beta<\/a> :<\/p>\nserver side : log in as Admin<\/p>\n
Client side : log in as users created in domain<\/p>\n
Note : machine is already a member of my test* domain<\/p>\n<\/blockquote>\n<\/aside>","upvoteCount":1,"datePublished":"2013-11-01T15:10:38.000Z","url":"https://community.spiceworks.com/t/gpo-in-active-directory-not-working/252089/18","author":{"@type":"Person","name":"beta","url":"https://community.spiceworks.com/u/beta"}},{"@type":"Answer","text":"
Are you able to take a screenshot of your GPO management console with the GPO in question highlighted?<\/p>","upvoteCount":0,"datePublished":"2013-11-01T15:10:56.000Z","url":"https://community.spiceworks.com/t/gpo-in-active-directory-not-working/252089/19","author":{"@type":"Person","name":"mhache","url":"https://community.spiceworks.com/u/mhache"}},{"@type":"Answer","text":"\n\n
<\/div>\n
mhache:<\/div>\n
\nAh, it was so close to my time in AM it threw me off.<\/p>\n
Can you confirm that you are in fact logged in as a domain user?<\/p>\n<\/blockquote>\n<\/aside>\n
but it did not cause any injury? <\/p>\n
server side : log in as Admin<\/p>\n
Client side : log in as users created in domain<\/p>\n
Note : machine is already a member of my test* domain<\/p>","upvoteCount":0,"datePublished":"2013-11-01T15:11:24.000Z","url":"https://community.spiceworks.com/t/gpo-in-active-directory-not-working/252089/20","author":{"@type":"Person","name":"johnenglatiera2845","url":"https://community.spiceworks.com/u/johnenglatiera2845"}}]}}
Hi Spice team,
I am practicing with AD/DNS Server using WS 2008 r2 64bit. I’ve created GPO and set policy which is to remove shutdown on user account, after that i did GP force update and even restart the target PC, then nothing happen, can you help me find out the why?
Hope to hear from you soon.
Regards,
John
2 Spice ups
mhache
(mhache)
November 1, 2013, 2:23pm
2
Is the GPO applied successfully to the user in question? Log in as the user and use gpresult /Scope User /v in an elevated command prompt.
1 Spice up
ccraddock
(Ccraddock)
November 1, 2013, 2:25pm
3
run RSOP.MSC on the machine to confirm the policy you want it applying
1 Spice up
rebelscum
(Justin G.)
November 1, 2013, 2:26pm
4
Are your machines joined to your test domain?
Hi Mhache,
one more thing, how do i set policy for specific user, by that i can eliminate the possible cause.
GPO is applied to and test to one user only, I’ll try the option you give, will get back to you about the results.
mhache
(mhache)
November 1, 2013, 2:33pm
6
At the bottom where it’s set for Authenticated users. If you’ve removed that and haven’t put anything in there it’ll apply to nothing.
@ Mchache : yes i did that, and nothings happen after the restart and force GP update
mhache
(mhache)
November 1, 2013, 2:41pm
8
Does the GPO show up as applied when you run gpresult /Scope User /v?
@ Ccraddock , just to confirm, you mean i run RSOP.msc in AD Server or at Domain Users?
mhache
(mhache)
November 1, 2013, 2:43pm
10
On the Domain User computer. It’s the GUI version of the command I gave you pretty much.
@ Mchache
here’s the result, please share the fix. …
Last time Group Policy was applied: 11/1/2013 at 11:46:02 PM
Group Policy was applied from: N/A
Group Policy slow link threshold: 500 kbps
Domain Name: CLIENT1
Domain Type:
Applied Group Policy Objects
N/A
The following GPOs were not applied because they were filtered out
Local Group Policy
Filtering: Not Applied (Empty)
The user is a part of the following security groups
None
Everyone
BUILTIN\Administrators
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
CONSOLE LOGON
NT AUTHORITY\Authenticated Users
This Organization
LOCAL
NTLM Authentication
High Mandatory Level
The user has the following security privileges
Bypass traverse checking
Manage auditing and security log
Back up files and directories
Restore files and directories
Change the system time
Shut down the system
Force shutdown from a remote system
Take ownership of files or other objects
Debug programs
Modify firmware environment values
Profile system performance
Profile single process
Increase scheduling priority
Load and unload device drivers
Create a pagefile
Adjust memory quotas for a process
Remove computer from docking station
Perform volume maintenance tasks
Impersonate a client after authentication
Create global objects
Change the time zone
Create symbolic links
Increase a process working set
RSOP_Results.txt (7.56 KB)
mhache
(mhache)
November 1, 2013, 2:56pm
12
This may sound stupid but see about correcting the time on the computer and try a gpupdate /force again.
11/1/2013 at 11:46:02 PM
beta
(beta)
November 1, 2013, 2:59pm
13
Are you logging on as a local user? Group policies don’t apply to local users.
2 Spice ups
@ Mchache …Ngeek…i forgot to mention that’s the correct time, client and server time are same
our timezone is +8
mhache
(mhache)
November 1, 2013, 3:02pm
15
Ah, it was so close to my time in AM it threw me off.
Can you confirm that you are in fact logged in as a domain user?
marruda
(Faythi)
November 1, 2013, 3:06pm
16
Is the user in the same container or a sub container as the GPO? And you’re sure you set it up on the user side, and not computer configuration side? If so the computer would have to be in that container.
1 Spice up
@ beta :
server side : log in as Admin
Client side : log in as users created in domain
Note : machine is already a member of my test* domain
beta
(beta)
November 1, 2013, 3:10pm
18
Your rsop results are from a local user. You need to run it for the domain user you are troubleshooting.
englandyow:
@ beta :
server side : log in as Admin
Client side : log in as users created in domain
Note : machine is already a member of my test* domain
1 Spice up
mhache
(mhache)
November 1, 2013, 3:10pm
19
Are you able to take a screenshot of your GPO management console with the GPO in question highlighted?
mhache:
Ah, it was so close to my time in AM it threw me off.
Can you confirm that you are in fact logged in as a domain user?
but it did not cause any injury?
server side : log in as Admin
Client side : log in as users created in domain
Note : machine is already a member of my test* domain