Group Policy ForumDiscussion of Group Policy on Windows Server© 2009 Microsoft Corporation. All rights reserved.Thu, 26 Nov 2009 03:57:52 Z6e8f35e0-c0eb-458f-94db-265b5a1db267http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/72357e38-7345-4b77-9734-aca45cb39e7chttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/72357e38-7345-4b77-9734-aca45cb39e7cHealthCareTechhttp://social.technet.microsoft.com/Profile/en-US/?user=HealthCareTechServer 2003 'my documents' folder redirection not working after roaming profile errorServer 2003 SP2 and all clients are XP pro SP3.  <br/>Recently encountered a problem that prevented some users roaming profiles from loading correctly.  That has been resolved and all RP issues seem to be working just fine. <br/><br/>However, previously working redirected folders are not working for these same users.  It is looking to the local drive for folders/files that are still on the server share.<br/><br/>I've checked all permissions and everything looks correct.<br/><br/>I've tried enforcing the GPO for redirected folders but it made no difference.<br/><br/>I've done a gpupdate /force on all the workstations with no luck.<br/><br/>It seems the roaming profile has just lost the redirected folders GP.  I'm tempted to just stop folder redirection for these users (policy is set to return folders/files to the users local drive) and then restart folder redirection, but that will be a very large file transfer for many of these users.<br/><br/>Any ideas?<br/><br/>Thanks!Wed, 25 Nov 2009 18:49:11 Z2009-11-26T03:57:52Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/fd14978c-13b5-4688-ad46-15e2ba00f661http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/fd14978c-13b5-4688-ad46-15e2ba00f661EMS SysAdminhttp://social.technet.microsoft.com/Profile/en-US/?user=EMS%20SysAdminSpecify Different Homepages depending on relationship to the FirewallI am an OU manager in a W2k3 AD setup within a single domain for a city government. I currently use GP to enforce our department's SharePoint portal as a homepage. The portal is not available outside the city's Firewall. Is there a way that I can configure the Group Policy for the homepage to NOT be enforced when the computer is outside the firewall? When users launch IE from outside the FW, the get an error page, since the local ISP's DNS servers have no way to get to my portal. Somebody from MS mentioned something about using sites to me last year at a conference, but I don't remember any specifics. I appreciate any suggestions.<br/><br/>-DarrylMon, 16 Nov 2009 21:36:24 Z2009-11-26T03:38:01Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/fe3d106a-fa39-498f-b788-5cd5ed5d8c06http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/fe3d106a-fa39-498f-b788-5cd5ed5d8c06VIctor Avileshttp://social.technet.microsoft.com/Profile/en-US/?user=VIctor%20AvilesSCE uninstallHello everyone,<br/><br/><br/>After an uninstall of SCE 2007 I have a policy that I just can't find.  According to my report it's located in &quot;<span class=sectionTitle>Application Error Reporting/Corporate Error Reporting&quot;.  However, when I search for it, the entire <span class=sectionTitle>Application Error Reporting&quot; is not listed.  Any clues?</span></span>Fri, 13 Nov 2009 15:46:39 Z2009-11-26T02:51:12Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/288aaf48-0c6d-4555-b25c-b285f885d6b0http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/288aaf48-0c6d-4555-b25c-b285f885d6b0ThePriesthttp://social.technet.microsoft.com/Profile/en-US/?user=ThePriestWindows firewall ruleHi,<br/><br/>I created a GPO for my 2 Servers that have Windows Firewall enable. Am trying to set the &quot;Define Port Exception&quot; in my Domain Profile GPO and it's not getting applied. What is strange is that I have other settings under the same GPO that are getting applied. <br/><br/>Windows 2003 SP2 DC's<br/><br/>Help please.Tue, 10 Nov 2009 14:01:15 Z2009-11-26T02:26:44Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/3941aaf5-af02-409a-b84b-db9970796a32http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/3941aaf5-af02-409a-b84b-db9970796a32sabo_ehttp://social.technet.microsoft.com/Profile/en-US/?user=sabo_eWindows XP and VPN Client<p>We are trying to get an Windows XP SP3 client to work when it is on our network with group policy/drive mapping but when it is on an external network we would like no group policy or drive mappings.     We found one web resource that said to delete the GPO registry settings on logoff or shutdown.    <br/><br/>Have anyone ever done this and if so could you give us some direction.</p>Tue, 27 Oct 2009 11:06:27 Z2009-11-26T02:07:49Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/be3d3a0c-ac30-4078-8078-13fd03278b70http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/be3d3a0c-ac30-4078-8078-13fd03278b70wlj3http://social.technet.microsoft.com/Profile/en-US/?user=wlj3deploy intermediate certificate via GPOTrying to install an intermediate certificat with Group Policy managment console and am only allowed to deploy root cersts with the wizard. Is there some place where step by step instructions exist in order to accomplish this with gpo on plain ole windows 2003 server?Wed, 25 Nov 2009 14:37:47 Z2009-11-26T01:44:16Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/8351aae1-1b0b-42e5-bc3f-71f83ee29987http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/8351aae1-1b0b-42e5-bc3f-71f83ee29987wlj3http://social.technet.microsoft.com/Profile/en-US/?user=wlj3intermediate certificate deployment via gpo win2k3 serverWe have deployed a trusted root cert with gpo on windows 2003 server. We would like to deply the intermediate certifcate in the same manner. is there an addon or othe sttep by step process that can be used to do this with GPO editor?Tue, 24 Nov 2009 14:54:50 Z2009-11-26T01:44:10Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/a1ebfe81-421e-4630-8c1f-8068222ee533http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/a1ebfe81-421e-4630-8c1f-8068222ee533Kyle LePrevosthttp://social.technet.microsoft.com/Profile/en-US/?user=Kyle%20LePrevostWallpaper via Group Policy and Windows 7My organization has recently deployed Windows 7 Professional (RTM, VLK) to our two computer labs. Users who log onto these machines get a wallpaper that has my organizations name and logo, deployed via group policy. After the upgrade to Win7 Pro, the wallpaper does not apply correctly. I began troubleshooting whether this was a result of conflicting policies, but even after making a new user, and placing him in a test OU with only the wallpaper GPO applied, this still happens.<br/> <br/> <img src="http://imgur.com/ZvtFa.png" alt="" width=716 height=572> <img src="http://imgur.com/xU3og.png" alt="" width=870 height=696> <img src="http://imgur.com/CUcR3.png" alt="" width=536 height=202> <img src="http://imgur.com/3qK9A.png" alt="" width=763 height=396>Thu, 27 Aug 2009 13:50:21 Z2009-11-26T00:33:35Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/222b92ea-562b-406f-af44-24c623c521d8http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/222b92ea-562b-406f-af44-24c623c521d8Vard0http://social.technet.microsoft.com/Profile/en-US/?user=Vard0IE8 Group Policy not applied at logon<p>Hi <br/><br/>I have a group policy with IE-specific settings.  The problem I have is that the policy does not get applied at logon.  It only gets applied if I run a gpupdate / force or if I make a change to the policy settings.  I have had a read through this post (<a href="http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/a698c5b2-4889-487d-be49-1320901efa82">http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/a698c5b2-4889-487d-be49-1320901efa82</a>) but it does not quite resolve my issue.  <br/><br/>The Group Policy I have configured has computer settings disabled and gets applied to all users.  Apart from the IE settings, this GPO also has the following setting:<br/><br/>User Configuration -&gt; Administrative Templates -&gt; System/Group Policy:-<br/><br/><span style="color:#000000">Group Policy refresh interval for users: Enabled</span><br/><br/><br/><br/>I then have another group policy which has the user settings disabled and gets applied to all computers.  Amongst other settings this GPO has the following options set:<br/><br/>Computer Configuration -&gt; Administrative Templates -&gt; System/Group Policy:- <br/><br/>Internet Explorer Maintenance policy processing: Enabled <br/>Process even if the Group Policy objects have not changed: Enabled <br/><br/>Would I need to enable these computer configuration settings in the IE policy as well?<br/><br/>Thanks</p>Wed, 25 Nov 2009 16:32:39 Z2009-11-25T22:31:51Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/08f22d4e-ec8f-4508-8d86-f67bfbfeee3fhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/08f22d4e-ec8f-4508-8d86-f67bfbfeee3fchris_rmyershttp://social.technet.microsoft.com/Profile/en-US/?user=chris_rmyersRDP Login of domain user on vista and 2k8 fails in domain with one way trustTo be honest I don't know if this is a GP issue or not But I suspect it is. I have a 2K8 domain setup with 4 DC's  with a one way trust to the corp domain. (see nltest results below)<br/> So far every vista and 2008 client that I have tried to RDP into fails with. <br/> <h2 style="margin:10pt 0in 0pt"><a name="_Q1:_Windows_Server"><span style="font-size:medium"><span style="color:#4f81bd"><span style="font-family:Cambria">&quot;The security database on the server does not have a computer account for this workstation trust relationship.&quot;</span> </span> </span> </a></h2> <br/> So far I have added domain users (from the domain we trust) to the remote desktop group and insured they had terminal services logon right. I have also tried adding them to the administrators group. <br/> I have also created groups on the DC with the domain user names. Added them with FULL privledges on the computer account in the domain and then added that group to both the remote desktop users and administrators group and still RDP  fails. when using the domain\user information<br/> <br/> At this point I have had my fingers in almost every GP I can find dealing with terminal services etc so If you need me to pull additional information just let me know<br/> <h2 style="margin:10pt 0in 0pt"><a name="_Q1:_Windows_Server"><span style="font-size:medium"><span style="color:#4f81bd"></span> </span> </a> <br/></h2> I did see this FAQ <br/> http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/26455b36-26bd-4a44-b594-5a9f67bcd8df#_Q1:_Windows_Server<br/> However Deleting and rejoin the domain have had no affect on any of the machines. Also running nltest /domain_trusts shows<br/> 0: XXXROOT xxxcorp.net (NT 5) (Direct Outbound)  ( Attr: 0x8 )<br/> 1: ESCE.adapps.XX.com (NT 5) ( Forest Tree Root ) (Primary Domain) (Native)<br/> <br/> <br/> <br/> <br/> <br/>Fri, 20 Nov 2009 01:40:47 Z2009-11-25T21:10:32Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/c7df2d6b-df8a-4554-acd4-93f8862ea9d9http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/c7df2d6b-df8a-4554-acd4-93f8862ea9d9stuarty1874http://social.technet.microsoft.com/Profile/en-US/?user=stuarty1874GPO Best Practice (Apply Permissions to folders on Domain Controllers)<p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'">Guys, I’m just looking for a bit of advice on GPO good\best practice.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'">I have a Windows 2003 SP2 domain.<span style="">  </span>Our security people have asked us to apply various settings to the DC’s which include some of the following folders. There’s many more but this is a reasonable sample.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'">%systemroot%</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'">%systemroot%\repair</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'">%systemroot%security</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'">%systemroot%system</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'">%systemroot%system32</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'">I plan to configure these settings as a GPO as we have multiple DC’s. Is it good practice to use a GPO here or should we really be applying these permissions to the folders manually?</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'">The settings they require are around general users (i.e. Everyone, Users, Authenticated Users)</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'">If you need any more information then please feel free to ask.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:11pt;font-family:'Arial Narrow'">Thanks in advance.</span></p>Tue, 11 Aug 2009 17:46:46 Z2009-11-25T19:41:46Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/b13f17bc-114c-4d20-a3b1-61edfb0cb220http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/b13f17bc-114c-4d20-a3b1-61edfb0cb220Jonas_Bsonhttp://social.technet.microsoft.com/Profile/en-US/?user=Jonas_BsonWindows Server 2008 X64 - gpupdate takes 10min - svchost.exe (gpsvc) pid logs 8.5 million events in procmonHello,<br/><br/>We've seen that on our 2008 x64 servers the svchost.exe that holds gpsvc in it takes up alot of CPU-time. Upon further investigation I saw that when it refreshes policies it holds 1 core for 10 minutes. I setup a procmon and filtered it on the pid off the gpsvc-svchost and saw that it logged 8.5 million events.<br/><br/>It keeps looping events where it seems to be checking history-data under &quot;C:\ProgramData\Microsoft\Group Policy\History\&lt;GUIDS&gt;&quot;. <br/><br/>We are using GPPreferences. Has anyone seen anything like this before?<br/><br/>I have the .PML-file from procmon, however its 350MB zipped so I dont know how to attach it to case.Wed, 25 Nov 2009 16:54:28 Z2009-11-25T16:54:30Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/36680803-b2ff-4800-89e2-15f5eadadc71http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/36680803-b2ff-4800-89e2-15f5eadadc71golforfoodhttp://social.technet.microsoft.com/Profile/en-US/?user=golforfoodlock computers after say 30 minutes of inactivityI am new to GPO's and I need to know if there is a GPO that will lock computers (desktops) after 30 minutes of inactivity.  Thank you in advance for your help.<br/><br/>GregWed, 25 Nov 2009 00:21:48 Z2009-11-25T16:36:26Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/47b78ad1-ec17-41dd-b3aa-58c3c6fc688ahttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/47b78ad1-ec17-41dd-b3aa-58c3c6fc688aKaron Whttp://social.technet.microsoft.com/Profile/en-US/?user=Karon%20Wcertificate autoenrollment Settings with citrix and certificate-based authentication <p>I have a citrix environment with a serious lag time for citrix logon. In the citrix forums (thread <span lang=EN></span><a href="http://forums.citrix.com/thread.jspa?threadID=252740"><span style="text-decoration:underline"><span style="font-size:x-small;color:#0000ff"><span style="font-size:x-small;color:#0000ff"><span style="text-decoration:underline"><font size=2 color="#0000ff"><font size=2 color="#0000ff"><span lang=EN>http://forums.citrix.com/thread.jspa?threadID=252740</span></font></font></span></span><span style="text-decoration:underline"><font size=2 color="#0000ff"></font></span></span></span></a> ), there has been much discussion regarding the Computer Config\Windows Settings\Security Settings\Public Key Policies\Autoenrollment Settings.  It appears that if that setting is edited, whether to enable or disable it, it will add significantly to the citrix logon time. <br/><br/>It has been demonstrated that if the policy is recreated without editing this setting, the logon time drops from 35 plus to around 10 seconds. My question is what affect would this have on certificate-based authentication for the wireless and e-mail encryption capabilities that we may be using int the future if we do not actively enable this setting?</p> <p> </p><hr class="sig">Karon WMon, 16 Nov 2009 21:06:50 Z2009-11-25T15:20:33Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/62a4427c-d5a7-4d5b-867c-0f5c6e921315http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/62a4427c-d5a7-4d5b-867c-0f5c6e921315StPaulsMVhttp://social.technet.microsoft.com/Profile/en-US/?user=StPaulsMVIE, Disable 'Automatically Detect Settings' Via GPOHi guys,<br/> <br/> We have recently been having a small problem with IE, whereby the 'automatically detect settings' check box will get ticked - resulting in our users not being able to traverse our proxy server. <br/> <br/> I use the User Configuration &gt; Policies &gt; Windows Settings &gt; IE Maintenance &gt; Connection to set up our proxy settings, however I can't see an option to explicitly disable the 'automatically detect settings' check box.<br/> <br/> Is this located somewhere else in an admin template, or am I simply missing an option that is right in front of me?<br/> <br/> Thanks.<br/> <br/> GlenMon, 09 Nov 2009 03:10:59 Z2009-11-25T10:11:37Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/459acbad-a9c4-44d5-a469-7eca76b642cahttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/459acbad-a9c4-44d5-a469-7eca76b642cadanstanlhttp://social.technet.microsoft.com/Profile/en-US/?user=danstanlNew Canon Plotter added to environment users can map to it but when you look at the Properties of the Plotter its showing Hewlett-Packard not canon<span style="font-family:arial, sans-serif;font-size:13px;border-collapse:collapse">Please forgive me if this is not the correct place to ask this but I am stumped. Here is the situation we have users that are using roaming profiles. They map to and connect to a newly installed canon IFP3000 plotter among alot of other Hewlet-Packard 8150DN printers. The Plotters reside on a separete print server than the HP printers. But when you look at the Printing Preferences of the newly mapped Plotter its says Hewlett-Packard not Canon like it should. <div>I had user log into another PC and map this plotter its fine you can see the correct properties of it does not have the HP printing preferences from their own PC its only from their PC. I can map it and its fine. Its only on certain HP xw6400 workstations that its not working it seems .I had this user log in and unmap ALL printers and then log out and back in and then remap the plotter same thing. So we thought it was a profile issue renamed his profile so now user is using a &quot; clean&quot; profile same issue on his PC. Had user log in and I opened the Registry and unmap each printer and see it is disappearing from each reg entry in HKLM/Printers.</div> <div>So I am thinking its a local Registry setting that is not deleting. I reimaged this user's machine and they are fine now go figure but I have other having this issue and I do not want to have to reimage anymore PC to fix this problem. On this one PC its like after we map this plotter its not bringing the drivers for the canon and using the HP ones for some reason and I cannot tell where in the registry or in windows XP Pro SP2 I need to look.</div> <div><br/></div> <div>Any Ideas where in the registry to look for a fix I have never ever seen this problem before and now its happening with another users I would rather not have to reimage and reinstall all their applications? Anyone else seen this before? Maybe if I localize this user that is having the issue then unmap ALL printers and remap then put back to roaming then restart that might fix it I am not sure the thing is its only on certain machines so i don't think its a profile issue.</div> <div> Canon and HP forums not much help either</div> <div><br/></div> <div><br/></div> <div>Help!!!</div> </span>Tue, 24 Nov 2009 02:44:33 Z2009-11-25T08:40:43Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/4d4d9d3c-9065-4c10-a176-2bd5b68f6194http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/4d4d9d3c-9065-4c10-a176-2bd5b68f6194johenghttp://social.technet.microsoft.com/Profile/en-US/?user=johengWindows 7: Changes in GPO user configuration only applies once (and it's not a preference setting)I'm currently trying to set up a test environment for Windows 7. I have problems with the user settings, though - the machines applies the policies OK (as far as I can can tell by running gpresult). When a user logs on for the first time, the current settings are applied. But if I make a change in the settings, for instance setting a theme, that setting won't apply unless the user profile is deleted on the PC and the user logs on again, thus recreating the profile. At that point the user profile has the new changes.<br/><br/>any ideas?Tue, 24 Nov 2009 15:56:54 Z2009-11-25T07:30:33Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/0f27d20d-c9de-4b57-a04d-9049bd69c11ahttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/0f27d20d-c9de-4b57-a04d-9049bd69c11amicromac1http://social.technet.microsoft.com/Profile/en-US/?user=micromac1plug and playOk, so this is probably an incredibly stupid question, but since i don't feel like googling for hours to find out i thought i would ask here.  I am wanting to use a Blackberry device for tethering but the network is locked down so that plug and play is disabled.  Is it possible that if the software/drivers are installed on the machine that i will be able to use the device or will the device itself also have to be installed by an admin?  I am trying to figure a good alternative out on this one.  Thanks for any help and sorry for such a newbie question!!!Fri, 20 Nov 2009 16:43:33 Z2009-11-25T07:27:18Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/0098de9f-3c09-4347-a6c0-78861b8275aehttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/0098de9f-3c09-4347-a6c0-78861b8275aedavincicodehttp://social.technet.microsoft.com/Profile/en-US/?user=davincicode802.1x Wired Auto Config / Machine authentication mode<p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 36pt"><span style="font-size:9.5pt;color:black;font-family:Verdana">Hi All,<br/>I am in the process of configuring 1500 machines with <span style="text-decoration:underline">802.1x authentication</span>. We are running Windows XP SP3 on all machines.<br style=""><br style=""></span></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 36pt"><span style="font-size:9.5pt;color:black;font-family:Verdana">For our test device the following needed to occur for 802.1x to authenticate successfully:</span></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 36pt"><span style="font-size:9.5pt;color:black;font-family:Verdana">- In the Services, Wired Auto Config had to be started and set to Automatic</span></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 54pt"><span style="font-size:9.5pt;color:black;font-family:Verdana">- In the Local Area Connection Properties (Authentication tab) </span></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 90pt"><span style="font-size:9.5pt;color:black;font-family:Verdana"><br/>- Enable IEEE 802.1x authentication (selected)<br/>- Choose a network authentication method:  Smart card or other Certificate<br/>- Use a certificate on this computer (Use simple certificate selection (Recommended) - selected)<br style=""><br style=""></span></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 54pt"><span style="font-size:9.5pt;color:black;font-family:Verdana"><br/>However, after using the above settings still had no luck with 802.1x authentication. <br/>The following line of code had to be inserted into the Local Area Connection XML file and then copied back to the original LAN XML file for it to work:<br/><br/></span></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 54pt;tab-stops:159.75pt"><span style="color:black"><span style="font-size:small;font-family:Times New Roman"> </span></span><span style="font-size:small"><span style="font-family:Times New Roman"><strong><span style="color:black">&lt;authMode&gt;machine&lt;/authMode&gt;</span></strong><span style="color:black"></span></span></span></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 81pt;text-indent:-18pt;tab-stops:36.0pt"><span style="font-size:small"><span style="font-family:Times New Roman"><strong><span style="color:black"> </span></strong></span></span><span style="font-size:9.5pt;color:black;font-family:Verdana"><br/>Does anyone know a way in which the settings listed above:</span></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 54pt;text-indent:-18pt"><span style="font-size:9.5pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 72pt;text-indent:-18pt;tab-stops:list 72.0pt"> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 72pt;text-indent:-18pt;tab-stops:list 72.0pt"><strong style=""><span style="font-size:9.5pt;color:black;font-family:Verdana"></span></strong></p> <span style="font-size:9.5pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 54pt"><span style="font-size:9.5pt;color:black;font-family:Verdana"></span></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 72pt;text-indent:-18pt;tab-stops:list 72.0pt"><span style="font-size:9.5pt;color:black;font-family:Verdana"><span style="">-<span style="font:7pt &quot;Times New Roman&quot;">         </span></span></span><strong style=""><span style="font-size:9.5pt;color:black;font-family:Verdana">Wired Auto Config Service: Started and set to Automatic</span></strong></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 54pt"><strong style=""><span style="font-size:9.5pt;color:black;font-family:Verdana"> </span></strong></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 72pt;text-indent:-18pt;tab-stops:list 72.0pt"><span style="font-size:9.5pt;color:black;font-family:Verdana"><span style="">-<span style="font:7pt &quot;Times New Roman&quot;">         </span></span></span><strong style=""><span style="font-size:9.5pt;color:black;font-family:Verdana">Local Area Connection properties as above</span></strong></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 54pt"><strong style=""><span style="font-size:9.5pt;color:black;font-family:Verdana"> </span></strong></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 72pt;text-indent:-18pt;tab-stops:list 72.0pt"><span style="font-size:9.5pt;color:black;font-family:Verdana"><span style="">-<span style="font:7pt &quot;Times New Roman&quot;">         </span></span></span><strong style=""><span style="font-size:9.5pt;color:black;font-family:Verdana">Local Area Connection Authentication mode: Machine</span></strong></p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 54pt"> </p> <p class=MsoNormal style="background:white;margin:0cm 0cm 0pt 54pt"><strong style=""><span style="font-size:11pt;color:black;font-family:Verdana"><br/>Can be set via Group Policy?</span></strong></p> <p> </p>Wed, 25 Nov 2009 00:34:15 Z2009-11-25T04:32:15Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/6a0224ee-33c4-4705-bcc5-54c08ea6884dhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/6a0224ee-33c4-4705-bcc5-54c08ea6884dsupersonic_oasishttp://social.technet.microsoft.com/Profile/en-US/?user=supersonic_oasisNot allowing searching for peopleHi all,<br/> <br/> We run Active Directory on Windows 2003 servers with Windows XP clients.  I do not want my users to be able to go to Start -&gt; Search -&gt; For People.  Is there a group policy setting to disallow that?Fri, 20 Nov 2009 14:23:13 Z2009-11-25T02:36:43Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/95ed9e96-a990-4a25-a842-03a4acf5a7b0http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/95ed9e96-a990-4a25-a842-03a4acf5a7b0Arctic_Cruiserhttp://social.technet.microsoft.com/Profile/en-US/?user=Arctic_CruiserInternet Explorer language settingsHi,<br/>Can i configure Internet Explorer Language settings with group policy (version 6 or 7)<br/>(IE - Tools - Internet Options... -Languages)<br/><span style="font-size:x-small"><br/>i have try to make registery based adm, but somewhy it's allways replaced on logon with<br/>english settings, have run rsop, policy is apply okay.<br/>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International]<br/>&quot;AcceptLanguage&quot;=&quot;fi&quot;<br/><br/>Is that possible to configure language settings, if so, how?<br/>Thanks for advice</span>Fri, 20 Nov 2009 07:10:58 Z2009-11-25T01:57:41Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/4a43b793-65e3-480c-b5a0-99eeaf4cf633http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/4a43b793-65e3-480c-b5a0-99eeaf4cf633lchandlerhttp://social.technet.microsoft.com/Profile/en-US/?user=lchandlerError while deploying printers to XP from 2K8 server using User Preferences (Client Side Extensions) - Error 0x8000ffffHi All,<br/> <br/> When trying to deploy a printer via the user preferences in a gpo the client event log has event id 4098.<br/> <br/> Client machine is a XP SP3 machine fully patched via WSUS2 SP3. The user logging on has no local account privileges on the workstation and the Client Side Extensions are installed.<br/> <br/> In the GPO I have a shared printer from the directory, set it as default and also tried targeting the users of the OU that the Policy is linked to.<br/> <br/> From everything I have researched this should be a straight forward task - what am I missing ??<br/> <br/> Cheers,<br/> <br/> Lee.<br/> <br/>Mon, 23 Nov 2009 01:01:52 Z2009-11-24T23:55:00Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/bc5997cf-b8a6-449f-b699-38daa4070428http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/bc5997cf-b8a6-449f-b699-38daa4070428xroadtripxhttp://social.technet.microsoft.com/Profile/en-US/?user=xroadtripxGroup Policy - Computer startup scripts- logging success and failuresI am trying to creating and testing group policy software installations for .exe files.  I have them running in the startup script of computer configuration in Group Policy.  They are running fine.  However I am wondering how I can generate a report that shows all the computers that the group policy ran on and whether or not the software installation was successful or not.  I can use GPinventory for .msi file installs, which is ok but not great,  but it does not show successful .exe installs. I am trying not to purchase any 3rd party software as I only need this for a few applications.  Any  help would be greatly appreciated.Thu, 19 Nov 2009 19:54:43 Z2009-11-24T21:25:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/72e4e99d-e400-4d51-8283-908534008294http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/72e4e99d-e400-4d51-8283-908534008294Sunny_dadwalhttp://social.technet.microsoft.com/Profile/en-US/?user=Sunny_dadwalNot able to access ADD Remove programmes in Windows Sever 2003Hi  <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"><br/></div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">i am not able to  access <strong style="font-weight:bold;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">add remove programmes.</strong></div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"><strong style="font-weight:bold;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"><br/></strong></div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"> The user rights are:</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"><br/></div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">C:\winnt\system32\INETSRV&gt;net user administrator</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">User name                    Administrator</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Full Name                    </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Comment                      Built-in account for administering the computer/domain</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">User's comment               </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Country code                 000 (System Default)</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Account active               Yes</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Account expires              Never</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"><br/></div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Password last set            7/21/2009 12:16 PM</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Password expires             Never</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Password changeable          7/23/2009 12:16 PM</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Password required            Yes</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">User may change password     Yes</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"><br/></div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Workstations allowed         All</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Logon script                 </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">User profile                 </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Home directory               </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Last logon                   11/20/2009 10:05 AM</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"><br/></div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Logon hours allowed          All</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"><br/></div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Local Group Memberships      *Account Operators    *ACSADMG              </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *ACSUSRG              *Administrators       </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *AESADMG              *AESUSRG              </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *APIOADMG             *APIOUSRG             </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *APLOCG               *APZADMG              </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *APZUSRG              *Backup Operators     </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *CDHFTPUSRG           *CPSUSRG              </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *CPUSRG               *DHCP Administrators  </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *DnsAdmins            *EVENTVIEWERG         </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *FMSADMG              *FMSUSRG              </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *FTPUSRG              *IIS_WPG              </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *MASADMG              *MASUSRG              </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *MCSADMG              *MCSUSRG              </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *MTS Impersonators    *Pre-Windows 2000 Comp</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *Replicator           *SECUREADMG           </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *Server Operators     *SGSADMG              </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *SGSUSRG              *STSADMG              </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *STSUSRG              *Terminal Server Licen</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *Windows Authorization</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Global Group memberships     *Domain Admins        *Group Policy Creator </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *Domain Controllers   *Schema Admins        </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                             *Enterprise Admins    *Domain Users         </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">The command completed successfully.</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">                                                             </div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"><br/></div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">kindly Suggest.</div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial"><br/></div> <div style="font-weight:inherit;font-style:inherit;font-family:inherit;padding:0px;margin:0px;border:0px initial initial">Sunny</div> </div>Fri, 20 Nov 2009 06:05:44 Z2009-11-24T09:53:02Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/d2193949-b6aa-4908-937f-fed5843e06ddhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/d2193949-b6aa-4908-937f-fed5843e06ddDominic Scheideggerhttp://social.technet.microsoft.com/Profile/en-US/?user=Dominic%20Scheidegger"other user" account picture in Windows 7hi there,<br/> <br/> id like to force a user acc default picture for the &quot;other user&quot; when i change the user on the logon by clicking &quot;other user&quot; - the user pic frame is empty... can i change that, resp. where is the picture for the &quot;other user&quot; located or where should it be saved?<br/> registry hack?<br/> <br/> thanks - dominicThu, 19 Nov 2009 13:41:33 Z2009-11-24T07:38:58Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/d80e265a-848e-4f35-8b3c-055ec154adfbhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/d80e265a-848e-4f35-8b3c-055ec154adfbMA_7ABKhttp://social.technet.microsoft.com/Profile/en-US/?user=MA_7ABKServer CoreDoes DC on server core support Group Policy Modeling?.<br/> i'm running  group policy modelin from a member serer via group policy management tool but getting the following error:<br/> &quot;The domain controller you have selected does not have the RSoP planning mode functionality available. Please select a different domain controller.&quot;<br/>Thu, 19 Nov 2009 12:32:56 Z2009-11-24T06:54:17Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/41558dae-65ac-4baf-bd3f-3bb347108e00http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/41558dae-65ac-4baf-bd3f-3bb347108e00BALR1415http://social.technet.microsoft.com/Profile/en-US/?user=BALR1415Is there a way to list local group policy settingsI am helping a school implement Group Policy. Currently they lock down XP machines by using gpedit on the Local Group Policy; but they have not documented what settings they have used. This is a Windows Server 2003 AD with XP domain computers to I have downloaded the Server 2003 Group Policy Excel document and plan to open Local GP on a few workstations and checkoff what I see. <br/>But is there a script or tool that I could run to create a txt or Excel file that has the status of Local GP settings? Or could I copy the local pol file and play it back on another computer? <br/>Sat, 21 Nov 2009 19:05:27 Z2009-11-24T06:17:29Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/da03b33d-661e-4f5e-bdb3-4dc06ec0e169http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/da03b33d-661e-4f5e-bdb3-4dc06ec0e169sgnaylorhttp://social.technet.microsoft.com/Profile/en-US/?user=sgnaylorGPO Settings Revert back to Original Settings after gprefreshHello,<br/><br/>I am trying to update some audit settings on my default domain controllers policy.  I make the changes, hit OK close the window, do a gprefesh, and they are back to what they originally were.  I checked inherit settings and there are none, and no block settings.  If it were a save error, I think I would get a permissions error or something to that effect.<br/><br/>Any suggestions?Thu, 19 Nov 2009 02:34:49 Z2009-11-24T06:14:45Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/95509985-04dc-4e3b-91bb-ae09384a2aa0http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/95509985-04dc-4e3b-91bb-ae09384a2aa0a.saravanakumarhttp://social.technet.microsoft.com/Profile/en-US/?user=a.saravanakumarGPO is not applying in Win 7 when the user act as a part of local admin in client machine.Hi All,<br/> <br/>          I am facing one big problem in win 7, when the user part of local admin in win 7 client the GPO is not applying. If they are not into local admin the GPO is working properly<br/> <br/>          Anyone help help me to troubleshoot this problem?Wed, 18 Nov 2009 09:05:42 Z2009-11-24T05:45:26Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/55a4c7a2-544b-418a-955e-4e29ff59102ahttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/55a4c7a2-544b-418a-955e-4e29ff59102aDagmar Heideckerhttp://social.technet.microsoft.com/Profile/en-US/?user=Dagmar%20HeideckerEditing the same GPO in Windows Server 2008 and Windows 7 --> confusionHi,<br/><br/>I came over this while testing the BitLocker Recovery Password feature, but it is not a BitLocker-realted but a Group Policy-related question:<br/>I have got a domain with Windows Server 2008 DCs only and Windows Vista and Windows 7 clients.<br/><br/>I created a Group Policy Object using GPMC on Windows Server 2008 and configured the setting &quot;Control Panel Setup: Enable advanced startup options&quot; to be enabled. The explanation to this setting states &quot;Requirements: at least Windows Vista&quot;. This setting only workd for my Vista clients but not for the Windows 7 clients (although the policy definetely applied to the Windows 7 machines). <br/><br/>I installed RSAT on a Windows 7 machine and opened exactly the same GPO and it showed different configuration options (the ones which are new to Windows Server 2008 R2 and Windows 7). The &quot;Require aditional authentication at startup&quot; setting still exists but the explanation says: &quot;Requirements: Windows 7 familiy&quot;. However, in Windows 7 RSAT I can see the changes made in Windows Server 2008 but to make the setting available for both Windows Vista and Windows 7 I have to open the GPO from both systems (or configure two GPOs)?<br/><br/>Is this behavior by design? Is it documented somewhere?<br/><br/>Kind regards,<br/>DagmarTue, 03 Nov 2009 10:49:34 Z2009-11-24T03:04:06Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/336377db-e0cb-4c8e-b7c7-01b7c11c0e27http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/336377db-e0cb-4c8e-b7c7-01b7c11c0e27Matt Jones.http://social.technet.microsoft.com/Profile/en-US/?user=Matt%20Jones.Group policy lockdown for Windows Server 2008 Terminal Servers <font face=Arial size=2>Hi,</font> <p align=left>I have a mixed Windows Server 2003/2008 environment where terminal servers exist (both 2003 and 2008 terminal servers). We would like to prevent users from being able to view the contents of the navigation pane, i.e. folders and favourite links, etc when opening the <strong>save as</strong>,<strong> open </strong>or <strong>Windows Explorer</strong> as this environment requires to be completely locked down. We would like the users accessing remote apps to only be able to navigate to their <strong>My Documents </strong>folder (redirected to their home directory) and other areas such as mapped drives, etc.<br><br>We have been able to lockdown the menus in Windows Explorer for all 2003 Terminal Servers but cannot do the same for the 2008 servers. I realise that you can remove the Navigation Pane manually by going to <b>Organize&gt;Layout </b>and un-checking <b>Navigation Pane</b>, but is there anyway of permanently setting this so a user would be unable to re-check it? Ideally we would like to do this using Group Policy but so far have been unable to find any settings related to remove this from Windows Explorer in 2008. </p> <p align=left>The domain controller is running Windows Server 2003 Ent Edition R2 SP2 with the 2008 group policy extensions installed. One of the 2008 terminal servers has the Group Policy Management Console feature enabled and is being used to configure the group policy extensions available for the 2008 Servers.</p> <p align=left> Thanks in advance</p>Mon, 20 Oct 2008 11:22:53 Z2009-11-24T01:06:20Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/cd8cde79-56d6-4378-9647-c7e37ba4667ahttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/cd8cde79-56d6-4378-9647-c7e37ba4667aTrustyMhttp://social.technet.microsoft.com/Profile/en-US/?user=TrustyMRemove 'Network' access button from Explorer in Windows 2008 R2Good day!<br/>We have: Windows Server 2008 R2 with &quot;Remote Desktops&quot; role installed. (DC is also under Windows Server 2008 R2)<br/>We need: to remove (or disable) &quot;Network&quot; access button in browser in Navigation pane for a group of users with Group Policy.<br/>We could not find such parameter in Group Policy Editor.<br/>Can anybody help us to solve the problem?<br/>Any help is appreciated.<br/>P.S. If it cannot be done, please, tell us how to make computers in &quot;Network&quot; invisible (hide) to this group of users.Mon, 09 Nov 2009 07:03:47 Z2009-11-24T02:03:08Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/a40db002-dc4b-4102-8fde-0083a60b1e1ahttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/a40db002-dc4b-4102-8fde-0083a60b1e1akg-thttp://social.technet.microsoft.com/Profile/en-US/?user=kg-tGroup Policy Preference - Computer Configuration, Shortcuts<p>I'm attempting to create a shortcut using Preferences under Computer Configuration. My target is on a share on a clustered 2008 file server. The application of the preference fails with Error suppressed. [ hr = 0x80070002 &quot;The system cannot find the file specified.&quot; ]. When I apply the same shortcut using User configuration instead, it applies fine. I want the shortcut to apply to a group of computers rather than users, and I'd rather not use loopback. Is there something I'm missing?</p>Thu, 19 Nov 2009 22:23:27 Z2009-11-24T08:51:33Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/708ee0b9-f8d9-4a9c-9fe5-a2119a5be692http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/708ee0b9-f8d9-4a9c-9fe5-a2119a5be692Eric Chathamhttp://social.technet.microsoft.com/Profile/en-US/?user=Eric%20ChathamAdd search criteria to AD Users, Contacts and Groups search. Hello,<br/><br/>I need to add search criteria to the AD Users, Contacts and Groups Search Utility?  I want to add an attribute to the search list (facsimileTelephoneNumber).  Would this involve modifying the AD schema?  We have some users that manage our AD accounts (Account Operator role status) that need to update Fax Numbers.  Can someone help me with this?  Thank you.<br/><br/>Original Question asked here:<br/><a href="http://social.microsoft.com/Forums/en-US/whatforum/thread/ce51f3e4-31ba-40b2-8382-404273509c14/">http://social.microsoft.com/Forums/en-US/whatforum/thread/ce51f3e4-31ba-40b2-8382-404273509c14/</a>Wed, 11 Nov 2009 17:09:03 Z2009-11-23T17:26:25Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/20b52a1d-ca94-46d8-ac36-28bc05d57eaahttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/20b52a1d-ca94-46d8-ac36-28bc05d57eaaDerek Dhttp://social.technet.microsoft.com/Profile/en-US/?user=Derek%20DRemove Desktop/My Documents LinkHi Everyone,<br/><br/>Could you please advise whether a GPO exists to remove the shortcuts to the Desktop and My Documents links when you are in a File-Open or File-Save screen?<br/><br/>Thanks,<br/>DFri, 20 Nov 2009 22:43:59 Z2009-11-23T09:57:20Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/23e5bbfa-ee80-40a4-a121-06f8320f8077http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/23e5bbfa-ee80-40a4-a121-06f8320f8077FraserMorganhttp://social.technet.microsoft.com/Profile/en-US/?user=FraserMorganGroup Policy Object HelpHello. The company I work for has decided that all workstations and users must use the company logo as their desktop background. Rather than do this manually...which is a LOT of users I have tried to define this via GPO. We are running Windows Server 2000 and the client machines are Windows XP Pro. I have specified in the domain default GPO that 1) Active desktop is enabled 2) users are prevented from making changes 3) specified the path of the relevant file and made certain that this path is accessible to client machines. In this case <a>\\server-name\desktops\logo.bmp</a> but there appears to be no change in any of the desktop settings.<br/><br/>I have done numerous restarts and gpupdate /force and the nothing seems to be working. Gpresult seems to suggest that everything is working as intended. I've run out of ideas to try to get the image to display. I am not even getting a blank desktop with no image, just whatever background the user has set. If it would be helpful, I could provide screen shots of my GPO settings to see if I've done something wrong and not picked up on it.<br/><br/>Thanks,<br/>FraserWed, 18 Nov 2009 13:46:57 Z2009-11-23T09:10:49Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/f8739691-c750-483d-a4c3-b4a5ea1becdehttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/f8739691-c750-483d-a4c3-b4a5ea1becdeSukeljumahttp://social.technet.microsoft.com/Profile/en-US/?user=SukeljumaGroup policy resettingis there a way to take a hard drive out of a 2000 server and delete a file or folder to force a reset for all group policy's i have all the privilages of administratoradministrator to run and install but i disabled scripting and access to the gp editting also i have taken this out of the domainSun, 22 Nov 2009 01:09:18 Z2009-11-23T08:54:11Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/9a39ffc1-0985-4c4f-b326-1df4d5ff8a00http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/9a39ffc1-0985-4c4f-b326-1df4d5ff8a00Chris Blairhttp://social.technet.microsoft.com/Profile/en-US/?user=Chris%20BlairFolder Redirection and Offline foldersI am running a 2003 Native Active Directory with all XP SP 3 clients. <br/> <br/> I have setup folder redirection for just the My Documents folder. Which is working fine. I have also setup offline folder sync so the users can access files while offline. <br/> <br/> The problem is when a user who is setup for folder redirection, which includes offline folder sync, logs into a computer that isn't there &quot;main&quot; computer, the sync happens. So, I am looking for a way to limit just the offline sync to happen on either the users &quot;main&quot; computer or at least a group of computers.<hr class="sig">Thanks, ChrisMon, 16 Nov 2009 16:07:41 Z2009-11-23T05:37:07Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/10598e31-6be0-4016-9a46-d5446787760fhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/10598e31-6be0-4016-9a46-d5446787760fvittal reddyhttp://social.technet.microsoft.com/Profile/en-US/?user=vittal%20reddynetwork path not foundyou might not have permissions to access this network resource.contact the administrator<hr class="sig">vittal reddyFri, 20 Nov 2009 14:34:27 Z2009-11-25T10:18:13Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/f4efdf01-fa0b-43c2-9533-9fe188c4658bhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/f4efdf01-fa0b-43c2-9533-9fe188c4658bradical93http://social.technet.microsoft.com/Profile/en-US/?user=radical93Blocking ICMP can affect the Group Policy Implementation...Good day guys,<br/><br/>     Any explanation, information and some links that blocking ICMP (ping command) from some firewall which is not to ping the A.D. Domain Controller where the Group Policy Settings resides for all clients computers?<br/><br/>     Any experience and information and related links that will discuss, and requirements is highly appreciated.<br/><br/>     Thank you guys...Fri, 20 Nov 2009 14:43:29 Z2009-11-23T02:56:24Z