none
GPO not always applying at site level - seems to work on some users only

    Question

  • Hi

    I created a controlled GPO for windows 8.1 domain policy and applied it at site level as my IT architect wanted that.

    Some users have received the policy; other users don't seem to be receiving the policy.

    The GPO has read access on it, has a WMI filter for 8.1 that works correctly, and it is set to Autenticated Users. There are no enforced GPOs to override this. There are other policies on an OU level that are working where my policy isn't being picked up. I am confused as to why some machines are getting the policy and others aren't. 90% of the machines at work are windows 8.1 so this isn't an issue with the WMI filter.

    Is there a reason site policy won't apply? Why would other policies apply and not my site one? It is very hit and miss. I need my site one working. Please let me know if you need more information and screenshots.

    Monday, February 15, 2016 12:47 AM

All replies

  • In addition to this I have changed my policy; removed it from Site level and now it doesn't appear at all. I have reapplied it on OU and Site level and despite gpforce it is not working.
    Tuesday, February 16, 2016 2:19 AM
  • Hi,
     
    Could you please share more details about your GPOs? What exact settings have you configured?
     
    >I have reapplied it on OU and Site level and despite gpforce it is not working.
     
    You mean even linking it at OU level, users won't pick these policy settings? Try to run "Gpresult /h C:\result.html" on the client machine and see if the GPO is applied successfully.
     

    Regards,

    Ethan Hua


    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com

    Tuesday, February 16, 2016 6:05 AM
    Moderator
  • Check the client machines are connected to same site where you have applied the GPO.

    Regards, MC Manikandan

    Tuesday, February 16, 2016 11:34 AM
  • Hi,
     
    Could you please share more details about your GPOs? What exact settings have you configured?
     
    >I have reapplied it on OU and Site level and despite gpforce it is not working.
     
    You mean even linking it at OU level, users won't pick these policy settings? Try to run "Gpresult /h C:\result.html" on the client machine and see if the GPO is applied successfully.
     

    Regards,

    Ethan Hua


    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com

    Hi Ethan,

    I have added Google Chrome Update keys in Computer configuration/Policies/Preferences/Windows Settings/Registry - so on HKEY LOCAL MACHINE there is a reg key called UpdateDefault, marked as 1, reg_dword. I also did another key called AutoUpdateCheckMinutes, marked as 1, reg_dword.

    I couldn't get the Google Chrome admx to import successfully into my admin templates for GPO so just manually created these keys. 

    If I run gpresult /r on my laptop I cannot see the site policy called Windows 8.1 Domain Security Policy that I have created. I now have this on my specific OU as well as Site.

    Tuesday, February 16, 2016 11:34 PM
  • Check the client machines are connected to same site where you have applied the GPO.

    Regards, MC Manikandan

    all appropriate subnets are in the list for my Site as well as my laptop is marked for the Site in ADUC - i.e. it is in the correct OU for the Site. 
    Tuesday, February 16, 2016 11:36 PM
  • I also ran rsop through GPM; 

    It then displays my policy called Windows 8.1 Domain Security Policy as Enforced. 

    Why is it i cannot see it if i run gpresult /r on my machine?  I can see all other policies. the reg key wasn't changed either. 

    I am going to redo the reg key again and see if it picks it up after server replication.

    Tuesday, February 16, 2016 11:40 PM