locked
Exception calling "OpenDSGpo" with "4" argument(s): "A GPO with ID {0} was not found RRS feed

  • Question

  • Hello , Again I am facing one more issue with UAG DA environment . I am trying to re apply the configuration after deleting the  earlier GPO's . However getting this error .

    UAGDA Group Policy Apply Completed. Elapsed time is 00:02:49.7610564 .
    WARNING: 3 warning(s):
    WARNING:   Couldn't write to GPO 'UAG DirectAccess: Clients
    (GDC-UAG.XXXXLOCAL)' on domain 'agreeya.local'. GPO will not be modified.
    Exception calling "OpenDSGpo" with "4" argument(s): "A GPO with ID {0} was not
    found in the xxxx.local domain."

    I have manually deleted the GPO's on all DC's and have also tried to manually run the script on one of the DC. Earlier as it seems to be some replication issue however I waited for a day after deleting the GPO's and still getting the same error.

    I am running on SP1.

     

    Here is the full Log.

     

    > Executing policy script.
    
    ============ UAGDA Group Policy Apply Started


    ============ Configuring Client GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'
    Trying to create GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local', with apply permissions for the accounts 'NT AUTHORITY\Authenticated yyers'
    > Trying to find GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)'
      Couldn't find GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)'
    > Creating GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local'
      GPO created
    > Trying to find GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' after creating it
      GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' found
    > Reading GPO's apply permissions
    > Setting GPO's apply permissions to the specified accounts:
    > Creating GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)''s apply permissions for account 'NT AUTHORITY\Authenticated yyers'
      Permissions created
    > Setting GPO's read permissions to the specified accounts:
    > Saving GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)''s permissions
    > Done
    Trying to clear all links for GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' in domains 'xxxx.local'
    > Clearing all links for GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local'
      > Done!
    Clearing all links for GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' - done!
    Linking GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' >
        to 'OU=DirectAccess,OU=Workstations,OU=GDC,OU=zz,OU=xxxx Solutions,DC=xxxx,DC=local'
        Linked
    Checking if GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local' is writable.
    > Trying to find GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'
      GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' found
    > Checking if the GPO 'UAG DirectAccess: Clients (GDC-UAG.xxxx.LOCAL)' is writable
    WARNING:   Couldn't write to GPO 'UAG DirectAccess: Clients
    (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'. GPO will not be modified.
    Exception calling "OpenDSGpo" with "4" argument(s): "A GPO with ID {0} was not
    found in the xxxx.local domain."

    ============ Configuring Gateway GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'
    Trying to create GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local', with apply permissions for the accounts 'xxxx.local\GDC-UAG$'
    > Trying to find GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)'
      Couldn't find GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)'
    > Creating GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local'
      GPO created
    > Trying to find GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' after creating it
      GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' found
    > Reading GPO's apply permissions
    > Setting GPO's apply permissions to the specified accounts:
    > Creating GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)''s apply permissions for account 'xxxx.local\GDC-UAG$'
      Permissions created
    > Setting GPO's read permissions to the specified accounts:
    > Creating GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)''s read permissions for account 'NT AUTHORITY\Authenticated yyers'
      Permissions created
    > Saving GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)''s permissions
    > Done
    Trying to clear all links for GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' in domains 'xxxx.local'
    > Clearing all links for GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local'
      > Done!
    Clearing all links for GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' - done!
    Linking GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' >
        to 'DC=xxxx,DC=local'
        Linked
    Checking if GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local' is writable.
    > Trying to find GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'
      GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' found
    > Checking if the GPO 'UAG DirectAccess: Gateways (GDC-UAG.xxxx.LOCAL)' is writable
    WARNING:   Couldn't write to GPO 'UAG DirectAccess: Gateways
    (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'. GPO will not be modified.
    Exception calling "OpenDSGpo" with "4" argument(s): "A GPO with ID {0} was not
    found in the xxxx.local domain."

    ============ Configuring AppServer GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'
    Trying to create GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local', with apply permissions for the accounts ''
    > Trying to find GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)'
      Couldn't find GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)'
    > Creating GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local'
      GPO created
    > Trying to find GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' after creating it
      GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' found
    > Reading GPO's apply permissions
    > Setting GPO's apply permissions to the specified accounts:
    > Setting GPO's read permissions to the specified accounts:
    > Creating GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)''s read permissions for account 'NT AUTHORITY\Authenticated yyers'
      Permissions created
    > Saving GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)''s permissions
    > Done
    Trying to clear all links for GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' in domains 'xxxx.local,zz.xxxx.local,spsocial.yy.xxxx.local,yy.xxxx.local'
    > Clearing all links for GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local'
      > Done!
    > Clearing all links for GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' in domain 'zz.xxxx.local'
      > Done!
    > Clearing all links for GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' in domain 'spsocial.yy.xxxx.local'
      > Done!
    > Clearing all links for GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' in domain 'yy.xxxx.local'
      > Done!
    Clearing all links for GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' - done!
    Checking if GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' in domain 'xxxx.local' is writable.
    > Trying to find GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'
      GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' found
    > Checking if the GPO 'UAG DirectAccess: AppServers (GDC-UAG.xxxx.LOCAL)' is writable
    WARNING:   Couldn't write to GPO 'UAG DirectAccess: AppServers
    (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'. GPO will not be modified.
    Exception calling "OpenDSGpo" with "4" argument(s): "A GPO with ID {0} was not
    found in the xxxx.local domain."

    ============ UAGDA Group Policy Apply Completed. Elapsed time is 00:02:49.7610564 .

    WARNING: 3 warning(s):
    WARNING:   Couldn't write to GPO 'UAG DirectAccess: Clients
    
    (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'. GPO will not be modified.
    Exception calling "OpenDSGpo" with "4" argument(s): "A GPO with ID {0} was not
    found in the xxxx.local domain."
    WARNING:   Couldn't write to GPO 'UAG DirectAccess: Gateways
    (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'. GPO will not be modified.
    Exception calling "OpenDSGpo" with "4" argument(s): "A GPO with ID {0} was not
    found in the xxxx.local domain."
    WARNING:   Couldn't write to GPO 'UAG DirectAccess: AppServers
    (GDC-UAG.xxxx.LOCAL)' on domain 'xxxx.local'. GPO will not be modified.
    Exception calling "OpenDSGpo" with "4" argument(s): "A GPO with ID {0} was not
    found in the xxxx.local domain."

     

    Regards

     





    • Edited by Dharm Singh Wednesday, October 5, 2011 6:43 AM
    Wednesday, October 5, 2011 6:36 AM

All replies

  • How long have you waited since trying to push the script for the first time? I see this message occasionally when waiting for replication between the DCs. Basically, the first time you "Apply Policy" and push the GPOs into place, it creates the GPOs but then fails with this message because replication has not yet happened and so the GPOs do not exist on all DCs yet. If you continue trying to Apply Policy it will continue to fail until replication is complete. Once replication is finally complete and the GPOs exist on all DCs, then when you click Apply Policy it will be able to actually open the GPOs to put the settings into place.

    I know that in theory it shouldn't have to be this way, you would think that the script would create the GPOs and then open those same GPOs just on one DC to be able to finish the job right away, but in real world testing I have found this scenario to happen quite often.

    Wednesday, October 5, 2011 12:50 PM
  • What I did is manually created the GPO's and again tried with wizard and it worked.

     

    Regards

    Friday, October 7, 2011 8:34 AM
  • You only have to do it again...
    Friday, July 20, 2012 3:22 PM