none
GPO not applying GPP IE11 settings

    Question

  • Hello,

    Problem description:
    AD domain: 2003 R2
    AD GPO NameX with IEM [ Internet Explorer Maintenance ] settings applied to User Group logging on Old 2003 R2 TS [ Terminal Server ]: OK
    # Especially important are settings in Connections Tab: LAN settings

    New 2012 R2 RDS Server added to domain with IE11.
    GPO NameX: added GPP [ GP Preferences ] to Internet Settings: IE10
    # These GP Preferences should also work with IE11. IEM settings don't apply to IE11.

    GP Preferences mentioned above don't apply to users logging to New RDS Server.
    This confirms also Gpresult.exe /R /V.

    I enabled also: GPSVC debug logging  but in log in %SystemRoot%\Debug\UserMode\ I didn't find useful info.
    # perhaps my knowledge was insufficient ...

    What could be wrong ?


    best regards Janusz Such


    • Edited by Janusz Such Tuesday, April 11, 2017 10:30 AM
    Tuesday, April 11, 2017 10:28 AM

Answers

  • IE gpp are horrible to set up...

    Do you have your setting underline in green ?

    If not, this is your matter...

    You have to press f5/6/7/8 to activate or desactivate one setting or all in the current page


    Merci de marquer comme réponse les sujets qui vous ont permis d'avancer afin que cela puisse être bénéfique aux personnes qui rencontrent le même problème.

    Wednesday, April 12, 2017 7:41 PM

All replies

  • > AD domain: 2003 R2
     
    Urgh...
     
    > GPO NameX: added GPP [ GP Preferences ] to Internet Settings: IE10
    > # These GP Preferences should also work with IE11. IEM settings don't apply to IE11.
     
    Security filter for a user group? Then check MS16-072 known issues...
     
    Tuesday, April 11, 2017 10:55 AM
  • Hi Janusz,
    If a GPO is not applied, please check the following article for common reasons to try troubleshooting:
    10 Common Problems Causing Group Policy To Not Apply
    http://social.technet.microsoft.com/wiki/contents/articles/22457.10-common-problems-causing-group-policy-to-not-apply.aspx
    And as Martin said, you could check if MS16-072 is installed on clients and domain controllers which might cause user group policy not working, if that is the case, please use the Group Policy Management Console (GPMC.MSC) and add the Authenticated Users group with Read Permissions on the Group Policy Object (GPO). If you are using security filtering, add the Domain Computers group with read permission. Please see: https://support.microsoft.com/en-sg/kb/3163622
    Best regards, 
    Wendy

    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com

    Wednesday, April 12, 2017 9:11 AM
    Moderator
  • Thank you for your answer !

    I'd like to clarify:
    GPO NameX's:
    * GP Settings are applied                   # not until I added New Server to security filter of this GPO with Read & Apply permissions
    * GP Preferences are NOT applied

    Can MS16-072 patch help in this situation ?
    I can install it only on New 2012 RDS Server, but not on DCs because domain = 2003 R2.


    best regards Janusz Such

    Wednesday, April 12, 2017 7:24 PM
  • IE gpp are horrible to set up...

    Do you have your setting underline in green ?

    If not, this is your matter...

    You have to press f5/6/7/8 to activate or desactivate one setting or all in the current page


    Merci de marquer comme réponse les sujets qui vous ont permis d'avancer afin que cela puisse être bénéfique aux personnes qui rencontrent le même problème.

    Wednesday, April 12, 2017 7:41 PM
  • Hi Janusz,

    Just checking in to see if the information provided was helpful. And if the replies as above are helpful, we would appreciate you to mark them as answers, please let us know if you would like further assistance.

    Best Regards,

    Wendy


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com

    Tuesday, April 18, 2017 2:49 PM
    Moderator
  • Hi Wendy,

    thank you for the link to article:
    "10 Common Problems Causing Group Policy To Not Apply"

    It's a great article !

    In p. 2 is written: "authenticated users includes both users and computer"

    Is it true, that "Authenticated Users" group includes both Users and Computers ?


    best regards Janusz Such

    Wednesday, April 19, 2017 9:11 AM
  • Yes.

    It's true.

    When you use security group filtering user group, you need to add in delegation tab authenticated user with read permission to apply this GPO.

    It's because of new change since june 2016

    https://support.microsoft.com/en-us/help/3163622/ms16-072-security-update-for-group-policy-june-14,-2016


    Merci de marquer comme réponse les sujets qui vous ont permis d'avancer afin que cela puisse être bénéfique aux personnes qui rencontrent le même problème.

    Wednesday, April 19, 2017 9:40 AM
  • YES !
    Main setting: use automatic configuration script  was underlined with RED.
    I had to use F5 key to toggle to GREEN [ as I remember, now I haven't connection to this server ]

    My stupid error & oversight ...

    Thank you.


    best regards Janusz Such

    Wednesday, April 19, 2017 10:54 AM
  • Hi Wendy,

    it seems that my case is resolved, I marked & voted appropriate  replies.

    Thank you.


    best regards Janusz Such

    Wednesday, April 19, 2017 10:57 AM