none
Group Policy Default Domain Policy is not applying on the clients

    Question

  • i have problem with my Group Policy is not applying the default Domain Policy on clinets. and iam sure that it is linked to my domain and i don't know why its not working.

    as my clients PC they can do any thing require admin credentials but the are not in need for credentials . anyone can do anything on his PC. 

    please help.

    the bellow is gpresult .

    C:\Users\Administrator>gpresult /r

    Microsoft (R) Windows (R) Operating System Group Policy Result tool v2.0
    c 2013 Microsoft Corporation. All rights reserved.

    Created on 12/14/2015 at 3:26:01 PM


    RSOP data for RETAJALNAHDI\administrator on RRA-DC : Logging Mode
    ------------------------------------------------------------------

    OS Configuration:            Primary Domain Controller
    OS Version:                  6.3.9600
    Site Name:                   Default-First-Site-Name
    Roaming Profile:             N/A
    Local Profile:               C:\Users\Administrator
    Connected over a slow link?: No


    COMPUTER SETTINGS
    ------------------
        CN=RRA-DC,OU=Domain Controllers,DC=retajalnahdi,DC=com
        Last time Group Policy was applied: 12/14/2015 at 3:25:04 PM
        Group Policy was applied from:      RRA-DC.retajalnahdi.com
        Group Policy slow link threshold:   500 kbps
        Domain Name:                        RETAJALNAHDI
        Domain Type:                        Windows 2008 or later

        Applied Group Policy Objects
        -----------------------------
            Default Domain Controllers Policy
            Local Group Policy

        The following GPOs were not applied because they were filtered out
        -------------------------------------------------------------------
            Default Domain Policy
                Filtering:  Disabled (Link)

        The computer is a part of the following security groups
        -------------------------------------------------------
            BUILTIN\Administrators
            Everyone
            BUILTIN\Users
            BUILTIN\Pre-Windows 2000 Compatible Access
            Windows Authorization Access Group
            NT AUTHORITY\NETWORK
            NT AUTHORITY\Authenticated Users
            This Organization
            RRA-DC$
            Domain Controllers
            NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
            Authentication authority asserted identity
            Denied RODC Password Replication Group
            System Mandatory Level


    USER SETTINGS
    --------------
        CN=Administrator,CN=Users,DC=retajalnahdi,DC=com
        Last time Group Policy was applied: 12/14/2015 at 3:10:03 PM
        Group Policy was applied from:      RRA-DC.retajalnahdi.com
        Group Policy slow link threshold:   500 kbps
        Domain Name:                        RETAJALNAHDI
        Domain Type:                        Windows 2008 or later

        Applied Group Policy Objects
        -----------------------------
            N/A

        The following GPOs were not applied because they were filtered out
        -------------------------------------------------------------------
            Local Group Policy
                Filtering:  Not Applied (Empty)

        The user is a part of the following security groups
        ---------------------------------------------------
            Domain Users
            Everyone
            BUILTIN\Administrators
            BUILTIN\Users
            BUILTIN\Pre-Windows 2000 Compatible Access
            NT AUTHORITY\INTERACTIVE
            CONSOLE LOGON
            NT AUTHORITY\Authenticated Users
            This Organization
            LOCAL
            Domain Admins
            Group Policy Creator Owners
            KLAdmins
            Enterprise Admins
            Schema Admins
            Authentication authority asserted identity
            Denied RODC Password Replication Group
            Scan Operators
            High Mandatory Level

    Monday, December 14, 2015 12:57 PM

Answers

  • Hi,

    As per the gpresult mentioned in the question, it was filtered out due to “Filtering:  Disabled (Link)”.Probably the DDP was linked to another OU or site that the clients reside in, and it was somehow disable there.
    To check this, try to run gpresult /h to find the detailed link location


    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Thursday, December 17, 2015 8:23 AM
    Moderator

All replies

  • Hello

    please run grpresult on client not a dc.


    sorry my english

    Monday, December 14, 2015 7:50 PM
  • Hello

    please run grpresult on client not a dc.


    sorry my english

    C:\Users\rec6>gpupdate /force

    Updating Policy...

    User Policy update has completed successfully.

    Computer Policy update has completed successfully.

    C:\Users\rec6>gpresult /r

    Microsoft (R) Windows (R) Operating System Group Policy Result tool v2.0

    Copyright (C) Microsoft Corp. 1981-2001

    Created On 12/14/2015 at 5:51:26 PM

    RSOP data for RETAJALNAHDI\rec6 on FO-RECEPTION6 : Logging Mode

    ----------------------------------------------------------------

    OS Configuration: Member Workstation

    OS Version: 6.1.7601

    Site Name: N/A

    Roaming Profile: N/A

    Local Profile: C:\Users\rec6

    Connected over a slow link?: No

    USER SETTINGS

    --------------

    CN=Reception6,OU=FO,DC=retajalnahdi,DC=com

    Last time Group Policy was applied: 12/14/2015 at 5:25:08 PM

    Group Policy was applied from: RRA-DC.retajalnahdi.com

    Group Policy slow link threshold: 500 kbps

    Domain Name: RETAJALNAHDI

    Domain Type: Windows 2000

    Applied Group Policy Objects

    -----------------------------

    Default Domain Policy

    The following GPOs were not applied because they were filtered out

    -------------------------------------------------------------------

    Local Group Policy

    Filtering: Not Applied (Empty)

    The user is a part of the following security groups

    ---------------------------------------------------

    Domain Users

    Everyone

    BUILTIN\Users

    BUILTIN\Administrators

    NT AUTHORITY\INTERACTIVE

    CONSOLE LOGON

    NT AUTHORITY\Authenticated Users

    This Organization

    LOCAL

    Domain Admins

    Denied RODC Password Replication Group

    Scan Operators

    High Mandatory Level


    Tuesday, December 15, 2015 9:17 AM
  • Hello

    check domain controller ou for gpo inheritance


    sorry my english

    Tuesday, December 15, 2015 9:30 AM
  • i have done it but still the same problem ... its not working 
    Tuesday, December 15, 2015 9:55 AM
  • Hi,

    As per the gpresult mentioned in the question, it was filtered out due to “Filtering:  Disabled (Link)”.Probably the DDP was linked to another OU or site that the clients reside in, and it was somehow disable there.
    To check this, try to run gpresult /h to find the detailed link location


    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Thursday, December 17, 2015 8:23 AM
    Moderator