Results 1 to 4 of 4

Thread: GPO not working!

  1. #1
    Join Date
    Apr 2011
    Posts
    58

    GPO not working!

    HI, I’m running a server at my office with several clients. In order to control Internet Explorer on client workstations I have created a GPO using Group Policy Management snap-in and set a home page on IE with a favorites folder containing 5 urls. I don’t know why this GPO was not working. So to check it I ran Group Policy Modeling wizard whose result says the GPO was denied and the reason given was "Empty" .

    Any idea what is meant by this? How can make the GPO work to control Internet explorer? Please help.

  2. #2
    Join Date
    Sep 2004
    Posts
    136

    Re: GPO not working!

    First of all I would like to where does the particular policy should apply on your client workstations? I will suggest you better run gpresult or rosp.msc on those workstations and see what do you get. Also, whenever you get some GPO problem, the very first thing you need to check is GPO. Just check if it is working fine.

  3. #3
    Join Date
    Apr 2011
    Posts
    58

    Re: GPO not working!

    Thank you very much for the help LeonL. As you suggested i checked DNS. There was some problem which i successfully resolved with our FQDN. Apart from this i also ran the gpresult and the output is as follows:

    Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
    Copyright (C) Microsoft Corp. 1981-2001

    Created On 11/24/2004 at 8:21:50 AM

    RSOP results for COACD\bunnyb on CTMTESTLAB1 : Logging Mode
    ------------------------------------------------------------

    OS Type: Microsoft Windows XP Professional
    OS Configuration: Member Workstation
    OS Version: 5.1.2600
    Domain Name: COACD
    Domain Type: Windows 2000
    Site Name: WallerCreek
    Roaming Profile:
    Local Profile: C:\Documents and Settings\bunnyb
    Connected over a slow link?: No

    COMPUTER SETTINGS
    ------------------
    CN=CTMTESTLAB1,OU=ESG Test,OU=ESG,OU=CSD,OU=COACD,DC=coacd,DC=org
    Last time Group Policy was applied: 11/24/2004 at 7:28:36 AM
    Group Policy was applied from: coasrv01.coacd.org
    Group Policy slow link threshold: 500 kbps

    Applied Group Policy Objects
    -----------------------------
    Default Domain Policy
    SUS AutoUpdates

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
    ESG Logon Policy
    Filtering: Not Applied (Unknown Reason)

    MS Office Install Path
    Filtering: Denied (Security)

    ESG Folder Redirect
    Filtering: Denied (Security)

    Default Domain Policy
    Filtering: Disabled (Link)

    Local Group Policy
    Filtering: Not Applied (Empty)

    Tablet GPO
    Filtering: Not Applied (Empty)

    The computer is a part of the following security groups:
    --------------------------------------------------------
    BUILTIN\Administrators
    Everyone
    BUILTIN\Users
    CTMTESTLAB1$
    Domain Computers
    NT AUTHORITY\NETWORK
    NT AUTHORITY\Authenticated Users

    USER SETTINGS
    --------------
    CN=Bugs Bunny,OU=ESG Test,OU=ESG,OU=CSD,OU=COACD,DC=coacd,DC=org
    Last time Group Policy was applied: 11/24/2004 at 8:14:26 AM
    Group Policy was applied from: coasrv01.coacd.org
    Group Policy slow link threshold: 500 kbps

    Applied Group Policy Objects
    -----------------------------
    Default Domain Policy

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
    Default Domain Policy
    Filtering: Disabled (Link)

    Local Group Policy
    Filtering: Not Applied (Empty)

    SUS AutoUpdates
    Filtering: Not Applied (Empty)

    Tablet GPO
    Filtering: Not Applied (Empty)

    The user is a part of the following security groups:
    ----------------------------------------------------
    Domain Users
    Everyone
    BUILTIN\Administrators
    Remote Desktop Users
    BUILTIN\Users
    REMOTE INTERACTIVE LOGON
    NT AUTHORITY\INTERACTIVE
    NT AUTHORITY\Authenticated Users
    LOCAL
    TPSD GIS FOLDER ACCESS
    Tablet Users
    TPSD GROUP FOLDER ACCESS


    Now what? Please help.

  4. #4
    Join Date
    Oct 2005
    Posts
    144

    Re: GPO not working!

    As far as i know the problem is somewhere with your ACLs in your AD or SYSVOL because I have been through similar situation couple of months ago. What we had done to fix this problem was the following:

    Make sure that your workstation users has read access to the GPO object in AD
    Make sure he also has access to the files in the corresponding directory (GUID) in SYSVOL
    Make sure he has list rights to the root (domain level) of your domain, as retrieving GPO's upon user logon needs this to look trough OU structure.

    Hope it helps.

Similar Threads

  1. Replies: 10
    Last Post: 02-05-2012, 10:55 PM
  2. Replies: 8
    Last Post: 20-12-2011, 11:39 AM
  3. Replies: 3
    Last Post: 27-04-2011, 12:11 AM
  4. Replies: 4
    Last Post: 26-07-2009, 12:37 AM
  5. Replies: 1
    Last Post: 03-07-2008, 09:32 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,512,316.38988 seconds with 17 queries