Quantcast
Channel: Group Policy forum
Viewing all 19997 articles
Browse latest View live

Windows 2003 and 2008 SNMP Settings via Group Policy

$
0
0

Can someone point me in the right direction on this?

I need set SNMP settings on about 3000+ servers with multiple community names and remove PUBLIC.

How can this be accomplished via a group policy? I have set the policy and PUBLIC seems to appear in the Community name along with the the 2 trap desitinations I have configured. In the SNMP security piece I do see the 2 communities I defined.

My process was this:

I set the snmp settings like I wanted on the server I was setting the policy on. I exported the registry keys for the configuration into the policy and it does apply. I then went into the Network/SNMP settings and set the community names there. But the community name PUBLIC seems to always appear.

I read in other posts that a custom ADM template may have to be made so it will set this correctly? Has someone successfully done this?


Group Policy Logon script continuously firing.

$
0
0

My Logon Script works the first time as expected, however I can see that it is going off again later on. I notice this because the script creates shortcuts on our users desktop, I deleted these on one of the computers (knowing it would come back on next login), however I see them again in about 30 minutes. Does the login script get reused after unlocking the computer, or after a certain amount of time? If so can I turn this off?

I use Group policy to use the login script and its a powershell script.

Import GPOs from domain 1 to domain 2

$
0
0

Hello all,

After many searches I don't find how to import all my 50s GPOs into my test domain.

I have a physical Dc in my production environment where I backuped without trouble all my GPOs into a folder, but in my test environment, i can't import them. I tried the Migration table way but I'm not able to make it work. I take all solutions and if you can provide me one where each GPO will be translated into another one GPO (I mean, not 1 GPO with all my parameters), then thank you in advance, that will help me a lot....

Martin


Apply GPO only at certain time of day

$
0
0

Is there a way to apply a GPO during a certain time of day and later on in the day have it de-apply itself?

Server 2008 R2

Thanks for any feedback.

How to create website shortcut on client computer in GPO

$
0
0

Hello,

I have developed a web-based system in our company and have published it in our intranet. Now I want to create a shortcut for this web system on users' desktops. How do I achive this using a Group Policy?

Regards

How AD RMS allow Office 2013 Standard to use RMS policy templates.

$
0
0
I have an issue for the AD RMS in Office 2013 Standard Edition. Is there any third party software that can allow Office 2013 Standard Edition to use the RMS policy template.

How to enable Clear Type Text Tuner in Windows 7 using GPO?

$
0
0

Hi,

I like to enable Clear Type Text Tuner feature in Windows 7 by default on AD users using GPO settings. Is there any settings in GPO (Windows Server 2008 R2 SP1) to achieve it?

Regards,
Zain Khan

Screen Saver Group Policy

$
0
0

Hi All,

We have got a request to implement the screen saver policy for a 100 Windows 7 Enterprise machines. The screen save provided by application contains Test.scr file.

I would like to know how to implement the screen saver GPO and can the test.scr file can be used?


Thanks HA


Deploying MSI to Core Server 2012R2 via GPO

$
0
0

I have a GPO that deploys an MSI and the first server it was tested on was a core Server2012R2. The GPO says there was no deployments in the Deployment Count under the settings tab. 

Can you deploy software via group policy to a core server? 


Charlie Newman

Domain controller does not synchronize with external NTP

$
0
0
Personally,I have avery strangeproblem on mydomain controller,WindowsServer 2012Portugueseversion ofBrazil.
The timeofsystemdelays 10 minutes, I have doneall settingsinW3Timeasmanytutorials on the Internet,the server simplydoes not synchronizeandif Ichange the timemanually,backto slowafter a while, is notCMOSproblem andnotfirewall ruleon UDP port123.

I installedthis programon the server, http://www.satsignal.eu/ntp/setup.htmlis running, but the serverkeepslatehours10minutes.

Any idea ?

Ivanildo Teixeira Galvão

Screensaver group policy odd behaviour

$
0
0

Hi, I hope someone can help as I'm really struggling to work out what is happening.

We have an existing group policy that sets the screensaver to come on after 5 minutes of inactivity, this works great. We have noticed that users don't lock their computers when they step away and therefore decided to set the Password protect screensaver option in group policy. This we set but it caused some backlash as users complained that it happened too soon, so we decided to extend the screensaver to 10 minutes. However screensaver still activates after 5 minutes. If i remove the Password Protect screensaver part of the policy it does wait the 10 minutes but as soon as that part is enabled it reverts to 5 minutes. As a test i disabled Prevent changing screensaver part so that i could actually see what settings it showed on the Screensaver options in Windows 7 and it shows correct. 10 minutes whether the password protect part is enabled or not.

Is this normal behaviour? Hope that makes sense and i hope someone can assist. I have done the usual of GPupdate /force and even full reboots but nothing seems to make the policy apply how i want it to.

Problem with Server 2008r2sp1 GPO GPP on a Windows 10 Pro Workstation.

$
0
0

Workstations:  Windows 7sp1 Pro, Windows 10 Pro

Server:  2008r2sp1 Domain Controller

I've created a GPO GPP to delete some files on the users desktop. The GPO is linked to the OU which contains all my users. Security Filtering is set to a group named "MasterCAM Users". The "MasterCAM Users" group contains my test user. The Preference is located in User Configuration\Preferences\Windows Settings\Files.

  • Action: Delete
  • Delete file(s): C:\Users\Public\Desktop\*mastercam x9*
  • Item Level Targeting:  <check>
  • the computer is a member of the Security Group DOMAIN\MasterCAM Workstations

When I log into a Windows 7 member of the "MasterCAM Workstations" group with my test user the files are deleted as expected. I tested this on 3 different Windows 7 machines, all worked fine. When I log into a Windows 10 member of the "MasterCAM Workstations" group nothing is deleted. I also tested this on 2 other Windows 10 workstations.

If I remove Item Level Targeting and log into the Windows 10 machine with my test user the files are deleted. If I set Item Level Targeting to check the Computer Name instead of Security Group the files are deleted. But whether I check user or computer membership of a Security Group no files are deleted. I have also double and triple checked the membership of both "MasterCAM Users" and "MasterCAM Workstation".

Group Policy Modeling shows that the GPO should be applied for the Windows 10 machine and my test users. Group Policy Results for the Windows 10 workstation and my test user shows the GPO in question under Applied GPOs on the Summary Tab. The Settings tab of Group Policy Results shows nothing for User Configuration\Preferences\Windows Settings\Files. If I run the same Group Policy Results Query on a Windows 7 machine with my test user the delete operation shows up under User Configuration. If I query the results for the Windows 10 machine and my test user after removing Item Level Targeting I see results under User Configuration\Preferences...

Did something change in Windows 10 that isn't working with a Server 2008r2 GPP files delete operation? Is there a bug? Am I doing something wrong?

Thanks for taking the time to read my question!


Albion


Security Issue

$
0
0

Hello all,

I think it's time to ask for help,

Here is the situation: we have a server that virtualises applications that users can then run through a 3rd party software installed on their machines to execute the virtualized software program.

in this virtualized software program there is an option to open folder, this folder opens a windows explorer window, that lets the user navigate through the server with his rights, i thought that i had found a way to prevent this from happening with GPO to hide the server drives and deny access to these drives, however i've found an issue, if the client connects to his own drive through network client/ or through librairies (on the server) he can create new folders etc, and more importantly, he can bybass a ton of security issues, just by creating a shortcut, to the same server\admin$ or server\c$, no password prompted nothing directly access to everything even though he is a simple user.

How can i secure this server? GPO are not applying to hide network/libraries through this virtualized app, however i'm sure they are being applied because when i connect through remote desktop with another user i have access to nothing.

if somehow i could prevent the user from creating new shortcuts,i could already stop him from bypassing security concerns

hope i was clear on what my problem is.


Internet Explorer settings not applying

$
0
0

Hi, this is my situation. Our DC is Win2008 SP2 x86 both Primary and Secondary. We have a requirement for all of our users. 

First is to add some list of websites to be excluded from pop-up, second is to add some sites in compatibility list.

So I added this sites in the following:

Computer Config>Admin Templates>Windows Comp>Internet Explorer>Pop-up allow list

User Config>Preferences>Control Panel Settings>Internet Settings>Internet Explorer 7

Not sure if I lack something but both of these policies are not applying in my network. 

Our IE version is 11.

Thanks

Jeff

"Switch User" is missing

$
0
0

Hey all,

I changed several group policy settings for the Default Domain in order to conform to the USGCB standards.

Some of the changes I made involved the Windows logon screen.

The PDC runs on Windows Server 2012 and the workstations all run Windows 7 Enterprise.

I enabled the "Always use classic logon" setting, enabled the "Do not display last user name" setting, and disabled "Do not require Ctrl+Alt+Del to logon" setting.

However, I received complaints from a few users that when a workstation is locked either purposely or due to inactivity, they must log in with the last user's credentials only.  There is no option to switch user or shut down, restart, etc.

My question is, could any other settings possibly have caused this? I did not configure the group policy setting that hides the Fast User Switching options, so I don't think that had anything to do with it.

All help is appreciated.  Thanks


How do they do it?

$
0
0
I've seen how you can use group policy, but how do administrators make group policy settings apply to all computers within a network or a member of a domain? Do they use Active Directory?

I am from PMC; planetminecraft.com/member/dr__steve You should join!

How to assign Policies to a server local group within a domain GPO?

$
0
0

Hi.

let me quickly draw the scenario. I have 10 servers. Each of them is a domain member and has a server local group (not a domain group!) called "technical users". Within this group I assign those domain service accounts that run services on that specific server.

How can I assign policies to this local group using a domain GPO?

Thanks for input

Sven

GPO Office 2010 & 2013 - Default .ost location

$
0
0

Hi everybody,

I have implement new policies for Outlook 2010 & 2013 clients to force .ost file to be kept on U: drive which is personal storage for each user.

I have downloaded administrative template from Microsoft website for both 2010 & 2013 and configured all the registry keys as per below:

Software\Policies\Microsoft\office\14.0\outlook\cached mode\cachedexchangemode 2
Software\Policies\Microsoft\office\14.0\outlook\cached mode\enable 1
Software\Policies\Microsoft\office\14.0\outlook\forceostpath U:\
Software\Policies\Microsoft\office\15.0\outlook\cached mode\cachedexchangemode 2
Software\Policies\Microsoft\office\15.0\outlook\cached mode\enable 1
Software\Policies\Microsoft\office\15.0\outlook\forceostpath U:\

Now, this setting will not force current Outlook profile to change the .ost file location, it will only affect the new profiles which are set up from scratch.

As we have a lot of users and computers, walking around each individual machines doesn't seem like an option.

Does anyone know on how to enforce current outlook profiles to change the .ost path as well?

All the best,













Group Policy Location

$
0
0

Hi!

Is it possible when we right click on a configured group policy settings under group policy management it should directly open that policy in Group Policy Management Editor?

Thanks.

Support and Compatibility of Group Policy Parameters configured on DC 2008 R2 for Windows Server 2012 R2 member server.

$
0
0

Hi All,

i'm working on a projet about GPO evolution to Windows Server 2012 R2 and i have a question about tools, methods and technicals skills for starting this project study.

the current environment is 4 DCs that running Windows Server 2008 R2.

We have only 8 GPOs with a multiple GP Parameters (110 configured /enabled parameters per GPO).

The goal is to study the compatibility of these 8 GPOs and their support on Windows Server 2012 R2.

These 8 GPOs will be exported and applied to WS 2012 R2 member servers.

I'would like to know the set of tools /methods to study the compatibility and support of these GPO on WS 2012 R2.

Thanks a lot in advance for your help.

i'll appreciate any help.

Thanks again.

Christianne.



Viewing all 19997 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>