Questions tagged [group-policy]

Group Policy is a built-in feature of the Microsoft Windows operating systems. Group Policy allows administrators to automatically configure myriad options within the OS. These policies can be configured, and applied, either locally to the computer via Local Group Policy or remotely within an Active Directory environment.

Group Policy is a built-in feature of the Microsoft Windows operating systems. Group Policy allows administrators to automatically configure myriad options within the OS. These policies can be configured, and applied, either locally to the computer via Local Group Policy or remotely within an Active Directory environment.

Microsoft has added Group Policy Preferences Client Side Extensions, formerly a third-party tool called PolicyMaker, to its in-support Windows OSes. The CSEs greatly extend the number features which can be configured via Group Policy.

See the following links for more details.

http://gpsearch.azurewebsites.net - Searchable list of configurable group policies http://blogs.technet.com/grouppolicy - Microsoft’s official Group Policy blog http://blogs.technet.com/askds - Ask Directory Services is the official blog from Microsoft engineers supporting group policy and other related AD technologies

3186 questions
1
vote
0 answers

Allow log on locally custom message

I recently moved into a new position and we have a few computer labs that are currently restricting access by running a script on logon that checks the user's group membership and if not in the correct group, displays an error message telling them…
Ian
  • 91
  • 1
  • 9
1
vote
1 answer

Why are Active Directory password resets ignoring the Password History Count rule?

I have a situation whereby an AD domain I am working with has a sensible enough password policy in place (e.g., sufficiently high PasswordHistoryCount, MinPasswordLength settings etc.). I can change a given user's password via PowerShell easily…
1
vote
1 answer

Modify "Policy" without Group Policy: Best Practice?

I have a need to address some policy settings on a number of machines that are not on a domain. Specifically, we are dealing with a technology conference lab, built with loaner machines from various vendors, and I would like to lock down certain UI…
Gordon
  • 175
  • 6
1
vote
0 answers

Group Policy: delegate definition of local group memberships

In a heavily branched organization with Active Directory, I am working with the head IT department and we are delegating control to parts of the branch OU to the respective branch admins. Our delegation concept currently handles group policies in a…
the-wabbit
  • 40,737
  • 13
  • 111
  • 174
1
vote
1 answer

WMI filter is ignored by certain clients in group policies

The applied WMI filter to a group policy is ignored by certain clients. It works fine on other clients, returns the correct value, but on some clients it is just not applied and does not appear in group policy results. Group Policy: Computer…
marsh-wiggle
  • 2,145
  • 5
  • 29
  • 45
1
vote
0 answers

Windows Server 2008 R2 - allow more time to reset password

Good morning everyone! I apologize if this has been asked - I have tried searching every where I can think of, to include the search bar here on serverfault. I work as an IT technician at a high school, and during our first week of school, we have…
1
vote
0 answers

Different group results for GPResult -vs- "net users MyName /domain"?

I have a user that is set up as a member of "My Test Group". When I am logged in as that user and do a "GPResult /R" that user does not appear to be a member of "My Test Group" but when I do "Net users *MyUserName* /Domain" they do appear to be a…
John S
  • 125
  • 6
1
vote
1 answer

GPO will only work after an Admin logs in with same policy being applied to the admin account

I have created a GPO that will put a shortcut on our receptionists desktops that is linked to a file share that is full of Internet shortcuts for Insurance verification. This has worked for almost 90% of my users. I have that remaining 10% that just…
CZobell
  • 11
  • 2
1
vote
1 answer

Unable to run gpupdate after changing domains

I recently moved a Windows Server 2008 R2 machine from one domain to another. Everything appears fine on the surface. It attached to the new domain and I can remote to and log into it using an account on the new domain. There are forward and…
Tony
  • 457
  • 3
  • 11
  • 23
1
vote
1 answer

Migration from Windows server 2003 to 2012 R2

We went from Windows 2003 R2 to Windows Server 2012 R2. I did the following: Joined 2012 server to the 2003 domain Installed Active Directory Domain Services (aka dcpromo) on the server Transferred all roles to new server within fsmo maintenance…
dzint
  • 11
  • 3
1
vote
1 answer

Possibilities and best practises regarding deployment of GPO for the user right "Log on as a service"

Background I have a case where a developer computer is in a environment where the IT department have set up a forced group policy for the user rights assignment policy "Log on as a service". The policy is set to be forced and not editable and…
Octadrone
  • 11
  • 1
1
vote
1 answer

GPO aren't being applied for some users only because of slow link

I have encountered a situation where all GPO are applied for some user accounts, but only critical GPO get applied for other users because slow link was detected. Our offices are on different coasts and connected via VPN tunnel. Until local server…
1
vote
1 answer

Install RSAT by GPO on Win 8.1

I recently noticed that many Windows 8.1 Pro workstations do not have hidden shares, such as admin$ enabled. I need to have such shares available for remote app deployment. I noticed that RSAT installation automatically enables administrative hidden…
1
vote
0 answers

Group Policy Preferences: Content Advisor disabled

We decommissioned our last Windows 2008 R2 server, and with it goes the ability to edit Internet Explorer Maintenance policy settings. Moving forward is Group Policy Preferences... so, I open up Group Policy Management, create a new GPO > User…
1
vote
1 answer

Cannot reproduce a GPO effect due to server version?

I am running a domain with functional level Windows Server 2008 R2, within this environment I have host machines that run Windows Server 2012 R2. This environment is running nothing custom everything is about as "out-of-the-box" as it can be. I…
user305997
  • 19
  • 1