I have created a group policy object (gpo) that I would like to apply
to most of the users in my active directory (ad). My problem is the
gpo will only apply if the test user (uTest) is a member of the Domain
Admins (DA) security group. I definitely don't want my users to be in
Domain Admins. I'm trying to restrict access. I don't think putting
people in DA is a good way to do this. Here is somebackground:
A) I am running Windows SBS 2003 SP1 as a file server and domain
controller.
B) The test workstation (and all my workstations) is/are running
Windows XP SP2.
C) uTest (my test user) is also member of only two other security
groups (gVTT_Everyone and gVTT_TNS).
Both groups I have created and have set up with minimum access
to shared folders on my server. uTest is not a member of any
built in security groups or
default groups; except for Domain Admins when I want to see the
effect of my gpo.
D) uTest is in an organizational unit (oTest -> uTest).
E) oTest is in an organizational unit also (oVTT -> oTest -> uTest).
F) vtt.local is in my one and only domain (vtt.local - > oVTT ->
oTest -> uTest).
G) My gpo (gpoVTT) is linked to oTest.
H) Sometimes I use Specops Gpupdate to apply my gpo to the
workstation.
I) Sometimes I use Sysinternsals "psexec \\<workstationame>
gpupdate" to
apply gpoVTT to the workstation. Both psexec and specops work as
expected. That is the gpo is applied (but of course only if uTest
is a member of
"Domain Admins"). These tools work well in that many changes are
applied
without me needing to log uTest off or restart the workstation.
On many occasions,
just to be sure, I have loggged uTest off and I have restarted
the test workstation.
J) gpoVTT does the following: restricts the running of some windows
components,
prevents windows updates, hides all drives in windows explorer,
limits what users
can do to their start menus, prevents users from changing their
desk tops, hides
all icons on the desktop, prevents the addition, or deletion of
printers, forces Windows
classic theme, disables screen savers, restricts applets in the
control panel, redirects
my documents, hides start up scripts, forces classic logon, turns
off autoplay, adds
some ports to windows firewall, turns on and prevents users from
turning off windows firewall
(I have disabled the FW so that I can force updates to my test
workstation), And all this
happens if uTest is a member of Domain Admins. Otherwise it does
not.
I have tried the following in vain to resolve this problem:
1) I have removed all other group policy links on my domain
(vtt.local) and all OU except
for the gpo that I am trying to apply (gpoVTT) and...
2) ...I have not removed gpo "Default Domain Controllers Policy"
from OU "Domain Controllers".
I am a little concerned that if I did I might create serious
problems for myself and my users.
3) I have removed "Default Domain Policy" from the domain.
4) I have set the delegation security on all OUs and the gpo itself
for one of the security groups
that uTest is a member of (gVTT_Everyone) to "Full Control".
5) I have set the delegation security on all OUs and the gpo itself
for uTest himself to "Full Control".
6) I have set the delegation security on all OUs and the gpo itself
for my test workstation
(named BALTIMORE) himself to "Full Control".
7) I have put the workstation that I am testing (name is BALTIMORE)
this on in OU
"oTest" (the same one that the gpo is linked to and uTest is
in).
8) I have left the workstation that I am testing all this on in
"Computers" (it's default location).
9) I have deleted BALTIMORE from the AD and used the "New Object -
Computer" wizard to put it
back.
10) I have deleted uTest and oTest and recreated them and done all
these things again.
11) I have enforced and not enforced the gpo link before applying
it.
12) I have linked gpoVTT to the domain and moved my user there. That
is: I have removed the
user from any organizational units.
13) I have made the test workstation (BALTIMORE) a member of Domain
Admins.
Nothing I have done allows the gpo to be applied to uTest on BALTIMORE
unless uTest is a member of Domain Admins. Any suggestions?
Jonathan.
<jonatha...@gmail.com> wrote in message
news:1174183515.6...@n59g2000hsh.googlegroups.com...
gVTT_Everyone: the security group that my test user is a member of.
BALTIMORE: the computer that I'm trying to get this to work on.
I added the group and the computer myself. Authenticated Users was as
you wrote added by default when I created the gpo. I have tried to
resolve my problem by setting permission for all to read and apply and
with full control. Neither do the trick. My gpo will only apply to my
user if he is a member of "Domain Admins"
On Mar 20, 6:57 am, "Dave Nickason [SBS MVP]"
<gwdib...@NOSPAM.frontiernet.net> wrote:
> I gave this a fairly quick read, and can't see what you've got set for
> security filtering. In the Group Policy Management Console, if you select
> the GPO in the left pane, what does it say in the right pane, Scope tab,
> under Security Filtering? By default, the GPO should contain "authenticated
> users." This is where you'd set this, not in Delegation.
>
> <jonathan.elk...@gmail.com> wrote in message
>
> news:1174183515.6...@n59g2000hsh.googlegroups.com...
>
>
>
> > Hello.
>
> > I have created a group policy object (gpo) that I would like to apply
> > to most of the users in my active directory (ad). My problem is the
> > gpo will only apply if the test user (uTest) is a member of theDomain> Admins(DA) security group. I definitely don't want my users to be in
> >Domain Admins. I'm trying to restrict access. I don't think putting
> > people in DA is a good way to do this. Here is somebackground:
>
> > A) I am running Windows SBS 2003 SP1 as a file server and domain
> > controller.
>
> > B) The test workstation (and all my workstations) is/are running
> > Windows XP SP2.
>
> > C) uTest (my test user) is also member of only two other security
> > groups (gVTT_Everyone and gVTT_TNS).
> > Both groups I have created and have set up with minimum access
> > to shared folders on my server. uTest is not a member of any
> > built in security groups or
> > default groups; except forDomain Adminswhen I want to see the
> > happens if uTest is a member ofDomain Admins. Otherwise it does
> > 13) I have made the test workstation (BALTIMORE) a member ofDomain> Admins.
>
> > Nothing I have done allows the gpo to be applied to uTest on BALTIMORE
> > unless uTest is a member ofDomain Admins. Any suggestions?
>
> > Jonathan.- Hide quoted text -
>
> - Show quoted text -
On Mar 20, 6:57 am, "Dave Nickason [SBS MVP]"
<gwdib...@NOSPAM.frontiernet.net> wrote:
> I gave this a fairly quick read, and can't see what you've got set for
> security filtering. In the Group Policy Management Console, if you select
> the GPO in the left pane, what does it say in the right pane, Scope tab,
> under Security Filtering? By default, the GPO should contain "authenticated
> users." This is where you'd set this, not in Delegation.
>
> <jonathan.elk...@gmail.com> wrote in message
>
> news:1174183515.6...@n59g2000hsh.googlegroups.com...
>
>
>
> > Hello.
>
> > I have created a group policy object (gpo) that I would like to apply
> > to most of the users in my active directory (ad). My problem is the
> > gpo will only apply if the test user (uTest) is a member of theDomain> Admins(DA) security group. I definitely don't want my users to be in
> >Domain Admins. I'm trying to restrict access. I don't think putting
> > people in DA is a good way to do this. Here is somebackground:
>
> > A) I am running Windows SBS 2003 SP1 as a file server and domain
> > controller.
>
> > B) The test workstation (and all my workstations) is/are running
> > Windows XP SP2.
>
> > C) uTest (my test user) is also member of only two other security
> > groups (gVTT_Everyone and gVTT_TNS).
> > Both groups I have created and have set up with minimum access
> > to shared folders on my server. uTest is not a member of any
> > built in security groups or
> > default groups; except forDomain Adminswhen I want to see the
> > happens if uTest is a member ofDomain Admins. Otherwise it does
> > 13) I have made the test workstation (BALTIMORE) a member ofDomain> Admins.
>
> > Nothing I have done allows the gpo to be applied to uTest on BALTIMORE
I'd go to the workstation where the policy is not applying and do Start ->
Run -> RSOP.msc, choosing the credentials that you know will fail. This
will give you a console showing all the policies that are applied on that
PC. If you drill down to the policies in question, can you see if there is
a different GPO applying policies there? In other words, is a different
policy trumping the one you're having a problem with?
Is the workstation logging any errors in its system or application log? I
can't think of anything accidental that would cause a policy to be
restricted to a specific user or group, but at least it's something to look
at.
<jonatha...@gmail.com> wrote in message
news:1174419943.7...@o5g2000hsb.googlegroups.com...
And there was an Application error: "Windows has detected that Offline
Caching is enabled on the Roaming Profile share - to avoid potential
profile corruption, Offline Caching must be disabled on shares where
roaming user profiles are stored."
Immediately followed by: "Unable to apply folder redirection policy,
initialization failed."
What does this mean?
...<a coupla tries and about 20 minutes later>....
....errors have reappeared in the application event log:
1) "The Group Policy client-side extension Folder Redirection failed
to execute. Please look for any" Event ID #1085.
2) "Unable to apply folder redirection policy, initialization failed."
Event ID #111.
Regarding error #1) MS's Help and support center has a bunch o' DLL's
that they suggest may need to be re-registered and a bunch of white
papers that I can read on debugging group policy. And no additional
info for #2).
But first I'm gonna go to bed.
I'd create a new policy by r-clicking your test OU and choosing create and
link a GPO here. Leaving everything at its default, create one policy
setting and see what happens. If you get rid of the errors by registering
the DLLs or whatever else you have to do, and the new policy applies as
expected, I'd just dump the whole GPO you're having the problem with and
start again.
<jonatha...@gmail.com> wrote in message
news:1174470230.3...@e1g2000hsg.googlegroups.com...
Incidently the application event error has not gone away even after
the reinstall and disbling the offline caching for the share as
descibed by microsoft here:
http://go.microsoft.com/fwlink/events.asp?EvtSrc=Userenv&EvtCat=None&EvtID=1085&EvtCatID=0&EvtType=Error&EvtTypeID=1&EvtRptTime=1174531311&EvtTZBias=480&CoName=Microsoft%20Corporation&ProdName=Microsoft%c2%ae%20Windows%c2%ae%20Operating%20System&ProdVer=5.1.2600.1106&FileName=userenv.dll&FileVer=5.1.2600.1106
I dunno what to do. I am very frustrated. You know I switched from
Novell to Windows in June and I'm started to regret it.
If you don't want to do that, I'd try to solve the underlying error. Since
a new, blank policy should just simply apply to any OU it's linked to, it
seems that you need to get rid of the 1085 error and see if that changes
anything. Any help here?
http://eventid.net/display.asp?eventid=1085&eventno=1412&source=Userenv&phase=1
<jonatha...@gmail.com> wrote in message
news:1174527928....@l77g2000hsb.googlegroups.com...
I definitely agree with you that I should get rid of this 1085 Event
error before proceeding. I will contact Microsft on Monday. I am
extremely frustrated with Windows as a file server. I have upgraded
from an older Novell Server and can't believe what a hassle two
relatively straight forward taks have been with it. I appreciate that
Windows is trying to control the whole world with their O/S but really
the implementation seems to me to be overly complex and well fraught
with pitfalls. At this point I'm really diapointed.
I will try to resolve the 1085 problem. I have tried a coupl of
things: 1) The first suggestion in the EventId.com article you sent
says add full control permissions to "the share" (which one I wonder)
and NTFS (I sume they mean the directory structure) I did this for one
share and the entire directory structure (from C:\ to all sub-
folders). No luck.
I did have folder redirect in my test gpo. I have taken it out but
noticed that the GPMC reported it still there. So I deleted the gpo
created a new one added one polict (remove Help) and still the
error. ....I'm trying stuff as I write this...I think we're on to
something here. I have just deleted all policies (except for DC and D.
The server won't let you) and RSOP on the workstation is showing that
my test gpo (which no longer exists) is active and has a policy
setting for redirecting the My Documents folder! Hmmmmm?
Is there any way to completely delete all policies from a workstation?
Jonathan.
It'll be interesting to see what ends up being the cause of this - in my
experience, group policy generally works pretty simply and reliably. Or at
the worst, it logs when there's a problem.
<jonatha...@gmail.com> wrote in message
news:1174808078.2...@n59g2000hsh.googlegroups.com...