User policy being applied to Win 2012 servers, but not 2008
hello,
have deployed first windows 2012 server domain , having odd issue gp being applied when shouldn't.
ou structure follows:
users:
ou=location1,ou=companyusers,dc=company,dc=local
ou=location2,ou=companyusers,dc=company,dc=local
etc
servers:
ou=appservers,ou=servers,dc=company,dc=local
ou=sqlservers,ou=servers,dc=company,dc=local
etc
2012 server located in 'appservers' ou (along number of 2008, 2008 r2, 2003 servers). user account in 'location1' ou.
have number of gp's - 1 of them called 'location - drive maps' , configured drive mappings via built in gp preferences accomplish this. applies users within organisation member of 'mapdrives-workstations' security group. there no wmi filters in place. linked @ root of users ou:
ou=companyusers,dc=company,dc=local
if log 2003/2008 server, drives don't map - expect have not linked gp @ servers level, , isn't inheriting ou's @ different levels within tree. if log 2012 server however, drives mapping , gpresult shows receiving gp. doing same on 2008 machines not show gp being applied.
has me confused. should gp have applied 2008 machines seeing logging in user account in right user ou? or has 2012 server got greater smarts allows happen?
ran gp modeling wizard across both servers, , according each should getting drive maps anyway, last few years have never had drives map on 2008 machines. assumed correct.
don't have gp inheritance blocked anywhere. have rebuilt gp's built when domain consisted of 2003 servers only, no change above. domain running @ 2003 functional level (needed legacy systems).
ideas?
have deployed first windows 2012 server domain , having odd issue gp being applied when shouldn't.
ou structure follows:
users:
ou=location1,ou=companyusers,dc=company,dc=local
ou=location2,ou=companyusers,dc=company,dc=local
etc
servers:
ou=appservers,ou=servers,dc=company,dc=local
ou=sqlservers,ou=servers,dc=company,dc=local
etc
2012 server located in 'appservers' ou (along number of 2008, 2008 r2, 2003 servers). user account in 'location1' ou.
have number of gp's - 1 of them called 'location - drive maps' , configured drive mappings via built in gp preferences accomplish this. applies users within organisation member of 'mapdrives-workstations' security group. there no wmi filters in place. linked @ root of users ou:
ou=companyusers,dc=company,dc=local
if log 2003/2008 server, drives don't map - expect have not linked gp @ servers level, , isn't inheriting ou's @ different levels within tree. if log 2012 server however, drives mapping , gpresult shows receiving gp. doing same on 2008 machines not show gp being applied.
has me confused. should gp have applied 2008 machines seeing logging in user account in right user ou? or has 2012 server got greater smarts allows happen?
ran gp modeling wizard across both servers, , according each should getting drive maps anyway, last few years have never had drives map on 2008 machines. assumed correct.
don't have gp inheritance blocked anywhere. have rebuilt gp's built when domain consisted of 2003 servers only, no change above. domain running @ 2003 functional level (needed legacy systems).
ideas?
sorry, away weekend.
the authenticated users group removed policy default. have custom group applies instead.
i realised had loop processing enabled on gp object....whoops!
soon remove policy applied.
Windows Server > Group Policy
Comments
Post a Comment