none
GPOP only applies when Authenticated Users set in Group Filtering

    Question

  • Hi,

    Windows 2008 R2 AD.

    I'm trying to apply a GPO with User settings and it fails to apply when a Security Group is set in the GPO's Security Filtering.

    In the case I remove that group and apply the GPO for the entity Authenticated Users, the GPO is applied.

    When I run a Group Policy Result, everything is ok and the GPO apperas in the section Applied GPOs of the User Details, but the settings don't apply to the user configuration.

    Thank you.

    Tuesday, July 26, 2016 12:25 PM

Answers

  • > I'm trying to apply a GPO with User settings and it fails to apply when
    > a Security Group is set in the GPO's Security Filtering.
     
    Welcome to MS16-072...
     
    • Marked as answer by fedayn2 Wednesday, July 27, 2016 10:17 AM
    Tuesday, July 26, 2016 3:01 PM
  • Hi,
    I agree with Martin that Please check if MS16-072 was installed on DC or clients. If that is the case, to resolve this issue, please use the GPMC to add the Authenticated Users group with Read Permissions on GPO. If you are using security filtering, please add the Domain Computers group with read permission.
    You could see more details from:
    Deploying Group Policy Security Update MS16-072 \ KB3163622
    https://blogs.technet.microsoft.com/askds/2016/06/22/deploying-group-policy-security-update-ms16-072-kb3163622/
    MS16-072: Security update for Group Policy: June 14, 2016 https://support.microsoft.com/en-sg/kb/3163622
    Regards,
    Wendy

    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    • Marked as answer by fedayn2 Wednesday, July 27, 2016 10:17 AM
    Wednesday, July 27, 2016 6:14 AM
    Moderator

All replies