Quantcast
Channel: Group Policy forum
Viewing all 19997 articles
Browse latest View live

Limit Group Policy to specific OS

$
0
0

Hi. I'm sure this is a common scenario, but I would like to hear the forum members opinion as to the best way to do this. I have a Domain (currently Server 2003 DC) consisting of Windows 7 and Windows 8.1 workstations. I've created a GPO to control what Windows 8 "modern" apps are available to users, using a PowerShell script. I only want it to run on Windows 8 machines, but I want it to be per user (in other words, I have it set in the user configurations). Do I put all those workstations into a separate OU and link the GPO there, or do I use a wmi filter?

Thanks!


Active Directory in Windows 8.1

$
0
0
I am trying to set up Active Directory on my home network, for the purpose of practice. I need assistance with how to go about this

Unable to apply .bat script on domain users using GPO

$
0
0

I created a batch file for message flash at shutdown and Log-off time and trying to apply at my Domain users. I tested in my Internal LAB(VM) and it's working fine but when i apply this policy to my AD then it's not working also not getting any error.

This is my batch file code.

@echo off
msg * Please turn off the UPS and other peripherals too.


I type in my email address to be sent an identity verification code but I keep getting nothing

$
0
0
I bought a new laptop and in the Settings and Accounts it tells me to verify my identity on this computer. So I follow the process and it says a code will be sent to my email address. However, nothing is sent to me! I've been doing this for 3 days now and still nothing! I'm absolutely outraged! Somehow, I added my cellphone number in the microsoft account and I got a text message with a 4-digit code. But it is not the code that the computer wants (it asks for a 7-digit code).

Access Denied Group Policy Object

$
0
0

hi

Cannot Create and Edit Group Policy Object

Error Access Denied Change Group Policy

NOTE 1 -  Access Denied Change Permission %SystemRoot%\Ntds

NOTE 2 - Permission SYSVOL   Full Control Group Administrator and Domain Admina and SYSTEM and Authentication

              ----- Read Folder SYSVOL Group : Domain Users - everyone

NOTE 3 - User Login Active Directory for change group policy with ****Administrator****

NOTE 4 - Windows is server 2012

NOTE 5 - End Update windows server 2012

Error (0x80070005) occurred saving settings file. Access is denied.

$
0
0

hi

Cannot Create and Edit Group Policy Object

Error Access Denied Change Group Policy

NOTE 1 -  Access Denied Change Permission %SystemRoot%\Ntds

NOTE 2 - Permission SYSVOL   Full Control Group Administrator and Domain Admina and SYSTEM and Authentication

              ----- Read Folder SYSVOL Group : Domain Users - everyone

NOTE 3 - User Login Active Directory for change group policy with ****Administrator****

NOTE 4 - Windows is server 2012

NOTE 5 - End Update windows server 2012

Email Address: abdi.mreaz@live.com

                        mr_abdi@live.com

Unable to edit my GPO's- Win. Server 2008

$
0
0

It is a while that I am not able to make any edits to my GP's in windows server 2008 . When I edit an object (for example: edit a Map drive) I get an a "blank error message" (bellow screenshot). there is nothing in the event viewer as well.

GPO apply user Logon script or GPP who Wins

$
0
0

hi

i have 2 GPO's linked to a OU1 GPO with precedence 1 has a GPP setting which applies a Value 

the 2nd GPO has a Logon script which applies a value that is different that the 1st GPO

How does Precedence take place if both have conflicting settings.

How can i have change Linkorder/Precedence so that GPO 1 always wins

Who Wins the battle between Logon Script for a setting or GPP for a setting 

Also 

None of these GPO's apply HKLM settings 

But even though i see following when i run ProcMon during User logon. Why is HKLM setting being set when user logon , is it not a computer logon thing

Operation - RegSetValue
Result - Success
Path - HKLM\SOFTWARE\MySoftware\Licensing\1\Server

Command Line "C:\Windows\regedit.exe" /s \\DC01\NETLOGON\ABC\License.reg


GPO to disableSSL3.0

$
0
0

I am going to create a GPO to disable SSL 3.0 using the following:

  • DisableSSL 3.0 andenableTLS1.0,TLS1.1,andTLS1.2forInternet ExplorerinGroupPolicy

YoucandisablesupportfortheSSL3.0protocolinInternetExplorerviaGroupPolicybymodifyingtheTurnOffEncryptionSupportGroupPolicyObject.

  1. OpenGroupPolicyManagement.
  2. Selectthegrouppolicyobjecttomodify,rightclickandselectEdit.
  3. IntheGroupPolicyManagementEditor,browsetothefollowingsetting:

ComputerConfiguration->AdministrativeTemplates->WindowsComponents->InternetExplorer->InternetControlPanel->AdvancedPage->Turnoffencryptionsupport

  1. Double-clicktheTurnoffEncryptionSupportsettingtoeditthesetting.
  2. ClickEnabled.
  3. IntheOptionswindow,changetheSecureProtocolcombinationssettingto"UseTLS1.0,TLS1.1,andTLS1.2".
    1. NoteItisimportanttocheckconsecutiveversions.Notselectingconsecutiveversions(e.g.checkingTLS1.0and1.2,butnotchecking1.1)couldresultinconnectionerrors.
  4. Click OK.

I am going to link the GPO to the OU where my computers are located.  My question is should I also link this GPO to the domain controllers OU?  Thanks.

How to set Internet limits to particular user by gpo ?

$
0
0
How to set Internet limits to particular user by gpo ?

Thanks & Regards, Amol . Amol Dhaygude

Best way to filter a GPO

$
0
0

Hi

I wonder if someone could advise on the best way to filter a GPO, mainly from a performance point of view.

The majority of our estate is Windows 7 currently, although we are going to start rolling out some Windows 8.1 devices and then probably following that Windows 10 for testing. We have a few pieces of software which we don't want to deploy to an OS above Windows 7.

I realise there are 2 ways I can achieve this, either Security Filtering or WMI filtering - which would be the recommended way with the least performance impact, a WMI filter or adding all Windows 8 machines to a Security Group and filtering on that until the balance tipped the other way?

Wmi filter which I was going to use is simply:

SELECT Version FROM Win32_OperatingSystem WHERE Version < "6.2"

Thanks in advance


Question about the shutdown /f command

$
0
0

Hello,

We monitor several Windows computers using software from a 3rd party vendor. (N-Able Technologies) Recently on our servers, we have observed that after some automated routines we would find that the "Unscheduled Shutdown" window was displayed after these routines.  After asking a few questions with N-Able, I found out that their Restart routine included the shutdown /f /r command to ensure that the shutdown is completed successfully.

My question would be the following:

Could this potentially be dangerous to any Servers that we may have with a SQL and/or Exchange database on them?  Would it possibly cause corruption if the databases are forced to stop?

We have Servers that range from 2003 to 2012 with the majority of them being SBS servers.

Thank you,

Jesse

Install MSI using Group Policy Management

$
0
0

Hi Friends

I'm trying to install my Outlook Plugin MSI using Group policy management. But Its not working for me. I get help from this URL.

https://www.youtube.com/watch?v=jXAz6vrWMP0

Is there anything additional I need to do to work this? In my client machine or server....?

Thanks

Bobbin

How to change user rights from admin to standard user?

$
0
0

Hi!

I am working in a city with around 400 users and all of them have admin rights on their local accounts. We want to change that to  user rights instead. I would like to know how to create a GPO that would make that change. I think the best way would be through GPO unless you have other ideas! 

Thank you for your help in advance!

Dag

Roaming profile & folder redirection

$
0
0

Hi 

I am facing challenges in applying Roaming profiles & folder redirection on Windows 2012 Remote desktop servers. I am planning to use it for VDI.

--------------------------------------------------------------------------------
Windows cannot locate the server copy of your roaming profile and is attempting to log you on with your local profile. Changes to the profile will not be copied to the server when you log off. This error may be caused by network problems or insufficient security rights.  DETAIL - The handle is invalid.
---------------------------------------------------------------------------------------------------

---------------------------------------------------------------------------------------------------

Failed to apply policy and redirect folder "RoamingAppData" to "\\Share\user2\AppData".
 Redirection options=0x1210.
 The following error occurred: "Can't create folder "\\Share\user2\AppData"".
 Error details: "Invalid Signature.
".


---------------------------------------------------------------------------------------------------

Thanks.


Adding newly added users to a security group

$
0
0
Is there a way to add new users automatically to a specific security group using group policy?

Office 2013 Administrative Templates & GPO

$
0
0

Hey, everyone!

I’m sure someone here will know what I’m doing wrong, so hopefully it’s something simple.

This is my first attempt to utilize Office 2013 Administrative Templates in a GPO. I downloaded the templates from Microsoft (http://www.microsoft.com/en-us/download/details.aspx?id=35554) and extracted them.

I then created a new GPO so that the policy folder was created in logonserver\sysvol\%userdnsdomain%\policies\Adm. In that folder, I copy the appropriate .admx files and the en-us folder.

Then, when I go to edit that GPO, I get an error:

The following error has occurred in \\Hudsonchapel.org\SysVol\Hudsonchapel.org\Policies\<GUID>\Adm\proj15.admx on line 1: Error 51 Unexpected keyword.
Found <?xml
Expected: CLASSCATEGORY, [strings]
The file can not be loaded.

This occurs for any .admx file I’ve tried.

I’m not sure what else to try. I’ve followed what I know to do.

Could someone help me figure out what I’m doing wrong?

Thanks!

-Eric

Bunch of errors in Windows Server 2008 R2

$
0
0

Hi everyone,
I've searched Technet and all the Internet for a clear solution or any clue that could help me solve this issue, but didn't manage.

Recently Windows Server 2008 R2 SP1 started to frequently and spit out bunch of errors that are connected to each other in my opinion, but I have no idea what is causing them and why they started to appear so suddenly.

Those errors are (ID):

TermDD (50, 56)

Group Policy (1058, 1080, 1006, 1079, 1110)

Schannel (36888)

Sometimes also

Distributed COM (10010) and NETLOGON (5719)

In first step I did the update of the servers and disabled chimney offloading, but it didn't solve the problem. I found couple of technet's articles describing SIMILAR problems, but I have no idea if they are describing exactly what I need.

http://support.microsoft.com/kb/2643970/en-us

http://support.microsoft.com/kb/2519736/en-us

Those servers are not our ones, but the other company that we are supporting. I'm also student and just started to gain experience with servers, so please mind that when providing any clue for which I will be extremely thankful.

why GPO software installation categories, does not appear on windows 7 program and features ?

$
0
0

hi all

why GPO software installation categories, does not appear on windows 7 program and features ?

Unable to update the password. The value provided for the new password does not meet the length, complexity, or history requirements of the domain

$
0
0

When i tried to change password then got this message"Unable to update the password. The value provided for the new password does not meet the length, complexity, or history requirements of the domain"

But i fulfill all requirements and try to change policy.But not work.


Thanks, Limon Dhaka,Bangladesh

Viewing all 19997 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>