GPO and Logon scripts not working so lekka.

EasyUp Web Hosting

EasyUp Web Hosting
Company Rep
Joined
Mar 18, 2008
Messages
8,517
Reaction score
43
Location
Alberton
Hey Guys,

I have a very strange problem, but with a MS environment, what else can you expect.

First, the network setup:
7 Servers, one being a DC(Server 2003).
10/100mbps network with POE.
+-20 Users.

This is only at head office. We have other offices as well.

So, we had a request to change the screen saver on everyone's pc to the same custom made screen saver. We then found out that the screen saver doesn't work on Windows 7 64bit pcs. The screen saver was originally installed to the c:\windows\system32 folder, but to solve the problem, we had to move it to the c:\windows folder.

Now, the problem is, I have my own GPOs here at head office and block inheritance of other GPOs. I didn't create a GPO for my users, because I waited for the problem to be fixed first, as most of my users are running Win7 64bit.

Somehow the "screen saver" GPO was applied to my users' pcs and now they are getting the error. I have gone through my GPO settings over and over again and I can't see how they got it. I even created my own GPO for screen saver settings, but this isn't replacing the current settings.

I also have a GPO for logon scripts, which was very basic. Disconnect map network drive and map them again. I created a registry file to change the registry settings for the screen saver and changed my logon script to merge it. When I edit the registry, I can see that it has been changed.

I did run a Group Policy Modeling on one of the usernames to check what GPOs are applied to her and they are all correct.

My problem is, even thought the registry and windows personalization is showing correctly, it is still somehow using the incorrect settings for the screen saver, eg c:\windows\system32\"screensaver".scr

I know deleting the user profile and creating it again, will solve this, but that isn't an option at all. The only reason why I know this, is because it's been a windows bug since forever, at least I see it that way. Back in the day when I was first playing with GPOs, I used a Server 2003 DC and Winxp test pc and the first GPO setting that was applied, never got changed after I changed it on the GPO settings. I always had to delete the profile and when I created a new one, I would get the new settings.

I have changed the "screen saver" GPO last week already, so I know it's not because of replication not done yet. I have also tried gpupdate /force with no effect as well.

What is there to do?
 
Use "gpupdate /force" on your clients and check event viewer to see which policies were in-fact applied.
GP Modelling sometimes confuses the issue as it doesn't always show what is really happening when you have conflicting Policies & login-scripts.

Check the "Group Policy Inheritance" tab to see which policies are in-fact being applied for your OU.
Also check to see if the screensaver policy doesn't have "enforced" enabled.
It's "no override" in older versions of Group Policy Management.

If it's enabled then you'll have to disable it.

"enforced" overrides "block" - always.


http://technet.microsoft.com/en-us/library/cc757050(WS.10).aspx
 
Like bubba said - enforced overrides block or inheritance. You can start by downloading command line 'rgprefresh' if you want to force gpo's to pc remotely (no need to gpupdate /force on local pc then) - unless you have firewalls enabled on the pc's then it wont work unless you open ports. Extra info there, use it dont use it.

Best bet is - delete the gpo object in gpo management. Then, revert the 'registry file to change settings' to remove or change the setting you applied back to normal. let it propegate for a day or so. Check the modelleing and see which GPO is applying most of the settings in a user's gpo. (like 'Default Domain' etc - seems trivial but this helped alot in other issues I had where I couldnt get settings or policies to change). Set the desired setting you initially set to DISABLED in the GPO. Make sure its enforced too.

You also might want to make sure the GPO you deleted is ACTUALLY deleted out of your sysvol\policies folder. You can check this in your registry to see which ID is the policy you want to get rid of. Sometimes, especially 2003, you delete the GPO object in management but the policy remains in the ID in the sysvol.

Had lots of this k@k before so if you have a query - lemme know, I probably have a workaround for you.

Cheers!
 
Top
Sign up to the MyBroadband newsletter
X