I created new GPO’s under the Group Policy Objects.<\/p>\n
It is filtered for specific security groups - there are about 40 of them for different regions. just mapping some drives and deploying the correct printer.<\/p>\n
All have Authenticated Users set to READ<\/p>\n
the specific security group set to READ (from Security Filtering)<\/p>\n
On user computer - tested with GPUPDATE /Force - when running GPRESULT /r - it only shows the first Domain Policy applied, and then the first 3 GPO’s Denied (Security) as it should - the ones further down the list are not being denied or applied.<\/p>\n
Verified Delegation settings that all are the same.<\/p>\n
Help!<\/p>","upvoteCount":5,"answerCount":16,"datePublished":"2022-02-15T20:04:13.000Z","author":{"@type":"Person","name":"kencaplan2714","url":"https://community.spiceworks.com/u/kencaplan2714"},"acceptedAnswer":{"@type":"Answer","text":"
Under Delegation but you havent shown the scope tab. I have seen issues when authenticated users were not under the scope tab as far as GPO’s applying.<\/p>","upvoteCount":0,"datePublished":"2022-02-15T21:24:53.000Z","url":"https://community.spiceworks.com/t/gpo-not-applying/825229/12","author":{"@type":"Person","name":"kevinweller","url":"https://community.spiceworks.com/u/kevinweller"}},"suggestedAnswer":[{"@type":"Answer","text":"
I created new GPO’s under the Group Policy Objects.<\/p>\n
It is filtered for specific security groups - there are about 40 of them for different regions. just mapping some drives and deploying the correct printer.<\/p>\n
All have Authenticated Users set to READ<\/p>\n
the specific security group set to READ (from Security Filtering)<\/p>\n
On user computer - tested with GPUPDATE /Force - when running GPRESULT /r - it only shows the first Domain Policy applied, and then the first 3 GPO’s Denied (Security) as it should - the ones further down the list are not being denied or applied.<\/p>\n
Verified Delegation settings that all are the same.<\/p>\n
Help!<\/p>","upvoteCount":5,"datePublished":"2022-02-15T20:04:13.000Z","url":"https://community.spiceworks.com/t/gpo-not-applying/825229/1","author":{"@type":"Person","name":"kencaplan2714","url":"https://community.spiceworks.com/u/kencaplan2714"}},{"@type":"Answer","text":"
A lot of the time when you run gpresult it will tell you where to look in the event log to see what is going wrong. I always use the HTML version of gpresult though. Is there any chance it is pointing you to some logs? That is where I would start. Feel free to post your logs, and/or screenshots of your config.<\/p>","upvoteCount":0,"datePublished":"2022-02-15T20:23:17.000Z","url":"https://community.spiceworks.com/t/gpo-not-applying/825229/2","author":{"@type":"Person","name":"kevinweller","url":"https://community.spiceworks.com/u/kevinweller"}},{"@type":"Answer","text":"
For what it’s worth, I have one GPO called DriveMappings that is applied to all regular users (non-admin, non-service). Then I use Group Policy Preferences Item-Level Targeting to map the drives (82 of them) to various security groups. Much easier to keep track of.<\/p>","upvoteCount":0,"datePublished":"2022-02-15T20:50:52.000Z","url":"https://community.spiceworks.com/t/gpo-not-applying/825229/3","author":{"@type":"Person","name":"cerbere","url":"https://community.spiceworks.com/u/cerbere"}},{"@type":"Answer","text":"
@kevinweller<\/a> <\/p>\n Here is the gpresult /r<\/p>\n C:\\WINDOWS\\system32>gpresult /r<\/p>\n Microsoft (R) Windows (R) Operating System Group Policy Result tool v2.0 Created on 2/15/2022 at 12:00:21 PM<\/p>\n OS Configuration: Member Workstation CN=,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=wgi,DC=local Default Domain Policy<\/p>\n 002 Lake City 001 Lynnwood 000 All Stores Local Group Policy Domain Users As you can see - the Default Domain policy applies - and then next 3, 000 - All Stores, 001 Lynnwood, 002 Lake City<\/strong> are all denied as they should be because they do not apply to that user.<\/p>\n At the bottom of the GPO’s - the Folder Redirection<\/strong> applies to this user - and doesn’t appear to be processed. The individual stores such as the 000, 001, 002 works for those specific users, but when a user that should have 003 applied - only the first 3 show denied, the remainder do not process. As I originally stated all have the same security settings with Authorized User marked as read - and the specific security group set to Read (from Security Filtering)<\/p>\n Below is a picture of GPO’s under the Group Policy Object bucket - and the a shot of 001 - which is processing, and then two other’s that are not - yet with exact same permissions save for the specific security group.<\/p>\n For the example user - JKB - you can see they are a part of the security group Folder Redirection<\/strong> - which the authorized security group listed in the GPO Folder Redirection<\/strong> - yet it doesn’t process per gpresult as shown above.<\/p>\n Its only processing the first few in order of alphabet from the Group Policy Objects - and I can’t figure out why. (apologies if my explanation seems scattered)<\/p>\n Below is screen shots of the GPO<\/p>\n
\n© Microsoft Corporation. All rights reserved.<\/p>\n<\/a>RSOP data for WGI\\jkb on JKB : Logging Mode<\/h2>\n
\nOS Version: 10.0.19043
\nSite Name: N/A
\nRoaming Profile: N/A
\nLocal Profile: C:\\Users\\jkb
\nConnected over a slow link?: No<\/p>\n<\/a>USER SETTINGS<\/h2>\n
\nLast time Group Policy was applied: 2/15/2022 at 11:59:30 AM
\nGroup Policy was applied from: WESCO.wgi.local
\nGroup Policy slow link threshold: 500 kbps
\nDomain Name: WGI
\nDomain Type: Windows 2008 or later<\/p>\n<\/a>Applied Group Policy Objects<\/h2>\n
<\/a>The following GPOs were not applied because they were filtered out<\/h2>\n
\nFiltering: Denied (Security)<\/p>\n
\nFiltering: Denied (Security)<\/p>\n
\nFiltering: Denied (Security)<\/p>\n
\nFiltering: Not Applied (Empty)<\/p>\n<\/a>The user is a part of the following security groups<\/h2>\n
\nEveryone
\nBUILTIN\\Users
\nNT AUTHORITY\\INTERACTIVE
\nCONSOLE LOGON
\nNT AUTHORITY\\Authenticated Users
\nThis Organization
\nLOCAL
\nFolder Redirection
\nAuthentication authority asserted identity
\nMedium Mandatory Level<\/p>\n