|
Question : applying group policy in a domain
|
|
I"m trying to implement group policy for a small domain running a windows 2000 server DC but I"m running into some difficulty. First of all I created an OU and created serveral user accounts under this OU. I assigned a group policy object explicitly to this OU and set it up accordingly.
Everything appears ok but when I log on as a user in this OU from a workstation anywhere on the network, the policy is not applying in the least. I ran gpresult.exe on a workstation in the domain and pasted below the log-
User Group Policy results for:
RUN-RITE\S6
Domain Name: RUN-RITE Domain Type: Windows NT v4
Roaming profile: (None) Local profile: C:\Documents and Settings\S6
The user is a member of the following security groups:
LookupAccountSid failed with 1789. \Everyone BUILTIN\Users LookupAccountSid failed with 1789. LookupAccountSid failed with 1789. LookupAccountSid failed with 1789. LookupAccountSid failed with 1789. LookupAccountSid failed with 1789. \LOCAL NT AUTHORITY\INTERACTIVE NT AUTHORITY\Authenticated Users
###############################################################
Last time Group Policy was applied: Monday, December 23, 2002 at 1:48:15 PM
###############################################################
Computer Group Policy results for:
RUN-RITE\WARRENWORKSYS$
Domain Name: RUN-RITE Domain Type: Windows NT v4
The computer is a member of the following security groups:
BUILTIN\Administrators \Everyone BUILTIN\Users LookupAccountSid failed with 1789. LookupAccountSid failed with 1789. NT AUTHORITY\NETWORK NT AUTHORITY\Authenticated Users
###############################################################
Last time Group Policy was applied: Thursday, December 26, 2002 at 1:31:06 PM Group Policy was applied from: saylorsburg.run-rite.com
===============================================================
The computer received "Registry" settings from these GPOs:
Local Group Policy Default Domain Policy
=============================================================== The computer received "Security" settings from these GPOs:
Default Domain Policy
=============================================================== The computer received "EFS recovery" settings from these GPOs:
Local Group Policy Default Domain Policy
If I log on as user S6 locally on the domain controller itself, group policy is then applied successfully, on any remote machines it fails.... what am I overlooking?
|
Answer : applying group policy in a domain
|
|
I had a similar problem, the reason my policy was failing was that the clients hadn't picked up the DNS server. If you don't have a DNS server the DC needs to be set up as one for it to work. I also remember reading somewhere that Group Policies created in a 2000 AD Domain will n ot take effect on an NT4 machine, and looking at your printout out it looks as though your clients are NT4.
Here's a couple of Microsoft resources that may help.
http://support.microsoft.com/default.aspx?scid=kb;en-us;246108 http://support.microsoft.com/default.aspx?scid=kb;en-us;165064
Dave
|
|
|
|