Quantcast
Channel: Group Policy forum
Viewing all articles
Browse latest Browse all 19997

Windows 2003 Functional Level AD with W2K8 R2 Servers - AD GPO Issue

$
0
0

Hi

We currently have a majority Windows XP SP3 client estate on a Windows 2003 FL domain


We have recently moved Computer Accounts to another OU and have tried adding GPO to the container.


The one in question is for File Permissions. However, we are finding that the Group Policy does not apply.

When we run a gpresult we get

===============================

An error has occurred while collecting data for Security Configuration Engine (SCE) Extension.

This error impacts the following settings:
Account Policies (Password Policy, Account Lockout Policy, Kerberos Policy)
Local Policies (Audit Policy, User Rights Assignment, Security Options)
Event Log
Restricted Groups
System Services
Registry
File System
The following errors apply to all of the above settings:

An unknown error occurred while data was gathered for this extension. Details: Invalid class

==============================

We have also enabled verbose logging and find that it says

USERENV(3a0.bc0) 16:10:22:283 ProcessGPO:  Found display name of:  <name>
USERENV(3a0.bc0) 16:10:22:298 ProcessGPO:  Found user version of:  GPC is 0, GPT is 0
USERENV(3a0.bc0) 16:10:22:298 ProcessGPO:  Found flags of:  0
USERENV(3a0.bc0) 16:10:22:298 ProcessGPO:  No client-side extensions for this object.
USERENV(3a0.bc0) 16:10:22:298 ProcessGPO:  GPO <name>doesn't contain any data since the version number is 0.  It will be skipped.

=====================================

We have checked that the Sysvol and AD version are being reported as the same and they are

We have validated that Authenticate Users, Domain Users and domain computers are added in the read and apply

We only want the GPO to be added to the Computers in the given OU

We have linked the OU to the GPO

We have enforced the policy and can see that its applied when we review the Site based policy view

In GPRESULT on the Client I get

===================

    Applied Group Policy Objects
    -----------------------------

<Desired GPO is listed>

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Local Group Policy
            Filtering:  Not Applied (Empty)

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
   
        <required GPO>
            Filtering:  Not Applied (Empty)

=====================================

Anyone come across this or can help?

KB's that I have referred to

http://support.microsoft.com/kb/942412?wa=wsignin1.0







Viewing all articles
Browse latest Browse all 19997

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>