ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    GPO issue

    IT Discussion
    mapped drive gpo
    8
    32
    2.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • WLS-ITGuyW
      WLS-ITGuy @flaxking
      last edited by

      @flaxking said in GPO issue:

      So the library GPO is linked somewhere above this user's OU and is using security filtering to apply to the library security group only?
      Have Domain Computers been given read permission?

      List of GPOs:

      alt text

      GPOs in the OU:

      alt text

      WLS-ITGuyW NDCN 2 Replies Last reply Reply Quote 0
      • WLS-ITGuyW
        WLS-ITGuy @WLS-ITGuy
        last edited by WLS-ITGuy

        @WLS-ITGuy Library GPO v2 was a start fresh GPO to test if it was something with the way I did the first GPO but nothing has changed. Security Filtering is set to Authenticated Users.

        The Faculty GPO is set the same way as the Library GPO with Security Filtering. And the two mapped drives attach just fine.

        1 Reply Last reply Reply Quote 0
        • NDCN
          NDC @WLS-ITGuy
          last edited by

          @WLS-ITGuy said in GPO issue:

          @flaxking said in GPO issue:

          So the library GPO is linked somewhere above this user's OU and is using security filtering to apply to the library security group only?
          Have Domain Computers been given read permission?

          Not sure if I understand your questions exactly, I'll post some screenshots when I get back in the office.

          That question is due to the topic discussed here: https://blogs.technet.microsoft.com/askds/2016/06/22/deploying-group-policy-security-update-ms16-072-kb3163622/

          It sounds like you don't actually have things set up that way though so probably not the problem.

          @WLS-ITGuy said in GPO issue:

          @flaxking said in GPO issue:

          So the library GPO is linked somewhere above this user's OU and is using security filtering to apply to the library security group only?
          Have Domain Computers been given read permission?

          List of GPOs:

          alt text

          GPOs in the OU:

          alt text

          OK so the user is in the WLS-Faculty group. The two GPOs there will apply. It sounds like that is happening as expected.

          You say the user is a member of the library group but I don't see you mention where that group lives in the AD structure. Is the library group in the WLS-Library OU?

          1 Reply Last reply Reply Quote 0
          • EddieJenningsE
            EddieJennings @WLS-ITGuy
            last edited by

            @WLS-ITGuy said in GPO issue:

            @EddieJennings said in GPO issue:

            @WLS-ITGuy said in GPO issue:

            @scottalanmiller said in GPO issue:

            @WLS-ITGuy said in GPO issue:

            @JasGot said in GPO issue:

            @WLS-ITGuy said in GPO issue:

            It isn't being applied.

            How many Domain Controllers?

            2 - Checked both and both show the correct GPO

            Check from a client machine, though, too.

            Hmmm. Not hitting the client machine.

            Meaning it's not listed when you run gpresult /r (or gpresult /r /scope:computer), or it's listed but not being applied?

            gpresult shows the Faculty GPO as being applied but not the Library GPO

            What's the listed reason for it?

            Where I am, unknown reason, is usually because of inheritance blocking, but from the screenshots how shared, that's not going to be the issue.

            10112eff-be6f-4d7a-92c9-ab0356ef5e3d-image.png

            WLS-ITGuyW 1 Reply Last reply Reply Quote 0
            • WLS-ITGuyW
              WLS-ITGuy @EddieJennings
              last edited by

              @EddieJennings said in GPO issue:

              @WLS-ITGuy said in GPO issue:

              @EddieJennings said in GPO issue:

              @WLS-ITGuy said in GPO issue:

              @scottalanmiller said in GPO issue:

              @WLS-ITGuy said in GPO issue:

              @JasGot said in GPO issue:

              @WLS-ITGuy said in GPO issue:

              It isn't being applied.

              How many Domain Controllers?

              2 - Checked both and both show the correct GPO

              Check from a client machine, though, too.

              Hmmm. Not hitting the client machine.

              Meaning it's not listed when you run gpresult /r (or gpresult /r /scope:computer), or it's listed but not being applied?

              gpresult shows the Faculty GPO as being applied but not the Library GPO

              What's the listed reason for it?

              Where I am, unknown reason, is usually because of inheritance blocking, but from the screenshots how shared, that's not going to be the issue.

              10112eff-be6f-4d7a-92c9-ab0356ef5e3d-image.png

              Correct. I do not get any Not Applied (Unknown Reason) errors or Denied errors.

              EddieJenningsE 1 Reply Last reply Reply Quote 0
              • EddieJenningsE
                EddieJennings @WLS-ITGuy
                last edited by EddieJennings

                @WLS-ITGuy said in GPO issue:

                @EddieJennings said in GPO issue:

                @WLS-ITGuy said in GPO issue:

                @EddieJennings said in GPO issue:

                @WLS-ITGuy said in GPO issue:

                @scottalanmiller said in GPO issue:

                @WLS-ITGuy said in GPO issue:

                @JasGot said in GPO issue:

                @WLS-ITGuy said in GPO issue:

                It isn't being applied.

                How many Domain Controllers?

                2 - Checked both and both show the correct GPO

                Check from a client machine, though, too.

                Hmmm. Not hitting the client machine.

                Meaning it's not listed when you run gpresult /r (or gpresult /r /scope:computer), or it's listed but not being applied?

                gpresult shows the Faculty GPO as being applied but not the Library GPO

                What's the listed reason for it?

                Where I am, unknown reason, is usually because of inheritance blocking, but from the screenshots how shared, that's not going to be the issue.

                10112eff-be6f-4d7a-92c9-ab0356ef5e3d-image.png

                Correct. I do not get any Not Applied (Unknown Reason) errors or Denied errors.

                Ah, so the GPO isn't listed anywhere when you run gpresult /r (or gpresult /r /scope:computer) on the client computer, not even under "The following GPOs are not applied because they were filtered out" sections.

                Forgive me, if I seem to be missing something obvious.

                1 Reply Last reply Reply Quote 0
                • DashrenderD
                  Dashrender @WLS-ITGuy
                  last edited by

                  @WLS-ITGuy said in GPO issue:

                  I have a user who is in the Faculty OU

                  OK that's pretty straight forward

                  but is part of the library group as well.

                  How is the user part of the library group?

                  WLS-ITGuyW 1 Reply Last reply Reply Quote 0
                  • WLS-ITGuyW
                    WLS-ITGuy @Dashrender
                    last edited by

                    @Dashrender said in GPO issue:

                    @WLS-ITGuy said in GPO issue:

                    I have a user who is in the Faculty OU

                    OK that's pretty straight forward

                    but is part of the library group as well.

                    How is the user part of the library group?

                    I created a library security group under the Library OU that has all employees that are workers in the library.

                    DashrenderD 1 Reply Last reply Reply Quote 0
                    • DashrenderD
                      Dashrender
                      last edited by

                      2868a96a-13bc-4ac5-a137-7512d6e00cf4-image.png

                      1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @WLS-ITGuy
                        last edited by

                        @WLS-ITGuy said in GPO issue:

                        @Dashrender said in GPO issue:

                        @WLS-ITGuy said in GPO issue:

                        I have a user who is in the Faculty OU

                        OK that's pretty straight forward

                        but is part of the library group as well.

                        How is the user part of the library group?

                        I created a library security group under the Library OU that has all employees that are workers in the library.

                        OK - I'm not sure that GPOs will be applied to security groups that are in OUs - I think only User and Computer objects get GPOs applied to them.

                        1 Reply Last reply Reply Quote 1
                        • DashrenderD
                          Dashrender
                          last edited by

                          I would change this up by applying your GPOs to the OU above these WLS OUs, then set filters to only apply to the users you want.

                          So in the case of the Library, you've already created a security group, so you'll grant permissions to that group.

                          Then you'll need to create a WLS-Faculty security group and do the same with it's GPO.

                          WLS-ITGuyW 1 Reply Last reply Reply Quote 1
                          • WLS-ITGuyW
                            WLS-ITGuy @Dashrender
                            last edited by

                            @Dashrender said in GPO issue:

                            I would change this up by applying your GPOs to the OU above these WLS OUs, then set filters to only apply to the users you want.

                            So in the case of the Library, you've already created a security group, so you'll grant permissions to that group.

                            Then you'll need to create a WLS-Faculty security group and do the same with it's GPO.

                            So the GPOs would be at 'domain level' not in the OU level...Like this?

                            alt text

                            Then I apply the security groups from there? That makes sense.

                            pmonchoP DashrenderD 2 Replies Last reply Reply Quote 0
                            • pmonchoP
                              pmoncho @WLS-ITGuy
                              last edited by

                              @WLS-ITGuy said in GPO issue:

                              @Dashrender said in GPO issue:

                              I would change this up by applying your GPOs to the OU above these WLS OUs, then set filters to only apply to the users you want.

                              So in the case of the Library, you've already created a security group, so you'll grant permissions to that group.

                              Then you'll need to create a WLS-Faculty security group and do the same with it's GPO.

                              So the GPOs would be at 'domain level' not in the OU level...Like this?

                              alt text

                              Then I apply the security groups from there? That makes sense.

                              Correct. Now any user in the Domain (aka located in any OU), within the security group you created should have the GPO applied.

                              Side note - I ALWAYS make sure I set security filter BEFORE I enable the GPO. The last thing you want is some user logging in after you save the GPO and getting access to items they should not.

                              WLS-ITGuyW 1 Reply Last reply Reply Quote 1
                              • WLS-ITGuyW
                                WLS-ITGuy @pmoncho
                                last edited by WLS-ITGuy

                                @pmoncho said in GPO issue:

                                @WLS-ITGuy said in GPO issue:

                                @Dashrender said in GPO issue:

                                I would change this up by applying your GPOs to the OU above these WLS OUs, then set filters to only apply to the users you want.

                                So in the case of the Library, you've already created a security group, so you'll grant permissions to that group.

                                Then you'll need to create a WLS-Faculty security group and do the same with it's GPO.

                                So the GPOs would be at 'domain level' not in the OU level...Like this?

                                alt text

                                Then I apply the security groups from there? That makes sense.

                                Correct. Now any user in the Domain (aka located in any OU), within the security group you created should have the GPO applied.

                                Side note - I ALWAYS make sure I set security filter BEFORE I enable the GPO. The last thing you want is some user logging in after you save the GPO and getting access to items they should not.

                                It's funny you mention that... 😄

                                1 Reply Last reply Reply Quote 1
                                • DashrenderD
                                  Dashrender @WLS-ITGuy
                                  last edited by

                                  @WLS-ITGuy said in GPO issue:

                                  @Dashrender said in GPO issue:

                                  I would change this up by applying your GPOs to the OU above these WLS OUs, then set filters to only apply to the users you want.

                                  So in the case of the Library, you've already created a security group, so you'll grant permissions to that group.

                                  Then you'll need to create a WLS-Faculty security group and do the same with it's GPO.

                                  So the GPOs would be at 'domain level' not in the OU level...Like this?

                                  alt text

                                  Then I apply the security groups from there? That makes sense.

                                  yeah - you could do it at the domain level - I personally wouldn't. I'd make a new OU, and put your WLS-faculity and WLS-Library in that new OU.. then apply your GPOs to that new one you created. But that's just me.

                                  1 Reply Last reply Reply Quote 1
                                  • 1
                                  • 2
                                  • 2 / 2
                                  • First post
                                    Last post