I am experiencing some GPO Replication issues that trying to resolve with my server team is resulting in a finger pointing match like a false start during a football game.<\/p>\n
I have been trying to make some new GPO’s for both testing and production purposes, make them in the Group Policy utility, assign their groups and when I do a GPUpdate I get “The processing of Group Policy failed. Windows attempted to read the file \\Path\\to\\gpt.ini was not successful”<\/p>\n
Since we have a multi-DC environment I went individually to each DC and this is where I’m seeing problems. The “baseline” DC has no issues. Between our other 2 domain controllers I am seeing that either the \\Policies{identifier} folder is missing, or it may exist but when I check its security properties it tells me that I don’t have access to read the contents of the folder.<\/p>\n
Back in the Status screen of the GPO I can see the domain controllers with replication in progress saying that SysVol may be Inaccessible, or has ACLs listed.<\/p>\n
My server guys restarted the replication service one time and said that “it was fixed” even though they did not verify that GPO’s were replicating which I verified that they were not. It is my understanding that GPO replication (and associated folder rights) are handled automatically by the DC servers and should just be copies of each other, and something with replication has to be broken that is resulting in the GPO folders missing between the DC’s or not having identical folder rights. We should not have to directly access the folder security properties and change anything, it should be handled by Windows.<\/p>\n
I feel like I’ve exhausted the options available to me shy of deleting and recreating GPO’s which I am reluctant to do because they can be elaborate, and even GPO’s that I’m just changing seem to be having issues after I touch them. Has anyone been through this situation and have some pointers or anything that I can try to push along to my server guys to try since they can access the DC’s?<\/p>","upvoteCount":3,"answerCount":6,"datePublished":"2020-07-10T13:53:48.000Z","author":{"@type":"Person","name":"markmazurkiewicz","url":"https://community.spiceworks.com/u/markmazurkiewicz"},"suggestedAnswer":[{"@type":"Answer","text":"
I am experiencing some GPO Replication issues that trying to resolve with my server team is resulting in a finger pointing match like a false start during a football game.<\/p>\n
I have been trying to make some new GPO’s for both testing and production purposes, make them in the Group Policy utility, assign their groups and when I do a GPUpdate I get “The processing of Group Policy failed. Windows attempted to read the file \\Path\\to\\gpt.ini was not successful”<\/p>\n
Since we have a multi-DC environment I went individually to each DC and this is where I’m seeing problems. The “baseline” DC has no issues. Between our other 2 domain controllers I am seeing that either the \\Policies{identifier} folder is missing, or it may exist but when I check its security properties it tells me that I don’t have access to read the contents of the folder.<\/p>\n
Back in the Status screen of the GPO I can see the domain controllers with replication in progress saying that SysVol may be Inaccessible, or has ACLs listed.<\/p>\n
My server guys restarted the replication service one time and said that “it was fixed” even though they did not verify that GPO’s were replicating which I verified that they were not. It is my understanding that GPO replication (and associated folder rights) are handled automatically by the DC servers and should just be copies of each other, and something with replication has to be broken that is resulting in the GPO folders missing between the DC’s or not having identical folder rights. We should not have to directly access the folder security properties and change anything, it should be handled by Windows.<\/p>\n
I feel like I’ve exhausted the options available to me shy of deleting and recreating GPO’s which I am reluctant to do because they can be elaborate, and even GPO’s that I’m just changing seem to be having issues after I touch them. Has anyone been through this situation and have some pointers or anything that I can try to push along to my server guys to try since they can access the DC’s?<\/p>","upvoteCount":3,"datePublished":"2020-07-10T13:53:48.000Z","url":"https://community.spiceworks.com/t/gpo-replication-issues/768844/1","author":{"@type":"Person","name":"markmazurkiewicz","url":"https://community.spiceworks.com/u/markmazurkiewicz"}},{"@type":"Answer","text":"
Have you run something like the AD replication status too to prove that there is an issue?<\/p>\n
https://www.microsoft.com/en-us/download/details.aspx?id=30005<\/a><\/p>\n Tel them that updates have been known to bork permissions so they are full of shit.<\/p>","upvoteCount":1,"datePublished":"2020-07-10T13:59:18.000Z","url":"https://community.spiceworks.com/t/gpo-replication-issues/768844/2","author":{"@type":"Person","name":"rockn","url":"https://community.spiceworks.com/u/rockn"}},{"@type":"Answer","text":" Check the DFS replication logs on each DC. Also run “repadmin /showrepl” on a DC to see if any errors show up.<\/p>","upvoteCount":0,"datePublished":"2020-07-10T15:56:32.000Z","url":"https://community.spiceworks.com/t/gpo-replication-issues/768844/3","author":{"@type":"Person","name":"Farva06","url":"https://community.spiceworks.com/u/Farva06"}},{"@type":"Answer","text":" You need to make sure your DNS is in order and then if repadmin doesn’t show the problem move on to running DCDIAG on all DC’s.<\/p>","upvoteCount":0,"datePublished":"2020-07-10T15:59:49.000Z","url":"https://community.spiceworks.com/t/gpo-replication-issues/768844/4","author":{"@type":"Person","name":"da-schmoo","url":"https://community.spiceworks.com/u/da-schmoo"}},{"@type":"Answer","text":" I would say to check ALL DCs IP address setting to see what was entered in the 1st, 2nd & 3rd DNS server.<\/p>\n Then check if all the sites are properly listed in Domain Sites & Services and all DCs are in the correct sites (subnets). Then worse case is to “replicate now” using Domain Sites & Services to force replication among the DCs.<\/p>","upvoteCount":1,"datePublished":"2020-07-11T09:33:51.000Z","url":"https://community.spiceworks.com/t/gpo-replication-issues/768844/5","author":{"@type":"Person","name":"adrian_ych","url":"https://community.spiceworks.com/u/adrian_ych"}},{"@type":"Answer","text":" Hi. 16-Year MVP (14 years in Group Policy.)<\/p>\n So far, all good suggestions. If it helps, here’s my guide to troubleshooting this: 03: Troubleshooting Group Policy Replication Problems - PolicyPak<\/a><\/p>\n Nothing to sell here; hope it helps you.<\/p>","upvoteCount":0,"datePublished":"2020-07-11T15:33:49.000Z","url":"https://community.spiceworks.com/t/gpo-replication-issues/768844/6","author":{"@type":"Person","name":"jeremy-policypak","url":"https://community.spiceworks.com/u/jeremy-policypak"}}]}}
\n