User policy being applied to Win 2012 servers, but not 2008


hello,

have deployed first windows 2012 server domain , having odd issue gp being applied when shouldn't.

ou structure follows:

users:

ou=location1,ou=companyusers,dc=company,dc=local

ou=location2,ou=companyusers,dc=company,dc=local

etc

servers:

ou=appservers,ou=servers,dc=company,dc=local

ou=sqlservers,ou=servers,dc=company,dc=local

etc

2012 server located in 'appservers' ou (along number of 2008, 2008 r2, 2003 servers). user account in 'location1' ou.

have number of gp's - 1 of them called 'location - drive maps' , configured drive mappings via built in gp preferences accomplish this. applies users within organisation member of 'mapdrives-workstations' security group. there no wmi filters in place. linked @ root of users ou:

ou=companyusers,dc=company,dc=local

if log 2003/2008 server, drives don't map - expect have not linked gp @ servers level, , isn't inheriting ou's @ different levels within tree. if log 2012 server however, drives mapping , gpresult shows receiving gp. doing same on 2008 machines not show gp being applied.

has me confused. should gp have applied 2008 machines seeing logging in user account in right user ou? or has 2012 server got greater smarts allows happen?

ran gp modeling wizard across both servers, , according each should getting drive maps anyway, last few years have never had drives map on 2008 machines. assumed correct.

don't have gp inheritance blocked anywhere. have rebuilt gp's built when domain consisted of 2003 servers only, no change above. domain running @ 2003 functional level (needed legacy systems).

ideas?


sorry, away weekend.

the authenticated users group removed policy default. have custom group applies instead.

i realised had loop processing enabled on gp object....whoops!

soon remove policy applied.



Windows Server  >  Group Policy



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607