Cross Forest GPO Question...


  • Hi All,

    I would like to ask a question about configuring Cross Forest GPOs.

    In summary.  I have a environment with two forests in it.

    A resource domain/forest ( which has the AD Computer objects in it and the Computer based GPOs. 

    And a Managed AD Forest that has the user AD Objects and user based GPOs in it (

    There is a one-way trust (non transitive) from to

    Cross Forest GPO support has been enabled via one of the Computer Based GPOs in the Resource domain/forest.

    When User01 logs onto PC-Dev-01 (a Windows 10 PC) the computer based GPOs are all applying successfully.  However the user based GPOs do not appear to be applying successfully.

    Running a RSOP from the GPO Management Console or a gpresults locally on the PC gives a report that seems to indicate the user based GPOs are applying successfully.  But when the settings are checked manually they are not set.  Or if a setting is changed it is not reapplied at the next logon.

    Most common examples of this is the IE11 homepage, Auto Proxy script and shortcuts placed on the desktop.

    I'm rather confused about this.  Because if the user based policies were not applying successfully the various reports should indicate this.

    Any assistance would be gratefully received,

    Wednesday, October 26, 2016 6:04 AM


All replies