Quantcast
Channel: Group Policy forum
Viewing all 19997 articles
Browse latest View live

startup folder

$
0
0

Hi everyone i need to copy an exe file into C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup folder, What are the ways to copy the exe file, if though script please help me with the script.


QoS GPO - can multiple application names be specified in the same policy?

$
0
0

When creating QoS policies using both GP Mgmt Console as well as local security policy, I can actually enter multiple application names, separated by coma in the "only applications with this executable name" field. I don't get an error. But my question is if this will work? I don't see anything about using multiple application names. I know the alternative is to create a separate policy for each application, but I'd prefer to avoid that if I can, for the sake of simplicity.

Thanks!

Unable to add service account to GPO so that SEPM can start

$
0
0

We recently moved our Symantec Endpoint Protection Manager to another server and I cannot for the life of me figure out how to add these three accounts to the Default Domain Policy:

NT SERVICE\semsrvNT SERVICE\semwebsrv, and
NT SERVICE\SQLANYs_sem5

I need to add them to the Log on as a Service policy but when I go to add them I get this error:

Please help.


Machine based group policy to change display setting

$
0
0

We have windows 2008R2 AD DS with more than 700+ Windows 7 client pc. And users can log on to any pc using their domain username/password.We have a special group of computers ( say 30) in a OU with dual monitors.And users log on to those computers need to configure mirrored (duplicate) display / extended display. But current Group policy settings restricts users to change display setting to any computers they log on.I know we can create a user based group policy and place users to that group to change display settings. but in this case they are able to change display settings not only those 30 computers but all computes in the company. I think machine based group policy need to be configured to allow changing display setting to those 30 computers regardless who logs on those 30 computers. I mean any one can log on those 30 computers should able to change dispaly setting. How best ways to do that?

Printer GPOs fail on some computers but work on others - error code 0x80070034

$
0
0

Hello, I have a couple of GPOs that roll our printers. They have been running smoothly for quite some time, then suddenly started giving our errors on our newer machines. Meaning, the GPOs will work fine on some clients but will not work on others. Also all other GPOs work fine on all clients. The clients are similar Lenovo Windows 7 64-bit machines.

This is the error: Event ID: 4098, Group Policy Printers. The computer '123.123.123.123' preference item in the 'Deploy printers - {3F6DE6D0-86DC-4D1F-AB99-81BC07F23F3C}' Group Policy object did not apply because it failed with error code '0x80070034 You were not connected because a duplicate name exists on the network. If joining a domain, go to System in Control Panel to change the computer name and try again. If joining a workgroup, choose another workgroup name.' This error was suppressed.

I turned every stone I could think of on the problematic machines but cannot find out a reason. I disabled anti-virus/firewall, I logged in as domain admin and I tried both user & computer GPOs. No luck. Notice that I can successfully connect manually to the Printer shares (the ones used to distribute the drivers).

Domain is Win2008 R2. The printers "live" on a Win2012 machine and the drivers come from there. I am using Group Policy Preferences. Ideas are welcome.

Thanks

Christos

Disable Start Menu and Desktop Icons in windows8.1 using Windows 2008 R2 server Group policy

$
0
0

Hi,

I have Domain controller windows 2008 R2. I want to configure a group policy to disable the start menu and desktop icons of a windows 8.1 client computer using group policy. Please help me how to do this.

group policy quetion- please help!

$
0
0

I have a (big) question regarding GROUP POLICY… I’m working on a class project and I’m still a novice with Windows Server 2012.

If anyone can help me with a basic chart or diagram to get me started it would be VERY helpful!!!! I’m pretty lost with group policy.

I have to create a network for a small company with a 1 domain controller, 1 Read Only domain controller, 1 other server, and a Client 8.1. The domain controller will have ADDS, DNS, DHCP and WDS. The Read only controller will have file and print services, DFS and IIS. The other server will also have File and Print Services, DFS and WSUS.The Client 8.1 will have RSAT tools..

 

I need to have 30 users and 30 computer accounts. One main user will be an IT admin named John Production. I need to have a base Organizational Unit called MyCompannyXX.

There needs to be 6 Global Security groups ( IT, Marketing,Finance, HR, Executives, and Future Branch)

There also needs to be 7 Organizational units called IT, Marketing, Finance, HR, Executives and Furture branch. All of these units need to be put inside an OU called Company groups.

 

I need to have a password policy for the IT users. All users need to get to a company website when IE is launched.

Only IT users can access the control panel

I need to create (any) 2 policies for users

 And 1 policy for IT users.

Also, the Group policy settings for WSUS need to be set for 3 groups: Computers, Member Serrvices and Domain controllers

THANK YOU!!!

EventID: 0xc0001b7e

$
0
0
EventID: 0xc0001b7e

Best Regard Mohammad Reza Abdi


Powershell GPO

$
0
0

I have set the execution policy in GPO to remoteSigned, and it is working fine, when I run the script from cmd prompt "powershell –f "

If I right click the script and choose “run with PowerShell” it starts with this text in red

Set-ExecutionPolicy : Windows PowerShell updated your execution policy successfully, but the setting is overridden by a policy defined at a more specific scope.  Due to the override, your shell will retain its current effective executionpolicy of RemoteSigned

The script is working, but it do not look right for a user of the script.

Sometimes when I run the script “run with PowerShell” it prompts the user to overwrite policy, again no matter if I choose yes or no, the script will run.

I am running on Windows 8.1 Update 1 x64, Powershell 4.0

Do anyone know how to fix?

Kind Regards

Jens


Jens Lund

Created Home folder via GP, but user can see other user folders

$
0
0

We went from adding a home folder for all users through the AD profile tab to using Group Policy.

Currently the GP will map the H: drive for users as \\server\user\%username%.

The issue we are running into is that if the user decides to go to \\server\user he is able to get into any other users folder unrestricted.

I've attempted to lock this down, but all my efforts so far also prevent the user from getting into his H: drive.

Is there a proper way to secure all the folders so the user only has access to his folder?

I want to try to avoid going back to creating the user folders via AD.

Unable to view settings tab in one GPO. "An error occurred while generating report: Object reference not set to an instance of an object."

$
0
0

I am the owner of this GPO and I can view the settings tab in any other GPO. But, I get the following message when I try to view the settings tab in one particular GPO:

An error occurred while generating report:
Object reference not set to an instance of an object.

Other posts I look at reference the same error, but with different circumstances, and thus, they specify that the hotfix is for to fix the error underthose circumstances.

I'm accessing GPMC on a Win 7 SP1 machine. DC is Server 2012 Standard.

"Run only specified windows applications" list blank in Edit mode

$
0
0
After upgrading to 2008 servers, the "Run only specified Windows applications" list is blank when I open a GP in edit mode to add a new exe. In settings view, all of the exe's are listed as they should be. If I run the 2003 version of group policy management on a 2003 machine, I can open the group policy in edit mode, and the exe's are there and I can add a new one. I cannot do this on a Server 2008 or Vista machine running the new version of the server admin tools. I checked the registry.pol file for the group policy, and the list is there, so I am sure that the data is there, but that list (as converted from server 2003 to 2008) appears to be incompatible with server 2008 and gpm (v. 6.0.0.1).

Any ideas? If I try to add a new one, it wipes the old list, and there is no import. I would rather now manually readd each entry.

Thanks.

Group policy access denied

$
0
0

Active directory windows server 2012

Permission Administrator (Full Access)

but Error Group policy access denied


Best Regard Mohammad Reza Abdi

Importar / Exportar Políticas de Grupo y Usuarios en Windows Server 2008 Standard

$
0
0

Buenas tardes a todos !

Me gustaría saber que herramientas existen para importar directivas de grupo e incluso usuarios de un server a otro.

Actualmente necesito levantar un par de servidores y sería muy interesante poder exportar directivas y usuarios de unos servidores a los nuevos.

Los que tengo actualmente son WS2008 Standard y los nuevos WS2008 Standard R2

Muchas gracias, feliz jueves y buen fin de semana !

David HJ


David

Hide Display Settings not applied in User GPO

$
0
0

Hello,

I am trying to hide the display settings via a GPO so folks can't change the resolution. I set the "Disable the Display Control Panel" setting to enable, but users can still go to the Control Panel and change the display settings. Other parts of the GPO are applying, like the Ctrl+Alt+Del settings. The GPO has the loopback function set to replace. From my understanding, that should force all user settings in that GPO on everyone who logs into the computer, whether they are in that OU or not. Some settings apply, just not the Display settings. Is there something else I have to enable to get that working?

Thanks


Jason Watkins MCSE, MCSA, MCDBA, CCNA


how to give delegation

$
0
0
how to give delegation like if I want set of users need to access GPO or need to access OU so how to provide access either GPO or OU (meaning they can manage all GPO assigned to specific OU)

need to add security group in individual GPO

$
0
0
How to provide access to GPO or OU meaning I need to offer GPO access for a security group so I need to add  security group in individual GPO if any automated way like power shell etc.

backup of GPO and restore

$
0
0
How to take backup of GPO and restore same with example

GPO saves as keep a copy, backup of GPO and copy paste existing GPO

$
0
0
If any difference GPO saves as keep a copy, backup of GPO and copy paste existing GPO

nk or apply a GPO to only security group

$
0
0
How to link or apply a GPO to only  security group instead of OU
Viewing all 19997 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>