Quantcast
Channel: Group Policy forum
Viewing all 19997 articles
Browse latest View live

Automate disk cleanup on domain computers

$
0
0

Hi there,

I need to automate disk cleanup on all the machines available on our company's domain. I have been trying to do it by using sageset and sagerun commands. I also exported the registry keys of the machine on which I ran these commands. Actually I am stuck at importing these registry values into a GPO. I am trying to automate this process via GPO so that it gets applied on all the machines. Can anyone please help me with this?

Thanks,

Akshay 


How to import classic .adm templates into a Central Store?

$
0
0

We need to add Config Manager Current Branch administrative templates into our GPMC and we use a central store.

For some reason, the templates are not available as admx/adml files, but only .adm files.

How do we import adm files into a central store so the settings are available on all systems running GPMC?

I already tried copying the .adm files into the PolicyDefinitions folder with the admx files and it didn't work.


Find local documents after redirection Policy

$
0
0

Hello,

Documents of TS sessions are redirected to a file server.

Since CD migration, i don't know why, but documents fodlers of workstations are redirected too to the file server.

Problem : A user had "local documents" to his workstation, and "network documents" on his TS session. Now local folders of workstation are redirected to file server, and I am unable to find local "documents" folder.

Is any way to find this local documents ?

Thank You and sorry for my bad english.

Tony

Edge promts for use your location - how to hide

$
0
0

We have disabled location tracking on our Windows 10 v1607 machines. Now on some sites I get continous promts withxxx-site wants to use your location, but first you need to go to Settings and turn on Location in Edge browser.

I tried GPO - Windows Components/Microsoft Edge/Configure Do Not Track in Enabled and Disabled setting, but that does not effect on the promt itself, which I want to hide. I also cannot find registry settings for Edge.

 

Software installation is not working through GPO

$
0
0

Hi Experts,

I am trying to deploy mozilla and xml notepad through Group Policy. I have created a test OU on ad and moved few require users into that group. Created a policy assign the software when i try to login into domain machine from that specific user where we apply the policy software doesn't install at the same time when i run rsop.msc i can see policy has been pushed but why it didn't work i have no clue for reference I am attaching few snapshot also for better understanding. this is a client machine snapshot where it clearly shows it is been implemented and I tried changing the value of start policy processing wait time also saw somewhere in the forum but no luck interestingly whenever i run the command of gpupdate /force from client system it always shows below message. many times i choose yes and tried to login again but no luck. Pls advice accordingly. I am using Server 2008 R2 and client all machine is on windows 7 32/64 Bit. Pls let me know if any other information required.

output of client machine-

Updating Policy...

User Policy update has completed successfully.

The following warnings were encountered during user policy processing:

The Group Policy Client Side Extension Software Installation was unable to apply
 one or more settings because the changes must be processed before system startu
p or user logon. The system will wait for Group Policy processing to finish comp
letely before the next startup or logon for this user, and this may result in sl
ow startup and boot performance.
Computer Policy update has completed successfully.

For more detailed information, review the event log or run GPRESULT /H GPReport.
html from the command line to access information about Group Policy results.

Certain User policies are enabled that can only run during logon.

OK to logoff?. (Y/N)

Regards

Prem

Unable to provide delegation to handle DHCP to helpdesk

$
0
0

Hi ,

I am planning to provide access/delegation to helpdesk team to manage dhcp. we have enable filter access list on dhcp on daily basis who are coming new in the office team has to add there mac address to work on our network. We want to delegate this task to helpdesk team the problem is we have 20+ dhcp server which is separate on that server we just go to dhcp admin group and add that person to manage dhcp server. but in our corporate office we have installed dhcp where Active directory is installed because of that reason i am not able to provide access to individual. I tried to edit the permission on adsi edit but no luck . anyone can help me how to delegate the access in this situation, on required user principal what i did i am trying to paste here if policy allow me to past the snapshot.it is not allowing me paste the snapshot. on adsi edit on user object i have choose descendant dhcp class object and provide permission according to my requirement. still no luck my purpose is not solved.

Pls suggest



Prem


Group policy is applying, but GPRESULT /R says Filtering: Not Applied (Empty)

$
0
0

Hi folks,

I'm building a test environment for a small project which right now includes two Server 2008 R2's, a Win XP client, and a Win 7 client. So far all of my GPOs are applying and behaving properly, but when I run GPRESULT /R, all of my GPOs are listed under"The following GPOs were not applied because they were filtered out." This includes Default Domain Policy and Local Group Policy as well. The reason listed is "Filtering: Not Applied (Empty)." If I open RSOP in MMC, however, the policies are listed there. Any ideas on why this is happened?

Windows Server 2012 GPO Loopback Processing

$
0
0

I am currently in the process of creating a GPO in a Windows Server 2012 Active Directory domain. The domain and forest function level is Windows Server 2012.

In order to complete the GPO I need to enable the Loopback Policy processing but I cannot find the setting. In Windows Server 2008 it was found here:

Path: Computer Configuration\Policies\Administrative Templates\System\Group Policy

Setting: User Group Policy loopback processing mode

Was loopback processing removed from Windows Server 2012 AD or was the setting moved?

Any help is much appreciated.

Thank you!


IE11 Proxy settings

$
0
0

Hello,

My DFL/FFL is Windows Server 2008 R2 and my DC Windows Server 2012 R2.

Client : Windows Seven SP1 32bits with IE11

I create a new GPO and configure GPP with IE10 settings. I configured a few options but Proxy settings are not applied. IE Settings on client side are empty. I created RegKey (ProxyEnable, ProxyOverride, ProxyServer) but it's not applied.

gpresult -> not problems

Have you any idea?

Thanks.

GPO issue while adding WMI filter

$
0
0

Hi,

I have created a new WMI filter to apply for both WIn7 and Win10 PC's

select * from Win32_OperatingSystem WHERE Version like "10.0%" or Version >="6.1" and ProductType = "1"

But the GPO's are old which works fine on Win7, when I apply WMI filter created for both Win7 and WIn10 it works on Win7 PC but not on Win10

Quick answer will be helpfull.

Remove suggested apps in windows 10 via group policy

$
0
0
I have several windows 10 work stations  that the workstation start menu provides Suggested links for users to purchase and add software to the machines. How do I remove this option via group policy this is on a 2012 server domain

How to Configure Workgroup Password Policies in Windows 7

$
0
0

Hi Everyone!

I need to configure password policies in my local Workgroup environment for five Computers running Windows 7.

Please let me know if anyone has done and experienced it.

Thanks

Azaam




Apply user-level policy to all users on specific computers only

$
0
0
I reviewed the topic "Apply GPO User Configuration settings only to specific computers"
(apparently I can't post links -- sorry)

The goal:
Apply a policy to a single computer in an OU so that users logging in to that computer only are required to use a password-protected screen saver.

I created an OU for testing, and put two computers into that OU.
I created a GPO that has

"Configure user Group Policy loopback processing mode" set to "Merge" as the only computer setting
"Enable screen saver", "Force specific screen saver", "Password protect the screen saver" and "Screen saver timeout" are the only user settings.
One computer account is delegated to read and apply.
Domain users can read and apply.

Currently both computers have the screen saver activated after the timeout interval.

If I remove the right to apply from "Domain Users" or just leave it at "Authenticated users" then the user-level settings are not applied to either computer.

According to the results wizard, the computer-level (loopback policy) is being applied to both computers.

What am I missing here?

How do I set this up correctly.

Microsoft Edge options missing from group policy

$
0
0

I've installed the latest admx files for windows 10 (Windows10_Version_1511_ADMX) and the options for Microsoft Edge have disappeared in the Group Policy Management Editor.

The MicrosoftEdge.admx file is in C:\windows\PolicyDefinitions folder and also in the domain sysvol polices\policydefinitions

What have I done wrong?

Thanks

How can I restrict Settings-Windows within Windows 10 using Group Policy.

$
0
0

Hey Guys,

We are looking to restrict the Settings from Windows 10  in the start menu and all other places.

I have imported the ADMX from Windows 10 into our store.

I did already configure Show only specified Control Panel items from the User Configuration - Control Panel hoping this would also restrict the settings.

This unfortunately does not work.

Any suggestions where to look?

Regards, René.


GPP Mapped Drives disappear off network

$
0
0

Hi All, 

I've really been banging my head on the wall with this, so hopefully someone can help. We've added some Sufaces to our environment Windows 8.1 and Windows 10, and they're having some issues with GPP Drive Mappings with Server 2008r2. While on the network all drives work correctly, and everything is mapped correctly. Drive mappings are set to "Update" with "Reconnect" disabled. Additionally I use targeting, and only map the drives if X user is in X group. All drives are mapped on the same file server.

The issue is when a user is offline (working remote, traveling, ect) the drives do not show up at all. With Windows 7 all our drives still showed up, and just had a red X when they were offline. So on Windows 8 / 10 when a user hops on the VPN and tries to go to a sales drive (GPP mapped) it's missing. Now while on the VPN they can run "gpupdate /force" and it does map the drives. However that's really not a good workaround for all my users. 

So here are some things I've done to try to solve it. 

1. Changed the path from DNS to IP so instead of "//fileserver/sales" it would be "//192.168.10.10/sales"

2. Tried all sorts of variations of GPP mappings (update, replace, create, reconnect enabled, reconnect disabled). 

3. Tried recreating the policy all together

4. Enabled the GPO "Always wait for the network at computer startup and logon". 

5. Added reg key for "EnabledLinkedConnections" 

6. Ensured offline files / folders were enabled in Sync Center

7. Removed the policy entirely and re-created it. 

8. updated all the latest updates in Server 2008 r2. 

Thanks, and hopefully I'm missing something super easy. 


MCP. MCDST.

Running GPO's as an Admin

$
0
0

Hi,

I'm trying to run either a BATCH file or Powershell script via Group Policy to stop a service, install and file and then restart the service. However, it's not running on the workstations as the logged in users aren't local Administrators.. I'm looking everywhere but haven't been able to figure it out..

I've added the scripts in Startup via Computer Configuratio, Polices but haven't had any success.. 

Is this even possible? 

Thanks,

Error with Source initiated collector

$
0
0

I am trying to setup event forwarding to my domain controller. I have group polices  designating my domain controller to be the collection server. I also have group policies turning on the Winrm services according to rsop.msc the group policies are being applied. I used the domain computers as the group in the event subscription. I cannot seem to get it to work I am getting the following error when I run wecutil gr Test on my source servers.

Failed to get RuntimeStatus Active Property. Error = 0x2

the system cannot find the file specified

The status of the subscription is showing active in event viewer on my domain controller and I added the domain controller's machine account to the Event Viewers group in the domain builtin groups

any help is appreciated 

Lock Screen using GPO

$
0
0

I have changed the background and lock screen setting using the GPO and provide the custom image for background and lock screen. Background image is working fine but lock screen image is not coming. even it is showing in the registry.

Any one have solution for this.

Rename the registry path on multiple computers

$
0
0

Hi All,

I want to Rename the below registry path on multiple computers from a CSV or through a group policy.

HKLM\Software\Microsoft\SMS to HKLM\Software\Microsoft\SMS_old

Can some one guide ?

Thanks in advance.

Viewing all 19997 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>