none
Pl. help-GPO not applying on RDSH Server (Windows Server 2012 R2) for New Users, same was working when i was created a new Setup. I want to go in depth of this issue..

    Question

  • Dear All,

    I am facing an issue on Folder redirection policy GPO on RDS Server as Folder redirection Policy not applying on RDS Server (Windows Server 2012 R2) for New Users, same was working when i was created a new Setup. I want to go depth of this issue..

    Our Setup is as below:

    VIDC- Main Domain Controller + RDS Connection Broker +RD Web Access (Physical Server)

    DC1-ADC (Additional Domain Controller (On Hyper V)

    FS1-RDSH + File Server (Storage Spaces) to save User Profile (D:\Shares\UserProfiles)

    FS3-RDSH 

    Further i would like to inform you that as per my knowledge there is no Problem with GPO or DC as When i am login on Client PC (Windows7, 8,8.1,10/Virtual or Physical) then same policy is applying...only it is not working on our RDSH Servers. 

    In Advance i am giving all details. 

    On VIDC:

    C:\Users\admin>dcdiag

    Directory Server Diagnosis

    Performing initial setup:
       Trying to find home server...
       Home Server = VIDC
       * Identified AD Forest.
       Done gathering initial info.

    Doing initial required tests

       Testing server: Default-First-Site-Name\VIDC
          Starting test: Connectivity
             ......................... VIDC passed test Connectivity

    Doing primary tests

       Testing server: Default-First-Site-Name\VIDC
          Starting test: Advertising
             ......................... VIDC passed test Advertising
          Starting test: FrsEvent
             ......................... VIDC passed test FrsEvent
          Starting test: DFSREvent
             ......................... VIDC passed test DFSREvent
          Starting test: SysVolCheck
             ......................... VIDC passed test SysVolCheck
          Starting test: KccEvent
             ......................... VIDC passed test KccEvent
          Starting test: KnowsOfRoleHolders
             ......................... VIDC passed test KnowsOfRoleHolders
          Starting test: MachineAccount
             ......................... VIDC passed test MachineAccount
          Starting test: NCSecDesc
             ......................... VIDC passed test NCSecDesc
          Starting test: NetLogons
             ......................... VIDC passed test NetLogons
          Starting test: ObjectsReplicated
             ......................... VIDC passed test ObjectsReplicated
          Starting test: Replications
             ......................... VIDC passed test Replications
          Starting test: RidManager
             ......................... VIDC passed test RidManager
          Starting test: Services
             ......................... VIDC passed test Services
          Starting test: SystemLog
             A warning event occurred.  EventID: 0x000003FC
                Time Generated: 02/06/2017   09:24:08
                    ......................... VIDC passed test SystemLog
          Starting test: VerifyReferences
             ......................... VIDC passed test VerifyReferences


       Running partition tests on : DomainDnsZones
          Starting test: CheckSDRefDom
             ......................... DomainDnsZones passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... DomainDnsZones passed test
             CrossRefValidation

       Running partition tests on : ForestDnsZones
          Starting test: CheckSDRefDom
             ......................... ForestDnsZones passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... ForestDnsZones passed test
             CrossRefValidation

       Running partition tests on : Schema
          Starting test: CheckSDRefDom
             ......................... Schema passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... Schema passed test CrossRefValidation

       Running partition tests on : Configuration
          Starting test: CheckSDRefDom
             ......................... Configuration passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... Configuration passed test CrossRefValidation

       Running partition tests on : Corp
          Starting test: CheckSDRefDom
             ......................... Corp passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... Corp passed test CrossRefValidation

       Running enterprise tests on : Corp.Test.com
          Starting test: LocatorCheck
             ......................... Corp.Test.com passed test
             LocatorCheck
          Starting test: Intersite
             ......................... Corp.Test.com passed test Intersite

    C:\Users\admin>repadmin /replsummary
    Replication Summary Start Time: 2017-02-06 10:26:15

    Beginning data collection for replication summary, this may take awhile:
      .....


    Source DSA          largest delta    fails/total %%   error
     DC1                       04m:41s    0 /   5    0
     VIDC                      02m:12s    0 /   5    0


    Destination DSA     largest delta    fails/total %%   error
     DC1                       02m:12s    0 /   5    0
     VIDC                      04m:41s    0 /   5    0

    C:\Users\admin>nslookup
    Default Server:  vidc.corp.Test.com
    Address:  192.168.5.233

    > google.com
    Server:  vidc.corp.Test.com
    Address:  192.168.5.233

    Non-authoritative answer:
    Name:    google.com
    Addresses:  2404:6800:4007:801::200e
              172.217.26.174



    Run -->rsop on (FS1)


    On Client PC where same Policy is working: 

    I understand that same Policy is not showing on RDSH Server but why ? 

    For other details i will post on your conversion. 






    Monday, February 6, 2017 5:06 AM

All replies

  • On FS1: 

    C:\Users\admin>GPRESULT /H c:\GPReport.html

    https://drive.google.com/open?id=0B2AmIs5exoXuR0xvQzRObGVQd00


    Monday, February 6, 2017 5:36 AM
  • Only on Both RDSH Server, no any GPO is working. 

    So, i understand that Problem is on only these two Servers as for testing i have check some other policy like Mapping a Network drive..etc.

    Apart from these two servers, on all others Client PC, all the GPOs are working. 

    Wednesday, February 8, 2017 12:54 PM
  • I have re-installed the OS on FS1 (1 RDSH Server) and now all the GPOs are working fine.

    But on FS3 (2nd RDSH Server) still we are facing the same problem. GPO not applying. 

    Sunday, February 12, 2017 8:33 AM
  • As i have checked that after 2 days, once again GPO is not applying on our FS1 & FS3 (RDSH Server).

    Can anybody suggest me what i need to check now.

    Wednesday, February 15, 2017 8:04 AM
  • Hi,

    Sorry for the delayed reply.

    I cannot read the gpreport. Would you post gpresult like below.

    In addition, I suggest you try to check if the RDSHs server is member of the OU, which the GPO linked.

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.


    Wednesday, February 22, 2017 1:44 AM
    Moderator
  • I hope you already read my all Post reg. to this issue to understand its Problem. 

    GPO not applied after few days only on RDSH (Remote desktop session Host) Server.

    So, that i re-installed the OS on RDSH and found that for 2..3 days GPO was working and once again getting the same Prob.

      Here i am posting 2 Users GPresult @ FS1 report .

    User1-This is User who logged on this server when i re-installed the OS on RDSH & GPO was working.

    User2-This is user who is now log on this server but GPO is not applying on it. 

    Wednesday, February 22, 2017 11:41 AM
  • Wednesday, February 22, 2017 11:45 AM
  • Wednesday, February 22, 2017 11:46 AM
  • Hi,

    Sorry for the delayed reply.

    I cannot read the gpreport. Would you post gpresult like below.

    In addition, I suggest you try to check if the RDSHs server is member of the OU, which the GPO linked.

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.


    Yes, It's member of OU on which i am applying GPO.

    After few days GPO stopped only on RDSH Server. 

    If same user log on any System in domain then same GPO is applying on it but not applying when login on RDSH. 


    Wednesday, February 22, 2017 11:54 AM
  • Hi,

    Yes, It's member of OU on which i am applying GPO.

    After few days GPO stopped only on RDSH Server. 

    If same user log on any System in domain then same GPO is applying on it but not applying when login on RDSH. 

    >>>What you have configured is User configuration?

    If yes, I suggest you try to check if the RDSH applies loopback processing mode. By default, the user's Group Policy objects determine which user policies apply. If this policy is enabled, then, when a user logs on to this computer, the computer's Group Policy objects determine which set of Group Policy objects applies.

    The setting under the path Computer Configuration\Administrative Templates\System\Group Policy.

    For more information about loopback processing mode, please refer to the article below.

    User Group Policy loopback processing mode

    https://technet.microsoft.com/en-us/library/cc978513.aspx

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Wednesday, February 22, 2017 1:05 PM
    Moderator
  • Hi,

    Yes, It's member of OU on which i am applying GPO.

    After few days GPO stopped only on RDSH Server. 

    If same user log on any System in domain then same GPO is applying on it but not applying when login on RDSH. 

    >>>What you have configured is User configuration?

    If yes, I suggest you try to check if the RDSH applies loopback processing mode. By default, the user's Group Policy objects determine which user policies apply. If this policy is enabled, then, when a user logs on to this computer, the computer's Group Policy objects determine which set of Group Policy objects applies.

    The setting under the path Computer Configuration\Administrative Templates\System\Group Policy.

    For more information about loopback processing mode, please refer to the article below.

    User Group Policy loopback processing mode

    https://technet.microsoft.com/en-us/library/cc978513.aspx

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    I think now i am going to positive direction. I know very well GPO Loopback processing mode but never use it. 

    i am collecting my All GPOs Information to understand which GPOs are belong to Computer configuration and user Configuration. Further i have some query which i will post ASAP.

    Thursday, February 23, 2017 5:05 AM
  • Hi Sir,

    I am using the below GPO:

    Folder Redirection Policy, Network Drive Map Policy, USB Mass Storage Block Policy, Isolate Print Driver on FS1 Server.

    Now if i am using the Loopback Processing GPO as  replace /Merge Mode. 

    Then pl. check and suggest for Users & Computers location as Is it correct?

    All the Computers are in default location and all the domain users are in an OU Group  and i am applying the GPO on OU Group as below:


    Thursday, February 23, 2017 7:01 AM
  • Hi,

    I notice that you have configure the security filtering for group policy.

    If you put all users on one OU, and create a GPO link to the OU. But, If you configure the security filtering for a group. The GPO only apply to the member of the group.

    And I saw the User1 applied the group policy Drive map. And the User2 not.

    I suggest you try to check the security filtering for GPOs.

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Wednesday, March 1, 2017 3:40 AM
    Moderator
  • Hi,

    I notice that you have configure the security filtering for group policy.

    If you put all users on one OU, and create a GPO link to the OU. But, If you configure the security filtering for a group. The GPO only apply to the member of the group.

    And I saw the User1 applied the group policy Drive map. And the User2 not.

    I suggest you try to check the security filtering for GPOs.

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Both users are in same Security group "O/P/Q Drive Users" as well as in security Filtering.



    Wednesday, March 1, 2017 11:33 AM
  • Hi,

    I suggest you check like below.

    1. ODrivePolicy GPO linked to the User OU and with security filtering for ODriveUsers group (all member of the group are in User OU)
    2. The ODrivePolicy GPO will apply those users, which is member of OdriveUsers group
    3. Logon the RDSH with those users, which is member of the ODriveUsers group and run gpupdate /force
    4. Then run gpresult /h gpreport.html to check if the ODrivePolicy GPO has been applied successfully

    If the GPO still not applied on RDSH, I suggest you try to post the gpreport.html like below.

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Wednesday, March 1, 2017 1:19 PM
    Moderator
  • Hi,

    Are there any updates?

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Tuesday, March 7, 2017 1:20 PM
    Moderator
  • Hi Sir,

    Still i am facing the same Problem.

    Pl. find the GP result on FS1 for 2 users.

    https://1drv.ms/f/s!AobvvD-JnR5WgxVOXfO0q8MavgLb

    Wednesday, March 8, 2017 4:18 AM
  • Hi,

    From the group policy result, the user Harshit and Sandeepvs are member of local administrators.

    Try to run gpresult /scope user /h gpreport.html to check.

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Thursday, March 9, 2017 7:25 AM
    Moderator
  • Hi,

    Are there any updates?

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Tuesday, March 14, 2017 2:41 PM
    Moderator