locked
Gpo Trouble due to repeated use of the OU names RRS feed

  • Question

  • Hello,

    I've used several times identical names of ou,

    This caused problems with the gpo

    If I take gp results of a computer , from the server , they give GPO from another OU (which was the same name of the OU) but gpo related to his OU does not appear.

    Currently I changed all OU name and the problem persists

    Thanks in advance for your answers

    Wednesday, December 21, 2016 12:25 PM

All replies

  • Can you post an example of the GPRESULTS output and the properties of the GP that should be applied?

    Thanks

    Ed Gallagher, MVP

    Monday, December 26, 2016 9:45 PM
  • Thanks for your answer

    It associates gpo to wrong ou and there is an Error "ad / sysvol version mismatch"

    • Edited by mbyforum Tuesday, December 27, 2016 7:45 AM
    Tuesday, December 27, 2016 7:45 AM
  • OK.

    Lets get back to collecting some more basic info:

    How many domain controllers do you have?

    What server OS are they running?

    What OS is the client system running?

    When you say "It associates GPO to wrong OU" what is "It" and how do you know what the right OU is?

    Please post the entire output of the GPRESULTS and the properties of the GPO.

    Thanks

    Ed

    Tuesday, December 27, 2016 7:51 AM
  • How many domain controllers do you have? 2

    What server OS are they running? 2008 R2 Standard -2012 R2 DataCenter

    What OS is the client system running? all OS-7-8-10

    When you say "It associates GPO to wrong OU" what is "It" and how do you know what the right OU is? 

    For example the user anat-i send you on a report should get gpo named mapsif on User Configuration And here it does not exist at all

    Usually the problem is that the gpo computer work and the Gpo user does not work

    As I mentioned above I called to OU's computer and use the same name

    I changed it for over a week

    How can  I send you he report? It's over the 6000 Characters?



    • Edited by mbyforum Tuesday, December 27, 2016 8:29 AM
    Tuesday, December 27, 2016 8:23 AM
  • I think you may be missing the point in my questions. Sorry if I am not stating them clearly enough.

    What is the full path in the OU structure to the computer account object?

    What GPO's are linked to the OU that contains the computer account?

    What GPO's are inherited to the OU that contains the computer account?

    What is the full path in the OU structure to the user account object?

    What GPO's are linked to the OU that contains the user account?

    What GPO's are inherited to the OU that contains the user account?

    From the info that I did receive from you, it looks like you are trying to control the GPO processing through what I would consider to be an excessive amount of permission filtering instead of designing an OU structure that would facilitate your use of Group Policy. This can lead to lots of troubleshooting issues in my experience.

    Thanks.

    Ed

    Tuesday, January 10, 2017 2:48 AM
  • I downloaded all the gpo connected to OU problematic
    I put 1-1 and now seems right

    I'll check the option of proper management of the gpo as you specified.

    Thank you for taking the time issue
    Tuesday, January 10, 2017 8:56 AM