Quantcast
Channel: Group Policy forum
Viewing all 19997 articles
Browse latest View live

GPO: enable win32 long paths

$
0
0

I tried asking this question in the normal Microsoft Answers Community, but since it is a local policy, they said to come over here...

I saw that the Windows 10 Anniversary Update was supposed to address the limitation of long file paths and names.  According to what I found, the new GPO entry of "enable NTFS long paths" was supposed to be added, but I didn't see it.  Upon further research, I did find the "enable win32 long paths" option one level up in the Local Policy Editor.

Question:  Was this setting supposed to address the problem?  After I enabled it, rebooted the computer and confirmed that the setting was still enabled, I tried to copy a directory (via File Explorer) from a local hard drive (G:\*.*) to a server share (\\SERVER\SHARE), but it failed for the same old reason that the pathname was too long.  Does this only work locally, or does it only work with specific capabilities, like PowerShell?


i need a GPO to enable photos, signature and link auto download for domain users only

$
0
0

hi

i need a GPO to enable photos, signature and link auto download for domain users only, FYI the junk filter is disabled 

thanks 

Advance Group Policy Management issue

$
0
0

We are running Windows Server 2012 R2 64 bit..  AGPM is version 4.2.22 after installing MS 16-072 KB3159398 and  MS 16-075 KB3161561 AGPM stopped working I can no longer get to change control folder.  AGPM service will not run.  I have removed these patches and Policies seem to be set correctly, however.  I cannot get to change control. When I try to open folder I get a MMC cannot initialize snappin.  Also log file has a config  error Failed to initialize Program files\Microsoft\AGPM\Server\AGPM.exe.config line 3 ...configuration schema error
 Also in an effort to fix issue I ran the following:

Get-GPO -All | Set-GPPermissions -TargetType Group -TargetName "Domain Computers" -PermissionLevel GpoRead

I get an Expection from HResult:0x80070005(E_ACCESSDENIED)

Upon further research I have found that on my Domain Controller policy guid the icacls is showing duplicate and different values for I have

 for 3 users with different permissions and on my member server policy guid I have one user with different permissions how do I remove the incorrect icacls


Windows 10 Quick Access links not syncing with folder redirection

$
0
0

Hello everybody,

This week I upgraded a couple of computers from windows 7 to windows 10.

In windows 7 you could synchronise the "favourites" links in explorer between workstation using folder redirection for the "links" folder of a user profile.

In windows 10 this, sadly, isn't working anymore.

Does anyone know how to fix this issue, or what the location is where the links for quick access are stored?

Best regards,

Olivier Smet

Enable .net3 / .net3.5 via group policy

$
0
0

We have DC on windows 2012 R2, and have clients of windows 7, 8, 8.1, 10, 2008, 2008 R2, 2012 & 2012 R2 in our domain.

We have a s/w deployed by GPO and is successfully deployed, BUT it requires .net framework 3/3.5 to run.

My que is how to deploy it to all m/c without going to it. Our users also don't have admin permissions on their computers.

i will make this gpo (http://www.askvg.com/fix-cant-install-microsoft-net-framework-3-5-in-windows-8-and-later/) to not to go to windows update source but how to turn windows feature on & off for .net via GPO


Thanks, Rishi Pandit.

User policy is not reflecting in few machine

$
0
0

Hello

I created GPP and configured user configuration and added some website as trusted and intranet.

now in few machine the website are not reflecting when i check in Interet tool> security> local intranet > site and same goes with trusted site

and now when i login to few other machine, it is obsolutly working fine, i can see the website in local intranet and turst site

Can anyone tell what could be possible cause.

Aamir


NA

File and Print Sharing - Network Discovery GP

$
0
0

Hello All,

Im trying to create GP to enable file and printer sharing and network discovery, i did create GP and configured the following:

- computer configuration\administrative templates\ network\ network connections\ windows firewall\ domain profile\ allow inbound file and print sharing ( enabled)

- computer configuration\administrative templates\ network\ link-layer topology discovery\ turn on mapper i/o ( enabled)

then i linked to test OU , i run GPRESULT /R and it was applied but in client computer it still off. Is there is another way to configure these policies on DOMAIN profile. 

Thank you


Applying Domain Group Policy to standalone workstation

$
0
0

Hi all,

Im needing to export a Domain GPO object to something i can then apply to a non-Domain joined PC. Does anyone have any experience in doing anything like this. I need to package the Policy up as something i can push out onto a client and have the settings extract out into the local registry.

Any Ideas ?



Will I be able to manage GPO from 2008 R2 or Windows 7 after updating Central Store to Windows 10 Templates

$
0
0

Good morning,
i want to support Windows 10 in a Server 2008 R2 AD Domain (no 2012 Servers yet).
Will i be able to manage GPOs using Windows 7 or 2008 R2 RSAT after updating the Central store to the new Windows 10 templates?
Could there be a coexistence in Managing W7 GPOs from W7/2008 RSAT and Managing W10 GPOs from W10 RSAT?
Best regards

KB3163912 breaks Point and Print Restrictions GPO settings

$
0
0

Our labs install our printers through a simple Start Menu\Programs\Startup VBS script that points to a printer depending on the machine name.  This saves anywhere from 1-5 minutes from our login times.

This morning after the new cumulative update KB3163912 all our lab machines are now prompting for admin credentials to install these print drivers.

I have changed the Point and Print Restrictions section of our GPO to both "disabled" and "enabled" but without server restrictions, and disabling elevation prompts.  Neither take any effect.

After removing KB3163912 the printers install fine without any prompts.

We can add our printers back to the typical GPO location for now, but no doubt we will receive complaints on our login times increasing.

GPResults show our group polices are processing fine on machines that are both pre and post KB3163912.

Microsoft Edge favorites and homepage group policy settings not applying

$
0
0

Hi Everyone,

I've been working on getting group policy ready for our organization's Windows 10 roll out later this year. For certain computers, we need to be able to direct the Edge homepage to our SharePoint site, as well as be able to push out "favorites" directly to Edge.

When I first began working on our group policy settings, I was able to use the Windows 10 group policy settings "Configure Corporate Home Pages" and "Configure Favorites" to push these settings to our computers, and for a while it worked just fine. 

I noticed a couple of weeks ago that for some reason Edge is no longer going to SharePoint, nor is it displaying any websites under "favorites", despite my specifying these settings in GP.

What's strange is if I run RSOP.MSC I can see that the machine is getting the Edge policies, however once I run Edge, none of the settings apply.

Today I also modified the setting "Turn off Password Manager" in Edge group policy settings, and that one applies perfectly fine. I can see it in RSOP.MSC, and when I go to Edge advanced settings, the option is greyed out. However even with this setting working correctly in the same Group Policy Object as the other 2, the only one that applies is the Password Manager policy.

Because this is a Computer Policy, I've tried specifying the computer name in the scope, but still nothing.

Any help is greatly appreciated at this point!

Thanks!

Default Domain Policy overiding custom GPO

$
0
0

Hi All,

I have been tasked with creating a new GPO and linking it to an existing OU, the problem is that both Default Domain Policy and my custom GPO have this setting applied, the setting is screen timeout. I won't bore you with the why, but basically on the custom GPO I need to have the screen saver timeout to be 20 minutes just for the OU it is linked to, the Default Domain Policy is set to timeout at 5 minutes.

Problem is that it would seem that the settings on the Default Domain Policy will override any other GPO with that setting applied, I just that setting to be changed and keep the other settings on the Default Domain Policy.

Please help....

.... Just to add would stop Default Domain Policy being enforced allow to my custom GPO to enact it settings, whilst the Default Domain Policy settings would apply, but no override my custom GPO settings.

Apply GPO

$
0
0

Hello ,

I have DHCP server with 2 scopes ( wireless scope & LAN Scope )

all my PCs can access the LAN and take ip address from DHCP Lan scope ( 192.168.2.x) or DHCP wireless scope (192.168.4.x)

all PCs take ip address from LAN scope it is register the ip address in the DNS so if the user disconnect from the LAN and connect to wireless it is take ip address fron wirelss scope so it will be not reachable by name cause his new ip address not register in the DNS and still the old one which taked from the LAN scope register in the DNS .

how can i solve this issue ?

my question in the above case which the pc register his ip address in the DNS with the LAN scope ip address but he actually has a new ip address from wirelss scope and he is not reachable by host name from AD if we try to ping the hostname , in this case can i deploy a package on all these PCs although they are not reachable by hostname ??????

Thanks


MCP MCSA MCSE MCT MCTS CCNA

Mapped drives not showing

$
0
0

Hello 

We use Group Policy Preferences to map a number of drives to our users. All was working fine but now not all are not showing in the Computer window. Some users will get a drive but other will not. 

Running a GPResult we see that the drives are getting mapped same if we run a RSOP.MCS. We have also looked through the Event Log on both the client and servers and again cannot find anything out of the ordinary. Last week we remade the GPO from scratch, went through all Share, NTFS settings and user group membership, still no luck. 

Any ideas would be fantastic as we are fast running out of ideas. 

Thank you 

Policy to set Site to Zone not working?

$
0
0

Hi,

Using Windows 7 Pro desktops with IE 11.  I have created a policy to set a number of policies for Internet Explorer, however, I'm not seeing that they are being implemented. 

When I perform a gpresult /r I don't see my policy listed.  I have the policy linked to the OU where my user object is located and Security Filtering contains a security group for which my user is a member, which is similar to other policies that are being applied correctly.

Digging further I found that under User Configuration | Preferences | Control Panel Settings | Internet Settings there is one entry for Internet Explorer 8.  Interestingly enough, when I log on to a computer that still has IE9 installed the policy is being implemented.  Guessing 9 must be close enough to 8 to allow this.

But when I right-click and say New, my options only include IE 5 and 6, 7 and 8.  Thinking this is filtering my policy how do I get IE 11 in the list to use?  Or if I simply remove the IE8 reference will it will work for all versions?

Thanks in advance,

Linn


Folder Redirection with Group Policy not working

$
0
0

I have followed the following guide to try and setup folder redirection with GPO but no matter what I do whenever the user logs in the folders always point to the local machine:

https://technet.microsoft.com/en-us/library/jj649078(v=ws.11).aspx

I have verified that the users can access the share i created I can manaully move the folders to that location. But no matter what I try I cannot get GPO to automatically apply the redirection.

I am running Server 2012 R2 with a Windows 10 Client.

GPO for USB Printer

$
0
0

Hi. I'm setting up a Windows Server 2012 with Active Directory to manage my network. Basically, I have some computers with USB Printers and all are Shared (\\PC-Name\printer). So in some devices, I need to always have some printer installed, because the devices and the printer are in the same room. Every time that I change the user, the printer is not installed, and I need to have installed for each user.

I'm thinking about to use the Computer Name to apply the GPO's and install the printer. 

It's a good way to do it? Can anyone tell me another solution? Maybe a way to do it local.

One Drive, how to stop syncing on Windows 2008 Server but not stop access to Sharepoint !!!

$
0
0

We are using a Xenapp on Windows 2008 R2 Server , but everytime a user logs in, a new profile is created (or sync) but onedrive.  We need this to be stopped, but still allow working access to Sharepoint.

How is this best achieved

GPO to avoid DNS-Registration in specific networks

$
0
0

Hello everybody,

I'd like to create a GPO to avoid that our Windows-Clients (Laptops) register their Wifi-IP in DNS.
Sure - It would be easy to remove the checkbox in Advanced IPv4-Settings via GPO, but that should only happen if the client is in a specific Wireless-network.

Is there a possibility to do this via GPO?

Regards
Miranda

Remote Session Limits GPO applied but not working

$
0
0

Hello all,

I have created and verified application of a GPO to limit disconnected or idle remote sessions to a specific period of time and then to disconnect them if this limit is reached. Although, after testing it numerous times, the GPO is not working. I created and html file using gpresult /scope computer and verified that the GPO is listed. In the scope of the GPMC, domain users, domain computers, and authenticated users is listed. The GPO is also built in User configuration AND Computer configuration. I have tried it just in user configuration but it did not work. I have not tried it alone in computer configuration yet as I wanted to see if anyone has any ideas. Thanks!

Edit: I also forced replication over all the DC and that does seem to be working as well.

-Tyler


Viewing all 19997 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>