Quantcast
Channel: Group Policy forum
Viewing all 19997 articles
Browse latest View live

Group Policy to Set Lock Screen Image for Windows 10

$
0
0

I have set up a Group Policy to set the Lock Screen image to a defined image located on the C:\users\public\pictures\

There is also a registry key to change the lock screen image location.

I have also made it so that they can't change the Lock Screen.

I have installed the relevant Admx for windows 10 on the server and updated the group policy.

Some computers, when a gpupdate /force is done the lock screen does not change.

does anyone have any idea on how to get the lock screen changed via group policy?

Thanks


Henry Edwards


Printer Group Policy is deploying printers but printers will not print

$
0
0

Any ideas on this?

Printer server is an 08 R2. Client macines are running win 7. Printers are deploying via the gpo (computer config > preferences) however when the client attempts to print with a deployed printer the machine appears to queue the job locally and it simply is not hitting the print server.

this gpo was cloned from another printer gpo that is known to be good and working in a similar environment but a different location.

I'm hoping I'm just over looking something simple cause I've racked my brains on this.

Thank you!

GPO to remove “NT authority authenticated and NT authority interactive” groups members from all local computer users group.

$
0
0

I am looking for a  GPO to remove “NT authority authenticated and NT authority interactive” groups members from all local computer users group.

Thanks in advance for your help.

Folder redirection 2012 R2 Domain not working.

$
0
0

I have created a new 2012 R2 Domain. I have followed all the steps in this article  https://technet.microsoft.com/en-us/library/jj649078(v=ws.11).aspx to setup folder redirection for the domain users documents folders only. I am using Windows 10 1607 for the domain joined client and a user account I created to test but the documents folder is not redirected. I have given read only permissions to the Domain Computers in the GPO as suggested.

I have also read of these fixes none of which seem to work.

https://social.technet.microsoft.com/Forums/en-US/62f8eb91-1978-46ea-b521-a02d79072820/folder-redirection-gpo-not-working-on-windows-10-client?forum=win10itprogeneral 

I will update this question with more detailed information shortly.

Thanks for any help you might give.

Janpaul

GPO Assigned Applications not Deploying. GPO shows in GPRESULT but MSI not in GPRESULT /H

$
0
0

I have tried deploying an MSI at a client but the MSI is not picked up on the client or deployed. The GPO is applied but when running a gpresult /h the MSI is not present.

Other GPOs are applying OK and I have created a new GPO with other non Software Deployment settings and applied fine.

I have checked/tried:

  • Checked DCDIAG on DC (single DC domain) and OK. Confirmed nothing in FRS or any other obvious issues.
  • Checked DNS for any old DC entries (recent DC move from SBS).
  • Created a new share confirming permissions fine (Auth Users) and tried deploying in a new GPO from there.
  • Checked connectivity from the PC all OK.
  • Enabled Gpsvc.log and again can see it see the GPO but nothing else.

Nothing is logged for the application deployment in the System, Application or Group Policy logs on the PC Im testing from (this is not working for all PCs at the site though).

Is there some further logging I can check or enable to troubleshoot further?


Why I couldn't get MVP

$
0
0

Hi. so many times I have answered in forums. Uploaded few contributions and Scripting codes. Made changes on some wiki articles. Last year tried to nominate myself as MVP and nothing has changed. I would like to ask, do I need to prepare video lessons to get MVP or to answer in forums enough for nomination? Since I have started to answer on some questions I didn't receive any MVP status. Although I know some other colleagues has got MVP 3-4 times. And from their activity I see that they only have answered few questions and prepared 1-2 videos.  Again I would like to ask "DO ALSO I NEED TO PREPARE VIDEO LESSON or LESSONS TO GET MVP" or ONLY FORUM ACTIVITY ENOUGH?

Thanks.


-----------------------------------------------------------------

Sincerely!

Khalid Garayev

* Please don't forget to mark as answer or Vote if it helps!

VPN GPO

$
0
0
We have a PPTP VPN with a shared secret (this was already in place when i arrived here) that terminates to a meraki. We use Windows 10 pro only on campus. I created a GPO for this VPN and it DOES process on the specified users computers. The problem is, i don't see where to enter the shared secret in the VPN GPO. Is it possible?

Enable Modern Authentication through Group Policy

$
0
0

Hey all,

Is it possible to enable modern auth via GPO for Office 2013 rather than manual registry changes?

Thanks!


GPO - Automatic Browser Configuration - Apply button is greyed out

$
0
0

I'm trying to apply a new proxy and it didn't work.  Went back after messing with some other configs and modified the proxy slightly and then noticed the Apply button was greyed out.  I have no idea why...

If anyone has an idea, I'm all ears...

Thanks, 

R

Movie Maker GPO

$
0
0
Server 2012 R2 and we are education. We need to deploy movie maker to a computer lab where no user has admin rights except the local admin and domain admin(s). I have the live essentials movie maker msi, created a distribution point and made the GPO. I login as a domain admin and movie maker does not get installed. I have run gpupdate /force on the server and the client. The GPO is assigned and checked to install at logon time. The GPO is also configured in user configuration->policies->software settings. The security group assigned to this GPO has computers not users assigned to it. Should this be computer configuration instead of user configuration?

Problem with inetres.admx

$
0
0

Suddenly when opening Group policy manager and checking group policy settings, i get this:

Resource '$(string.SUPPORTED_IE11WIN8)' referenced in attribute displayName could not be found. File C:\Windows\PolicyDefinitions\inetres.admx, line 184, column 87

I tried copying same file (dated 14.11.2015) from another server > no change. Then downloaded newer version (dated 3.8.2016) and got this:

Resource '$(string.SUPPORTED_IE9_IE11NONWIN10)' referenced in attribute displayName could not be found. File C:\Windows\PolicyDefinitions\inetres.admx, line 162, column 103

Nothing GP related has been changed in weeks and old template has not given any errors before this.  Similar errors before were fixed with replacing file with another copy or updating to newer version. Server is 2008R2 std sp1

Any ideas what to try next?

Windows Updates corrupt PST files on Roaming Profiles

$
0
0
Hi guys!

I am having troubles with Windows Updates and roaming profiles...

I tunned the GPO "Exclude directories in roaming profile" to force sync "AppData\Local" This way I backup the Outlook pst files from "AppData\Local\Microsoft\Outlook"

This has been working great for a long time, because Windows update were manually installed on each PC with a local admin user (no roaming user).

But now I enable some Windows Updates GPO to force do it automatically meanwhile the user is logged on:
GPO: Configure Automatic Updates Value -> 4 = Automatically download updates and install them on the schedule specified below.

Then, a warning comes up to the users asking reboot to finish the updates... as usual.

User click on reboot
or
Do nothing and then turn of his computer at end workday

On both cases, the pst is corrupted.

I am sure that is a timeout issue... for some reason, Windows updates brake pst sync on shutdown (or reboot) and let it corrupted.

Nothing relevant showed on Windows Event. Not even following this steps to enable debug events https://technet.microsoft.com/en-us/library/jj649075(v=ws.11).aspx

On Event Viewer\Applications ands Services Logs\Microsoft\Windows\User Profile Service\
Operational: Event 7, Succesfully profile sync
Diagnostics: Nothing relevant.. only a few events 1001 and 1002 (Can't find ID event)

If set Windows updates to: 3 = (Default setting) Download the updates automatically and notify when they are ready to be installed , pst sync ok.

This only happens on the headqarter... at headoffice work ok...and this is the reasson:

HeadOffice: Server home place -> LAN 1GB
HeadQuarter: use headoffice server -> WAN link to HeadOffice FO 10MB

So... users on HeadOffice syn at 1GB and users on Headquarter sync at 10MB.

I think that should change the Windows Updates behavior at logoff...but no idea how can I do it.

Hopefully you can help me!

GPO Remotly

$
0
0

Hi Guys ,

I have an question as you know i have 2 domain controller one of them is 2003 R2 and other one is 2008  i want know how to make group policy forced throw command line ?

GPO not applying but present in modeling

$
0
0

Hello,

Since few weeks, we have missing GPO. 

When i use gpresult /r or /h file.htm i not find somes GPO.

When i make GPO modeling, i saw my GPO (in modeling i use my account, my computer account, my site and my DC).

I did not find where is the issue. In eventvwr i saw nothing. (on my computer)

I think my GPO is not deployed by my DC. There is anything for view which gpo is deployed from my DC to my computer ?

regards

Account GP not applied

$
0
0

I try to apply lock account policy, the policy appears on the client policies but unfortunately its not applied. Even after entering 100 wrong password, the user account dose not locked. How to solve this?


Scheduled Task not showing up in task list on Windows 10

$
0
0

I created a Computer Preference Scheduled Task. I have it applied to 3 computers, One is Windows 7 and the other two are Windows 10. On the Windows 7 PC, I see the task in the scheduled task list. On the Windows 10 PCs it is not there. I know the policy is being applied because I can see it with a gpresult /r.

What gives?

Client background jpg not always what is in Group Policy

$
0
0

Hello, I've got an odd problem. I've got about 100 computers in this location. I would like all our users backgrounds to be the same, with the option of me being able to change the background every once in a while.

I started out by having a jpg in a shared location (Access: Everyone R/W). It worked, the background was displayed. However, when we changed the background file, the clients would not update to the latest version. Understandable since Windows shouldn't be constantly watching that file. Soon, some computers would receive the latest version, after a reboot. Others, would never receive the latest background.

At this point, I changed the GPO so that the File would download to %USERPROFILE%\Background.jpg (Using File preferences, action Replace). Then changed it so that the Desktop wallpaper location was %USERPROFILE%\Background.jpg. Again, I would get the same results as above, some would change, others would not. (Even after multiple reboots, the file in %UP% was the correct one, but the background was the old one.

Finally, I decided to run a 'remove_bg' powershell script

Remove-Item $env:APPDATA\Microsoft\Windows\Themes\TranscodedWallpaper -recurse

This script was run on Logoff. SAME RESULTS! I'm pulling my hair out with this one.

Usually, I can get the correct background, running gpupdate /force, and then multiple reboots (usually 2 or 3).

What's really odd, is that most of the time, if I right click desktop -> Personalize, the thumbnail is the correct image, but the actual desktop background is incorrect. All clients are Windows 10 Pro v1607, Server is 2012 R2

My latest gpo:


Some feautures are controlled by your organisation, but I am my organisation

$
0
0

Hello,

I'm a home user of windows 10

since the installation of anti virus software (big mistake, use defender now and thats enough) the computer tells me that of the funtions regarding safety are controlled by my organisation....

I am my organisation. And i don't have a clue....

Is my computer now controlled by somebody else?

And how do i get it to turn back to the way it was? Don't understand what to do 

Restricted Group issue on Win7 / Server 2008R2 AD .. odd one

$
0
0

Have created a GPO that restricts the Administrators Group, linked it to an OU. GPO is enabled, enforced and at the bottom of the list of group policies.

If I add a user to a restricted group on the local machine and reboot, reboot often, wait hours, the user remains in the restricted group. HOWEVER if I do GPUPDATE /FORCE the account is removed immediately.  I cant see that there would be something wrong with the GPO if forcing it to run works.. 

Any thoughts? 

"Location has been blocked by your system administrator"

$
0
0

Hello,

I want to Share several Office Apps (e.g. Word, Outlook etc.) via RemoteApp based on a Windows Server 2012 infrastructure.

But before I do, I want to configure the Office 2016 Group Policy Preferences, especially theRestricted Browsing part.

IMO I think the policy is configured well:

Approve Locations is enabled and links to severel UNC paths in our Network
Activate Restricted Browsing is also enabled for Word, Excel, Powerpoint and Outlook.

Now my Problem, as soon as I want to browse a location i receive the following warning message: "Location has been blocked by your system administrator."
The thing is, it is possible to save anything to the defined paths, but I want wo get rid of that warning.

Do you have any clue of what I might can do or are there any known issues regarding Outlook 2016 and Group Policies?


I'm looking foward for you answer.

Best regards

Dominik Beckers

Viewing all 19997 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>