented by a software restriction policy. For more information, open Event Viewer or contact your system administrator.

I have already installed service pack 1 without issue and am not aware of any software restriction policies that have been put in place. I installed SQL Server 2005 recently with service pack 2 (on the same server) and did not come across this problem before so I am a bit confused.

Unknown Software Restriction Policy blocking Exchange Console

$
0
0

We are unable to launch the Exchange Management Shell for Exchange 2010 on Server 2008 R2 and the Exchange Management Console does not function because if depends on the Exchange Management Shell. When launching EMS it reports an error "File C:\Program Files\Microsoft\Exchange Server\V14\bin\RemoteExchange.ps1 cannot be loaded because its execution is blocked by software restriction policies." After enabling logging for Software Restriction Policies the SRP log reports "powershell.exe (PID = 22972) identified C:\Program Files\Microsoft\Exchange Server\V14\bin\RemoteExchange.ps1 as Disallowed using SRPv2 rule, Guid = {c71b5435-1293-4848-b0a3-b53066c76ca2}"

 

We are not currently using Software Restriction Policies. We have been unable to identify the source of the SRP that is blocking the Exchange Management Shell. A review of Local Security Policy, Local Group Policy and Domain Group Policies has not found any Software Restriction Policies. We have since created a Software Restriction Policies that specifies that all applications should be permitted and that Administrators should be exempt from SRP. The registry entries for "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer" and "HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows" only show the newly create policy that permits all applications. The Exchange Management Shell is still being blocked.

 

Further troubleshooting advice would be appreciated.

Best way to filter a GPO

$
0
0

Hi

I wonder if someone could advise on the best way to filter a GPO, mainly from a performance point of view.

The majority of our estate is Windows 7 currently, although we are going to start rolling out some Windows 8.1 devices and then probably following that Windows 10 for testing. We have a few pieces of software which we don't want to deploy to an OS above Windows 7.

I realise there are 2 ways I can achieve this, either Security Filtering or WMI filtering - which would be the recommended way with the least performance impact, a WMI filter or adding all Windows 8 machines to a Security Group and filtering on that until the balance tipped the other way?

Wmi filter which I was going to use is simply:

SELECT Version FROM Win32_OperatingSystem WHERE Version < "6.2"

Thanks in advance


Defragmentation via GPO

$
0
0

I have Server 2012 DC and clients are running on Win 8 and 8.1. I want to configure Disk DeFragmentation of clients via domain gpo. Is there any possible way to configure this.

Domain users don't have privilege to defragment disk. Can you recommend me how to schedule disk defragmentation through these domain users.

I will be glad to hear from you

Regards 

Akhil.B


HOW TO CREATE LOCAL USER PROFILE

$
0
0

SIR,

   OS            -    WINDOWS SERVER 2008 R2

   SYSTEM    -    IBM  MACHINE X3400 SERIES

    1. HOW TO CREATE A USER IN WINDOWS SERVER 2008 R2  WITHOUT ACTIVE DIRECTORY 

    2.  AFTER CREATE USER IN WINDOWS SERVER 2008 R2 BUT USER PROFILE NOT CREATE .

   

Group policy contains internet explorer maintenance and cannot access

$
0
0

Is it possible to remove the  internet explorer maintenance settings from an upgraded group policy.

We upgraded our active directory from Server 2008 functional level to server 2012 and now the settings are still applied by one policy, but I am unable to change or remove the settings in group policy editor. Is there a way to resolve this without deleting and recreating the entire policy?

GPO "Redirect Folders" and "Offline Folders"

$
0
0

Hello,

I have a problem with offline folders that don't synchronise automaticly. Here is my configuration :

  • Windows server 2012 R2 named "SERVER" domain "DOMAIN.COM"
  • Client : Windows 7 SP1 (with all updates)
  • GPO to redirect Desktop folders for all user in Z:\\SERVER\GROUP\%USERNAME%\DESKTOP

Everything is good when i am online, folders create on Desktop are on the server's folder.

When i open my session elsewhere and i create a folder on desktop, when latter i open my session on my domain, folders are not automaticly synchronize with share folder. I have to manualy synchronize doing a right clic on my network drive Z:

I've tried different option in GPO with slow connection but it doen't work.

Microsoft Security Updates

$
0
0

I would like to block a particular MS security update, KB3008923. How do I do that using GPO? Or is there a betting way?

Please help!!

Thank you,

Jason

UAC settings not applied for standard user

$
0
0

Hi- Windows 2012 R2 Server w/ 8.1 Enterprise workstations

I have created a GPO to manage UAC settings. However, the settings are only applied if the user logging in has Admin rights. I've tested this several times:

1) Adjust UAC settings in the GPO

2) Run gpupdate /force on workstation

3) Log in with account that has Admin rights

result: UAC settings are applied

1) Log in as standard domain user

result: settings are not applied


"Never, ever doubt what nobody is sure about." -Willy Wonka


Permission - User Profile

$
0
0

Hello Guys,

Is there any way to create a GPO that does not allow users to save and create files in their profile?

For machines with Windows XP I used the CACLS, but can not find a way to do it for machines with Windows 7

Thank you so much

Folder redirection problems

$
0
0

Hi, i have troubles with folder redirection option enabled on my windows xp and windows 7 workstations.

I put in GPO to redirect Documents and Desktop folders. Seems all ok but after we have network disconnects icons on desktop not appears and after workstation is online (again have LAN connection)   all icon is appearing but rearranged.

Hot to fix this any ideas?


Password Policy is not working

$
0
0

Hi,

we are trying to implement Pasword Policy on our clients.

it is windows 2008 active directory environment.

we changed Password policy settings on Default domain policy.

we disabled complexity setting and all the others.

we checked client with RSOP and confirmed that setting is updated on client.

but still when we try to change password on client, it warns as

The password does not meet the password policy requirements. Check the minimum password legth, password complexity and password history requirements."

Any idea.

Question about the shutdown /f command

$
0
0

Hello,

We monitor several Windows computers using software from a 3rd party vendor. (N-Able Technologies) Recently on our servers, we have observed that after some automated routines we would find that the "Unscheduled Shutdown" window was displayed after these routines.  After asking a few questions with N-Able, I found out that their Restart routine included the shutdown /f /r command to ensure that the shutdown is completed successfully.

My question would be the following:

Could this potentially be dangerous to any Servers that we may have with a SQL and/or Exchange database on them?  Would it possibly cause corruption if the databases are forced to stop?

We have Servers that range from 2003 to 2012 with the majority of them being SBS servers.

Thank you,

Jesse

Group Policy Preferences Files size limit

$
0
0

Hi

I am trying to use GPP to copy some files from a network share to desktops. All the files copy except one which I believe is due to file size, however I can't find any documentation to suggest that there should be a size limit on files that can be copied - does anyone know if this is the case?

For info I am running Server 2008R2, Windows 7 Pro and the file is around 8MB. I get the following error message: Group Policy object did not apply because it failed with error code '0x80070040 The specified network name is no longer available

If I use a file splitter and cut the file down to 4MB it copies, any bigger and it fails. Is this by design? Is there a way around it?

Thanks

Karl

Central Store ADMX/ADML Files MUI language

Central Store ADMX files update recommendation for Windows 8.1

$
0
0

I would like to update the "Central Store" with the latest ADMX file to support test computer with Windows 8.1 Update.
The network contains Windows 7 on production and some Windows 8.1 Update are on a test phase.

In the following KB article : http://support.microsoft.com/kb/2917033
Microsoft recommend that you keep the central store with the Windows 7 or Windows Server 2008 R2 ADMX templates
and use a Windows 8.1 like a GPMC console to manage GPO for Windows 8.1.

Why ?
Does anyone know the reason?
Is there any incompatible issue between ADMX file for Windows 7 and ADMX Files for Windows 8.1?


Regards,

-Misch-

Viewing all 19997 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>