I’m relatively new to an organization.<\/p>\n
I’ve been going nuts try to figure out why GPOs linked to user OUs are not applied.<\/p>\n
There were several already linked and it was found that none of them apply.<\/p>\n
Basically the structure is like the following where departmentX contains user accounts.<\/p>\n
We have a seperate OU for computers which has sub-OUs for each site.<\/p>\n
GPOs that contain computer policies linked to the computer account OUs apply fine.<\/p>\n
GPOs that contain user policies linked to the user account OUs do not get applied.<\/p>\n
I’ve checked:<\/p>\n
There are no GPOs linked to the root of the domain that have loopback enabled.<\/p>\n<\/li>\n
There are no computer GPOs that have loopback enabled which contain the settings that are being applied in the GPOs for the user OUs.<\/p>\n<\/li>\n<\/ol>\n
Example structure in AD:<\/p>\n
domain.internal<\/p>\n
---- department1<\/p>\n
----department2<\/p>\n
----departmentx<\/p>\n
—workstations<\/p>\n
–siteA<\/p>\n
–siteB<\/p>\n
–siteX<\/p>\n
Any ideas?<\/p>\n
thanks!<\/p>","upvoteCount":9,"answerCount":18,"datePublished":"2015-06-03T12:30:16.000Z","author":{"@type":"Person","name":"mikenichols","url":"https://community.spiceworks.com/u/mikenichols"},"acceptedAnswer":{"@type":"Answer","text":"
None of your loopback policies have ‘replace’ mode enabled, do they?<\/p>","upvoteCount":1,"datePublished":"2015-06-03T13:24:48.000Z","url":"https://community.spiceworks.com/t/gpos-wont-apply-to-user-ous/408821/13","author":{"@type":"Person","name":"Rob-Dunn","url":"https://community.spiceworks.com/u/Rob-Dunn"}},"suggestedAnswer":[{"@type":"Answer","text":"
I’m relatively new to an organization.<\/p>\n
I’ve been going nuts try to figure out why GPOs linked to user OUs are not applied.<\/p>\n
There were several already linked and it was found that none of them apply.<\/p>\n
Basically the structure is like the following where departmentX contains user accounts.<\/p>\n
We have a seperate OU for computers which has sub-OUs for each site.<\/p>\n
GPOs that contain computer policies linked to the computer account OUs apply fine.<\/p>\n
GPOs that contain user policies linked to the user account OUs do not get applied.<\/p>\n
I’ve checked:<\/p>\n
There are no GPOs linked to the root of the domain that have loopback enabled.<\/p>\n<\/li>\n
There are no computer GPOs that have loopback enabled which contain the settings that are being applied in the GPOs for the user OUs.<\/p>\n<\/li>\n<\/ol>\n
Example structure in AD:<\/p>\n
domain.internal<\/p>\n
---- department1<\/p>\n
----department2<\/p>\n
----departmentx<\/p>\n
—workstations<\/p>\n
–siteA<\/p>\n
–siteB<\/p>\n
–siteX<\/p>\n
Any ideas?<\/p>\n
thanks!<\/p>","upvoteCount":9,"datePublished":"2015-06-03T12:30:16.000Z","url":"https://community.spiceworks.com/t/gpos-wont-apply-to-user-ous/408821/1","author":{"@type":"Person","name":"mikenichols","url":"https://community.spiceworks.com/u/mikenichols"}},{"@type":"Answer","text":"
I would say start by checking your delegation. Make sure the GPO has proper permissions to get applied.<\/p>","upvoteCount":2,"datePublished":"2015-06-03T12:31:52.000Z","url":"https://community.spiceworks.com/t/gpos-wont-apply-to-user-ous/408821/2","author":{"@type":"Person","name":"littleangie","url":"https://community.spiceworks.com/u/littleangie"}},{"@type":"Answer","text":"
If you do a gpresult /H GPResult.html and look at the file it will probably give you some initial clues about why the policy is not applying. Have you verified that the user that you’re testing against is in the OU that you have your User Configuration GP linked to?<\/p>","upvoteCount":2,"datePublished":"2015-06-03T12:32:54.000Z","url":"https://community.spiceworks.com/t/gpos-wont-apply-to-user-ous/408821/3","author":{"@type":"Person","name":"kelly","url":"https://community.spiceworks.com/u/kelly"}},{"@type":"Answer","text":"
What do your security filtering settings say for those policies under the ‘Scope’ tab?<\/p>\n
If you go to the ‘Details’ tab of one of your user policies, what does the ‘GPO Status’ say?<\/p>","upvoteCount":1,"datePublished":"2015-06-03T12:33:47.000Z","url":"https://community.spiceworks.com/t/gpos-wont-apply-to-user-ous/408821/4","author":{"@type":"Person","name":"Rob-Dunn","url":"https://community.spiceworks.com/u/Rob-Dunn"}},{"@type":"Answer","text":"
Use RSOP to examine a user that is supposed to get the policy but isnt. What does it say?<\/p>\n
from a machine, you can also use gpresult /h test.html<\/p>\n
Are the GPOs ‘disabled’ in any way? User policies disabled, or completely disabled? (right click on them)<\/p>","upvoteCount":2,"datePublished":"2015-06-03T12:34:21.000Z","url":"https://community.spiceworks.com/t/gpos-wont-apply-to-user-ous/408821/5","author":{"@type":"Person","name":"overdrive","url":"https://community.spiceworks.com/u/overdrive"}},{"@type":"Answer","text":"
Have you tried a gpresult /R ? That will at least give you a starting point for why GPO’s are being filtered out. Could be that your users are in a group that’s excluded from the OU policy for machines.<\/p>\n
Could also try logging in as a local user to see if the GPO’s are applied to the machines then.<\/p>","upvoteCount":0,"datePublished":"2015-06-03T12:35:19.000Z","url":"https://community.spiceworks.com/t/gpos-wont-apply-to-user-ous/408821/6","author":{"@type":"Person","name":"chuckdruery","url":"https://community.spiceworks.com/u/chuckdruery"}},{"@type":"Answer","text":"
security filtering was set to authenticated users.<\/p>\n
for testing i tried adding myself, my user account is in the OU where the policy is linked.<\/p>\n
Security on the GPO is the default, authenticated users have read access.<\/p>\n
the gpo doesn’t even show up in the report when running gpresult /H<\/p>\n
in fact none of the GPOs that are linked to user OUs show up when running gpresult /H or when using group policy results wizard on a server.<\/p>\n
What’s interesting is i was trying to add a new GPO for user OUs that contain user settings and it was found that existing GPOs linked to the users OU haven’t been applied, i have no idea when that started.<\/p>\n
the user GPOs have computer settings disabled, there are no computer settings.<\/p>\n
on the details tab the status says computer configuration settings disabled.<\/p>","upvoteCount":0,"datePublished":"2015-06-03T12:38:53.000Z","url":"https://community.spiceworks.com/t/gpos-wont-apply-to-user-ous/408821/7","author":{"@type":"Person","name":"mikenichols","url":"https://community.spiceworks.com/u/mikenichols"}},{"@type":"Answer","text":"
There’s no ‘block inheritance’ set on any of the sub-OU’s, are there?<\/p>","upvoteCount":0,"datePublished":"2015-06-03T12:41:06.000Z","url":"https://community.spiceworks.com/t/gpos-wont-apply-to-user-ous/408821/8","author":{"@type":"Person","name":"Rob-Dunn","url":"https://community.spiceworks.com/u/Rob-Dunn"}},{"@type":"Answer","text":"
no, block inheritance is not set.<\/p>\n
truly a mind boggler, from what i can tell these should be applied.<\/p>","upvoteCount":0,"datePublished":"2015-06-03T12:41:45.000Z","url":"https://community.spiceworks.com/t/gpos-wont-apply-to-user-ous/408821/9","author":{"@type":"Person","name":"mikenichols","url":"https://community.spiceworks.com/u/mikenichols"}},{"@type":"Answer","text":"