Quantcast
Channel: Group Policy forum
Viewing all 19997 articles
Browse latest View live

Scripts.admx settings not displayed in Group Policy Management Editor

$
0
0

I have been using ADMX central Store for years. All ADMX templates are working fine with the exception of SCRIPTS.ADMX. I am not finding  any settings from this template in GP Editor under Computer\Administrative Templates\System\Logon.

All other ADMX that I have loaded Office, Skype etc are working.

I am using Win7-Windows2008R2 ADMX templates. Downloaded a fresh copy from MS and copied to domain controller to

C:\Windows\SYSVOL_DFSR\sysvol\<domain fqdn>\Policies\PolicyDefinitions (and the en-us folder) where all the other ADMXes are - no success.

Copied them to the local copy on c:\windows\PolicyDefinitions - no success.

Domain is Win2008R2, upgraded from Win2003. Tried from domain controller and other workstations.

Administrative templates are showing "Policy definitions (ADMX files) retrieved from the central store"

What am I missing?

 



enable/disable PerfTrack than what happen?

$
0
0

Hi All,

If I have enable/disable perftrack using group policy than what happen, if any have any screen shot please share with me.

Group policy Description:

This setting prevents responsiveness events from being aggregated and sent to Microsoft.

Drive mapping doesn't apply when changing machines

$
0
0

Hi all,

We are having an issue where users are provided a machine to work on where the drives map however when they change machine they no longer apply.

We can see this by running gpresult which shows that no user policies are applying. It's worth noting these are being applied over a VPN however we have looked into this and can see that there is no outage...

We've tried recreating and relinking the policies however to no avail. As there are several policies that are meant to apply we have also tried changing the order however again to no avail.

Please could someone advise?

Thanks

2008 R2 Scheduled Task GPO pushed to windows 10

$
0
0

Is there a way to push a scheduled task from Server 2008 R2 Group Policy to windows 10 machines on the same network?

If there is please advise me on how to do so.

Thank you in advanced.


Britten Falcher

MSI package installation using local GPO settings in Windows 7

$
0
0

Hi there,

Is there any way to install an application using local gpo settings in windows 7?

My scenario is like I don't have access to Domain Controller GPO and I need to manage my package installation from client itself.

Thanks in advance.

Roushan

IE proxy server setting checked automatically when user connects to work network and unchecked proxy server setting from IE when disconnect from work network

$
0
0

Hi,

If anyone know how to implement IE proxy server setting check automatically when user laptop connect to work network and uncheck proxy server settings from IE when user disconnects from work network.

please update..

Gpo to add route via openvpn (admin privileges by app and user)

$
0
0
Hi

Can anyone suggest a way to run openvpn as an administrator so standard users can add a route (the command that fails es route.exe). preferrably via gpo

Some computer in our office has vpn connection, using open vpn gui software, but this needs to be run with admin privileges because after it connects, it adds static routes using (route.exe), when a regular user connect, the policies denied to add the static router.

So really what I'm looking for is a way to have a GPO that will allow all users to be able to add routes on the fly, without having to make changes to individual pc's. 

Thanks

2003 DC - GPO with login script not applying to users on Win 10

$
0
0

I have a login script that I want to use temporarily.  It is to standardize local computer admins by doing a series of NET USER and NET LOCALGROUP commands.

I cannot use psexec, at least not very easily, because our current setup (being changed next year) uses Linux based DNS which does not dynamically register workstation host names.  So getting 100+ live leases across 4 locations and remote users would be a nightmare.

I know the GPO works because I have a test user set up.  If I log into a windows 10 test machines and do a gpupdate /force, than log out and in, nothing happens.  So I run GPRESULT /R and I notice the new GPO is not in the list of applied GPOs.

If I follow the same exact steps on one of my spare laptops with Win 7, it works as intended.  Any ideas?


How to use Group policy to control autodiscover

$
0
0
All users in our organization are using the Outlook 2010 and  Outlook 2013, we would like to disable SCP lookup for autodiscover. Please kindly share the information with us. 

Workfolders policy for specific computers for specific users

$
0
0

We use work folders with redirected folders but because our server is across the WAN for all our offices it can take a very long time to load so I have also mapped a Home Folder drive to the root of each of the users workfolders.

The problem is when the users roam between offices and log into other computers I do not want the work folders to start replicating.  I want the work folder/redirected folders to only work on their primary machine.

Is there a way to do this or would I have to create a separate policy for each user related to their specific machine?

Domain Controllers have two different sysvol locations

$
0
0

I have two domain controllers one running windows 2008 R2 and another running Windows server standard service pack 2. The AD running windows 2008 R2 has its sysvol on drive S while the other AD has its sysvol on drive C. 

Recently one of our AD restarted and we are o longer able to edit GP on the windows 2008 R2 DC. most of the computers are also not picking the policies applied on the windows 2008 DC.

I am able to edit and view policies on the windows standard server.

Can anyone please guide on how to get these two DC's to replicate from the same folder.

Group Policy Services

$
0
0

I'm running group policy from windows server 2012. Windows server 2012 does not have the service TABLETPCINPUT. as a result, all PCs (all running win7) in the domain are not able to have the tabletpcinput service run. I've changed it to auto and it repeatedly changes itself back to disabled when gpupdate /force, or logon occurs.

How can I work around this?


Ryan Piselli

MSI

$
0
0

Hello, 

I am trying to install some software in my server to send to my domain users, but it needs a msi file type to use, how do I create a msi file?

Thanks!

Modify Windows server 2012

$
0
0

We currently have a published desktop in Citrix for server 2008, I can assure you this topic is related to Microsoft Group Policy.

The objective is to publish a server 20120 desktop instead of an the existing server 2008 published desktop. Internally that would be a large learning curve for the end users  SO we want to make it easily adaptive to 2008 yet it must be 2012. 

I know that server 2012 has a toggle between tiles and the desktop and of course to add to the confusio9jn comparing this to group policy without using classic shell, I have found some information on the internet including installing feature, desktop experience and then cleaning away the tiles.

We need group policy to have them only login to the desktop and then only allow Logoff from the Start menu or if tile switch and start menu is not available I can see that there is a group policy to remove the Do not show start menu at login, but what about removing the Tile feature altogether and the start menu?   We could put application shortcuts on their desktop and then a shortcut to logoff.

This way they can just logoff at the desktop, but if we do that we would need to ensure that they do not delete the shortcut.  Hopefully I have defined the objective, please help.  Please let me know if you have any questions that I have not described.

Software Restriction Policy not respecting Disallowed Path for SVG file type

$
0
0

After reading about the "ImageGate" encryption hack, I decided it would be wise to further restrict what users can do in their download folders.

I set up three rules, all identical with the exception of the file extension to disallow.  The all work except the last.  I cannot determine why this is the case:

1)  C:\Users\%username%\Downloads\*.hta
2)  C:\Users\%username%\Downloads\*.js
3)  C:\Users\%username%\Downloads\*.svg

When I open a .hta or .js file in Downloads, I'm greeted with "Your system administrator has blocked this program.  For more information, contact your system administrator."

When I open the .svg, I receive a browser selection prompt and upon choosing a browser, the file opens. 

Is there a certain list of file types that SRP only applies to?


Group Policy Editor

$
0
0

Hi Everyone!

I want to disable USB access for pen drive or flash drives but allow external CD/DVD access through group policy management. I have done in some way but it deny access to all class of storage including CD/DVD. I can gain this by using regedit. But I want this as a domain policy. Please help!

Access error while obtaining ACLs information

$
0
0

Hi,

I tried crawling my shared folder and documents. I want to obtain all ACLs information but I got "Access is denied" error. So I added user of Domain admins and my problem is solved. 

Otherwise, It says here as "Domain Admins: Members of this group have full control of the domain. By default, this group is a member of the Administrators group on all domain controllers, all domain workstations, and all domain member servers at the time they are joined to the domain. By default, the Administrator account is a member of this group. Because the group has full control in the domain, add users with caution."

I don't want full control of the domain. How can I solve the problem as having less authority?

Slow logon caused by Drive Mapping Group Policy

$
0
0

We're experiencing slow logon times on certain clients (up to 20 minutes). The problem only occurs at the first (re)boot of that day. I've enabled "Display highly detailed status messages" and see it hangs at "Processing Drive Mappings" so I enabled "Configure Drive Maps preference logging and tracing". The only thing I see in this log is the following:

2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] Entering ProcessGroupPolicyExDrives()
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] SOFTWARE\Policies\Microsoft\Windows\Group Policy\{5794DAFD-BE60-433f-88A2-1A31939AC01F}
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] BackgroundPriorityLevel ( 0 )
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] DisableRSoP ( 0 )
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] LogLevel ( 3 )
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] Command subsystem initialized. [SUCCEEDED(S_FALSE)]
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] Set user security context.
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] Set system security context.
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] User impersonation initialized.
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] Client context subsystem initialized.
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] Configuration subsystem initialized.
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] Licensing subsystem initialized.
2016-11-29 06:34:06.046 [pid=0x4fc,tid=0x15f0] Set user security context.
2016-11-29 06:46:56.072 [pid=0x4fc,tid=0x15f0] User information initialized.
2016-11-29 06:46:58.958 [pid=0x4fc,tid=0x15f0] Variable %ComSpec% = "C:\Windows\system32\cmd.exe"
2016-11-29 06:46:58.958 [pid=0x4fc,tid=0x15f0] Variable %FP_NO_HOST_CHECK% = "NO"
2016-11-29 06:46:58.958 [pid=0x4fc,tid=0x15f0] Variable %OS% = "Windows_NT"

As you can see, it's initializing it's user information from 06:34:06.046 until 06:46:56.072 if I'm not mistaken. Why does this take so long? When I disable the policy (see bellow) the problem doesn't occur.

<?xml version="1.0" encoding="utf-16"?><GPO xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.microsoft.com/GroupPolicy/Settings"><Identifier><Identifier xmlns="http://www.microsoft.com/GroupPolicy/Types">{201AEDBB-6E09-4767-98DD-00F9E33BD701}</Identifier><Domain xmlns="http://www.microsoft.com/GroupPolicy/Types">domain.local</Domain></Identifier><Name>domain:Users_All:DriveMaps:UP</Name><IncludeComments>true</IncludeComments><CreatedTime>2016-08-30T09:02:19</CreatedTime><ModifiedTime>2016-11-23T12:30:32</ModifiedTime><ReadTime>2016-11-29T10:05:46.132037Z</ReadTime><SecurityDescriptor><SDDL xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">O:DAG:DAD:PAI(OA;CI;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-1410742142-344776957-3069341034-519)(A;CI;LCRPLORC;;;ED)(A;CI;LCRPLORC;;;AU)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;SY)(A;CIIO;CCDCLCSWRPWPDTLOSDRCWDWO;;;CO)S:AI(OU;CIIDSA;WPWD;;f30e3bc2-9ff0-11d1-b603-0000f80367c1;WD)(OU;CIIOIDSA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)(OU;CIIOIDSA;WP;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)</SDDL><Owner xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"><SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-1410742142-344776957-3069341034-512</SID><Name xmlns="http://www.microsoft.com/GroupPolicy/Types">domain\Domain Admins</Name></Owner><Group xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"><SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-1410742142-344776957-3069341034-512</SID><Name xmlns="http://www.microsoft.com/GroupPolicy/Types">domain\Domain Admins</Name></Group><PermissionsPresent xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">true</PermissionsPresent><Permissions xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"><InheritsFromParent>false</InheritsFromParent><TrusteePermissions><Trustee><SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-1410742142-344776957-3069341034-512</SID><Name xmlns="http://www.microsoft.com/GroupPolicy/Types">domain\Domain Admins</Name></Trustee><Type xsi:type="PermissionType"><PermissionType>Allow</PermissionType></Type><Inherited>false</Inherited><Applicability><ToSelf>true</ToSelf><ToDescendantObjects>false</ToDescendantObjects><ToDescendantContainers>true</ToDescendantContainers><ToDirectDescendantsOnly>false</ToDirectDescendantsOnly></Applicability><Standard><GPOGroupedAccessEnum>Edit, delete, modify security</GPOGroupedAccessEnum></Standard><AccessMask>0</AccessMask></TrusteePermissions><TrusteePermissions><Trustee><SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-9</SID><Name xmlns="http://www.microsoft.com/GroupPolicy/Types">NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS</Name></Trustee><Type xsi:type="PermissionType"><PermissionType>Allow</PermissionType></Type><Inherited>false</Inherited><Applicability><ToSelf>true</ToSelf><ToDescendantObjects>false</ToDescendantObjects><ToDescendantContainers>true</ToDescendantContainers><ToDirectDescendantsOnly>false</ToDirectDescendantsOnly></Applicability><Standard><GPOGroupedAccessEnum>Read</GPOGroupedAccessEnum></Standard><AccessMask>0</AccessMask></TrusteePermissions><TrusteePermissions><Trustee><SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-18</SID><Name xmlns="http://www.microsoft.com/GroupPolicy/Types">NT AUTHORITY\SYSTEM</Name></Trustee><Type xsi:type="PermissionType"><PermissionType>Allow</PermissionType></Type><Inherited>false</Inherited><Applicability><ToSelf>true</ToSelf><ToDescendantObjects>false</ToDescendantObjects><ToDescendantContainers>true</ToDescendantContainers><ToDirectDescendantsOnly>false</ToDirectDescendantsOnly></Applicability><Standard><GPOGroupedAccessEnum>Edit, delete, modify security</GPOGroupedAccessEnum></Standard><AccessMask>0</AccessMask></TrusteePermissions><TrusteePermissions><Trustee><SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-11</SID><Name xmlns="http://www.microsoft.com/GroupPolicy/Types">NT AUTHORITY\Authenticated Users</Name></Trustee><Type xsi:type="PermissionType"><PermissionType>Allow</PermissionType></Type><Inherited>false</Inherited><Applicability><ToSelf>true</ToSelf><ToDescendantObjects>false</ToDescendantObjects><ToDescendantContainers>true</ToDescendantContainers><ToDirectDescendantsOnly>false</ToDirectDescendantsOnly></Applicability><Standard><GPOGroupedAccessEnum>Apply Group Policy</GPOGroupedAccessEnum></Standard><AccessMask>0</AccessMask></TrusteePermissions><TrusteePermissions><Trustee><SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-1410742142-344776957-3069341034-519</SID><Name xmlns="http://www.microsoft.com/GroupPolicy/Types">domain\Enterprise Admins</Name></Trustee><Type xsi:type="PermissionType"><PermissionType>Allow</PermissionType></Type><Inherited>false</Inherited><Applicability><ToSelf>true</ToSelf><ToDescendantObjects>false</ToDescendantObjects><ToDescendantContainers>true</ToDescendantContainers><ToDirectDescendantsOnly>false</ToDirectDescendantsOnly></Applicability><Standard><GPOGroupedAccessEnum>Edit, delete, modify security</GPOGroupedAccessEnum></Standard><AccessMask>0</AccessMask></TrusteePermissions></Permissions><AuditingPresent xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">false</AuditingPresent></SecurityDescriptor><FilterDataAvailable>true</FilterDataAvailable><Computer><VersionDirectory>0</VersionDirectory><VersionSysvol>0</VersionSysvol><Enabled>false</Enabled></Computer><User><VersionDirectory>344</VersionDirectory><VersionSysvol>344</VersionSysvol><Enabled>true</Enabled><ExtensionData><Extension xsi:type="q1:DriveMapSettings" xmlns:q1="http://www.microsoft.com/GroupPolicy/Settings/DriveMaps"><q1:DriveMapSettings clsid="{8FDDCC1A-0C3C-43cd-A6B4-71A6DF20DA8C}"><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="A:" status="A:" image="3" changed="2016-09-07 09:56:23" uid="{7D73B874-DDFD-4696-A8BE-5019E87F0C32}" bypassErrors="1" disabled="0"><q1:GPOSettingOrder>1</q1:GPOSettingOrder><q1:Properties action="D" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="" label="" persistent="0" useLetter="0" letter="A"></q1:Properties><q1:Filters><q1:FilterGroup bool="AND" not="1" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-users-LocalComputer" sid="S-1-5-21-1410742142-344776957-3069341034-1232" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-users-Holding" sid="S-1-5-21-1410742142-344776957-3069341034-1249" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="A:" status="A:" image="3" changed="2016-09-07 09:56:38" uid="{8CF3A1DD-D928-4775-8C89-F16421F1DA1F}" disabled="0" bypassErrors="1"><q1:GPOSettingOrder>2</q1:GPOSettingOrder><q1:Properties action="D" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="" label="" persistent="0" useLetter="0" letter="A"></q1:Properties><q1:Filters><q1:FilterRunOnce hidden="1" not="0" bool="AND" id="{7738C1FB-9988-4308-B303-66540B515CBA}"></q1:FilterRunOnce><q1:FilterGroup bool="AND" not="1" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-users-ComfortEnergy" sid="S-1-5-21-1410742142-344776957-3069341034-1249" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="N:" status="N:" image="1" changed="2016-11-23 11:26:41" uid="{D5C903AE-6267-4B43-9E08-1B6E93FB5022}" removePolicy="1" bypassErrors="1"><q1:GPOSettingOrder>3</q1:GPOSettingOrder><q1:Properties action="R" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="\\domain.local\olddata\data1" label="DATA" persistent="0" useLetter="1" letter="N"></q1:Properties><q1:Filters><q1:FilterCollection bool="AND" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterCollection bool="OR" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-LocalComputer" sid="S-1-5-21-1410742142-344776957-3069341034-1232" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:FilterCollection></q1:FilterCollection><q1:FilterGroup bool="AND" not="1" name="domain\domain-role-dne-technieker" sid="S-1-5-21-1410742142-344776957-3069341034-1268" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-role-domain-techniekers" sid="S-1-5-21-1410742142-344776957-3069341034-1277" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterUser bool="AND" not="1" name="domain\tania.b" sid="S-1-5-21-1410742142-344776957-3069341034-1299"></q1:FilterUser><q1:FilterGroup bool="AND" not="1" name="domain\domain-users-Subdepartment1" sid="S-1-5-21-1410742142-344776957-3069341034-1325" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="O:" status="O:" image="1" changed="2016-11-23 11:26:47" uid="{D71CFD3D-4B84-4BB2-AE71-CD21FF93C2A9}" removePolicy="1" bypassErrors="1"><q1:GPOSettingOrder>4</q1:GPOSettingOrder><q1:Properties action="R" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="\\domain.local\olddata\data2" label="DATA2" persistent="0" useLetter="1" letter="O"></q1:Properties><q1:Filters><q1:FilterCollection bool="AND" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterCollection bool="OR" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-LocalComputer" sid="S-1-5-21-1410742142-344776957-3069341034-1232" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:FilterCollection></q1:FilterCollection><q1:FilterGroup bool="AND" not="1" name="domain\domain-role-dne-technieker" sid="S-1-5-21-1410742142-344776957-3069341034-1268" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-role-domain-techniekers" sid="S-1-5-21-1410742142-344776957-3069341034-1277" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterUser bool="AND" not="1" name="domain\tania.b" sid="S-1-5-21-1410742142-344776957-3069341034-1299"></q1:FilterUser><q1:FilterGroup bool="AND" not="1" name="domain\domain-users-Subdepartment1" sid="S-1-5-21-1410742142-344776957-3069341034-1325" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="P:" status="P:" image="1" changed="2016-11-23 11:27:05" uid="{D0099B48-6861-4897-AEC8-6694B634F4FD}" disabled="0" removePolicy="1" bypassErrors="1"><q1:GPOSettingOrder>5</q1:GPOSettingOrder><q1:Properties action="R" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="\\domain.local\olddata\data1\projecten" label="Projecten" persistent="0" useLetter="1" letter="P"></q1:Properties><q1:Filters><q1:FilterCollection bool="AND" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterCollection bool="OR" not="0"><q1:FilterGroup bool="AND" not="1" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-LocalComputer" sid="S-1-5-21-1410742142-344776957-3069341034-1232" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:FilterCollection></q1:FilterCollection><q1:FilterGroup bool="AND" not="1" name="domain\domain-role-dne-technieker" sid="S-1-5-21-1410742142-344776957-3069341034-1268" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-role-domain-techniekers" sid="S-1-5-21-1410742142-344776957-3069341034-1277" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterUser bool="AND" not="1" name="domain\tania.b" sid="S-1-5-21-1410742142-344776957-3069341034-1299"></q1:FilterUser><q1:FilterGroup bool="AND" not="1" name="domain\domain-users-Subdepartment1" sid="S-1-5-21-1410742142-344776957-3069341034-1325" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="Q:" status="Q:" image="1" changed="2016-11-23 11:27:10" uid="{FE675A8A-9444-4663-9746-0E674569B75E}" disabled="0" removePolicy="1" bypassErrors="1"><q1:GPOSettingOrder>6</q1:GPOSettingOrder><q1:Properties action="R" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="\\domain.local\olddata\data-Local" label="Data - Local" persistent="0" useLetter="1" letter="Q"></q1:Properties><q1:Filters><q1:FilterCollection bool="AND" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterCollection bool="OR" not="0"><q1:FilterGroup bool="AND" not="1" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-LocalComputer" sid="S-1-5-21-1410742142-344776957-3069341034-1232" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:FilterCollection></q1:FilterCollection><q1:FilterGroup bool="AND" not="1" name="domain\domain-role-dne-technieker" sid="S-1-5-21-1410742142-344776957-3069341034-1268" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-role-domain-techniekers" sid="S-1-5-21-1410742142-344776957-3069341034-1277" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterUser bool="AND" not="1" name="domain\tania.b" sid="S-1-5-21-1410742142-344776957-3069341034-1299"></q1:FilterUser><q1:FilterGroup bool="AND" not="1" name="domain\domain-users-Subdepartment1" sid="S-1-5-21-1410742142-344776957-3069341034-1325" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="R:" status="R:" image="1" changed="2016-11-23 11:27:13" uid="{96393BCE-0699-440C-99CD-554E4C52918E}" disabled="0" removePolicy="1" bypassErrors="1"><q1:GPOSettingOrder>7</q1:GPOSettingOrder><q1:Properties action="R" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="\\domain.local\olddata\projecten-Local" label="Projecten - Local" persistent="0" useLetter="1" letter="R"></q1:Properties><q1:Filters><q1:FilterCollection bool="AND" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterCollection bool="OR" not="0"><q1:FilterGroup bool="AND" not="1" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-LocalComputer" sid="S-1-5-21-1410742142-344776957-3069341034-1232" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:FilterCollection><q1:FilterUser bool="OR" not="0" name="domain\cooltool" sid="S-1-5-21-1410742142-344776957-3069341034-1246"></q1:FilterUser></q1:FilterCollection><q1:FilterGroup bool="AND" not="1" name="domain\domain-role-dne-technieker" sid="S-1-5-21-1410742142-344776957-3069341034-1268" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-role-domain-techniekers" sid="S-1-5-21-1410742142-344776957-3069341034-1277" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterUser bool="AND" not="1" name="domain\tania.b" sid="S-1-5-21-1410742142-344776957-3069341034-1299"></q1:FilterUser><q1:FilterGroup bool="AND" not="1" name="domain\domain-users-Subdepartment1" sid="S-1-5-21-1410742142-344776957-3069341034-1325" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="S:" status="S:" image="1" changed="2016-11-23 11:27:19" uid="{682C7C42-B8B1-4F0F-9976-03CAE4954768}" disabled="0" removePolicy="1" bypassErrors="1"><q1:GPOSettingOrder>8</q1:GPOSettingOrder><q1:Properties action="R" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="\\domain.local\olddata\DNE" label="Data - DNE" persistent="0" useLetter="1" letter="S"></q1:Properties><q1:Filters><q1:FilterCollection bool="AND" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-Subdepartment2" sid="S-1-5-21-1410742142-344776957-3069341034-1638" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterCollection bool="AND" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterCollection bool="OR" not="0"><q1:FilterGroup bool="AND" not="1" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-LocalComputer" sid="S-1-5-21-1410742142-344776957-3069341034-1232" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:FilterCollection></q1:FilterCollection></q1:FilterCollection><q1:FilterGroup bool="AND" not="1" name="domain\domain-role-dne-technieker" sid="S-1-5-21-1410742142-344776957-3069341034-1268" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="T:" status="T:" image="1" changed="2016-11-23 11:27:24" uid="{699B336A-B408-4138-9AC1-420C185300F2}" disabled="0" removePolicy="1" bypassErrors="1"><q1:GPOSettingOrder>9</q1:GPOSettingOrder><q1:Properties action="R" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="\\domain.local\olddata\dne-techniekers" label="Data - DNE Techniekers" persistent="0" useLetter="1" letter="T"></q1:Properties><q1:Filters><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-Subdepartment2" sid="S-1-5-21-1410742142-344776957-3069341034-1638" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterCollection bool="AND" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterCollection bool="OR" not="0"><q1:FilterGroup bool="AND" not="1" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-LocalComputer" sid="S-1-5-21-1410742142-344776957-3069341034-1232" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:FilterCollection></q1:FilterCollection></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="L:" status="L:" image="1" changed="2016-11-23 11:27:29" uid="{F6FA981B-B4E8-481B-9902-8347594C2A76}" disabled="0" removePolicy="1" bypassErrors="1"><q1:GPOSettingOrder>10</q1:GPOSettingOrder><q1:Properties action="R" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="\\domain.local\data" label="DATA" persistent="0" useLetter="1" letter="L"></q1:Properties><q1:Filters><q1:FilterCollection bool="AND" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterCollection bool="OR" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-LocalComputer" sid="S-1-5-21-1410742142-344776957-3069341034-1232" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:FilterCollection></q1:FilterCollection><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-Subdepartment1" sid="S-1-5-21-1410742142-344776957-3069341034-1325" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="J:" status="J:" image="1" changed="2016-11-23 11:27:38" uid="{6895B094-3888-4D98-8FA8-778126D09FE6}" removePolicy="1" bypassErrors="1"><q1:GPOSettingOrder>11</q1:GPOSettingOrder><q1:Properties action="R" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="\\srvdomain005\data$" label="BRILJANT" persistent="0" useLetter="1" letter="J"></q1:Properties><q1:Filters><q1:FilterGroup bool="AND" not="0" name="domain\domain-app-Briljant" sid="S-1-5-21-1410742142-344776957-3069341034-1291" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="0" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="S:" status="S:" image="1" changed="2016-11-23 11:27:45" uid="{814B7A9A-5DC1-421A-A8D3-7610D9250396}" removePolicy="1" bypassErrors="1"><q1:GPOSettingOrder>12</q1:GPOSettingOrder><q1:Properties action="R" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="\\domain.local\domain\frigodata" label="FrigoData" persistent="0" useLetter="1" letter="S"></q1:Properties><q1:Filters><q1:FilterUser bool="AND" not="0" name="domain\techdienst" sid="S-1-5-21-1410742142-344776957-3069341034-1747"></q1:FilterUser></q1:Filters></q1:Drive><q1:Drive clsid="{935D1B74-9CB8-4e3c-9914-7DD559B7A417}" name="M:" status="M:" image="1" changed="2016-09-08 15:33:34" uid="{1F552E4C-D8E2-4EFB-BBA2-9CFF86B89C89}" removePolicy="1" userContext="1" bypassErrors="1"><q1:GPOSettingOrder>13</q1:GPOSettingOrder><q1:Properties action="R" thisDrive="NOCHANGE" allDrives="NOCHANGE" userName="" path="\\domain.local\userdata\home\%USERNAME%" label="HOME" persistent="0" useLetter="1" letter="M"></q1:Properties><q1:Filters><q1:FilterCollection bool="AND" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterCollection bool="OR" not="0"><q1:FilterGroup bool="AND" not="0" name="domain\domain-users-LocalComputer" sid="S-1-5-21-1410742142-344776957-3069341034-1232" userContext="1" primaryGroup="0" localGroup="0"></q1:FilterGroup><q1:FilterGroup bool="AND" not="1" name="domain\domain-servers-ts" sid="S-1-5-21-1410742142-344776957-3069341034-1630" userContext="0" primaryGroup="0" localGroup="0"></q1:FilterGroup></q1:FilterCollection><q1:FilterUser bool="OR" not="0" name="domain\cooltool" sid="S-1-5-21-1410742142-344776957-3069341034-1246"></q1:FilterUser></q1:FilterCollection></q1:Filters></q1:Drive></q1:DriveMapSettings></Extension><Name>Drive Maps</Name></ExtensionData></User><LinksTo><SOMName>Users</SOMName><SOMPath>domain.local/customer/Users</SOMPath><Enabled>true</Enabled><NoOverride>false</NoOverride></LinksTo><LinksTo><SOMName>TS</SOMName><SOMPath>domain.local/customer/Servers/TS</SOMPath><Enabled>false</Enabled><NoOverride>false</NoOverride></LinksTo><

Missing GPO settings after migrating to Central Store

$
0
0

Hey everyone,

Setup: 2 New Server 2016 Core DC's, 1 Windows 10 Enterprise LTSB w/ latest RSAT.

On Core DC: Robocopy /MIR /XJ %systemroot%\PolicyDefinitions %systemroot%\sysvol\sysvol\domain\policies\PolicyDefinitions

Now when I run MMC and load the GPM snap-in, edit a GPO I see under the Admin Templates, it states grabbing admx files from the central store.

After making said change I noticed the settings to change the windows Store items are no longer available...

Computer -> Policies -> Admin templates -> Windows Components -> Store

I even copied the latest Windows 10 ADMX files (ver 1607) into my central store. Yet the location specified is still not available unless I remove the central store completely and have the snap-in use the DC's local store.

Sigh, what did I miss this time?

Consolidation and migrating GPOs

$
0
0

I am on a project where I have to take about 150 GPOs from 7 domains which are about to be consolidated into one as a prep for W10 migration. For the initial stage (POC) I backed up all GPOs and created migration tables, I was looking into importing all GPOs into SCM for reviewing, reporting and consolidation purposes where neededm however SCM seem to be able to import a single GPO at the time?

Can anyone recommend a better way for importing amass number of GPOS? Or a better advice on how to handle the overall process?

--

TIA


-- Adam

Viewing all 19997 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>