Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


February 2008

Group Policy Essentials No Sys Admin Can Live Without

Power tips for setting and enabling GPOs ensure Group Policy operates harmoniously
RSS
Subscribe to Windows IT Pro | See More Tips Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Troubleshooting Group Policy
Because Group Policy is complex, sometimes it doesn’t work the way you expect. You might have inadvertently misconfigured something, or it might not work because something is simply broken. Group Policy processing requires several elements to work in harmony. Your AD infrastructure must be healthy, your workstations must be healthy, and the various settings that you configure must be compatible with the applications running on your desktops.

When any of that is out of whack, you might see Group Policy processing failures. When failure happens, how do you find out what is amiss? The first step is to create a Resultant Set of Policy (RSoP) report on the problem computer. RSoP is gathered using the Group Policy Results Wizard within GPMC. You can also use the command-line utility gpresult.exe that comes with Vista, Windows 2003, and XP, to generate an RSoP report. The easiest thing to do is to run the Group Policy Results wizard from GPMC. The wizard lets you pick a local or remote computer to connect to, then pick a user who has logged onto that computer.The wizard then connects to that remote computer and gathers information about Group Policy processing that occurred during the last processing cycle. The most useful part of that report is the Summary tab, which you can see in Figure 4.

The summary tab shows you which GPOs were applied to the computer and user, and most importantly, which GPOs were denied and why. In the Component Status section, the report can give you information about whether any specific portions of Group Policy processing failed and why. The Group Policy Infrastructure item you see in that section tells you whether the basic setup of Group Policy processing succeeded. If this step fails, then it usually indicates some infrastructure problem that’s preventing any Group Policy processing from occurring. If the error occurs in one of the so-called client-side extensions that implement the various policy areas, then you might be able to isolate the problem by using the error messages provided. If you want to see which individual policy settings are being delivered to the computer or user, then you can view the Settings tab in the Group Policy results report to see which settings “won” and are being processed. However note that just because the RSoP report says the setting has been applied doesn’t actually guarantee that the setting was successfully made. It’s best to sometimes check the underlying setting, be it a registry value or security setting, to be sure.

You can also look in the Application event log on a given Windows system (note that Vista puts Group Policy events into the System event log and the Group Policy Operations log) to see additional errors related to Group Policy processing.

With Knowledge Comes Power
Group Policy is complex and powerful. By understanding how Group Policy is processed, you can get a better handle on using its power. Remember that Group Policy is processed in order of local GPO, AD site, domain, then OU (sometimes referred to as LSDOU) and that typically, the “last writer wins” when there are conflicting settings. Policies and preferences can affect how policy stays on your systems when the GPO is removed, and making explicit choices about using each is important. The registry policies delivered by Microsoft in their standard ADM and ADMX files don’t typically tattoo the registry, but any custom ADMX files you use might. In addition, other policy areas such as security do tattoo your systems and must be explicitly “un-done”, while some policy areas must be told to be undone when they no longer apply. Finally, if policy is still not doing what you expect, fall back to the Group Policy Results wizard in GPMC to tell you what’s actually going on with your problem system and to point you toward a solution.

End of Article

   Previous  1  2  [3]  Next  


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

Google's Browser Created Out of Fear of Microsoft

A deep fear of Microsoft drove Google to create its own Web browser, the company's cofounders implicitly admitted Tuesday, though each was careful never to mention the software giant by name. Instead, during a press conference, Google's leaders discussed ...

Let's Get Out of the (Network) Neighborhood

Network Neighborhood might've made sense way back when, but it's long past obsolete today. ...


Related Articles Monitor GPO Deployment

Windows Scripting Tips

Using WMI Filters with GPOs

Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Are You Satisfied?

A Preliminary Look at Deployment Plans for Microsoft Windows Vista

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

IT Connections
Dive into the new Microsoft platforms and products you implement and support with the experts from Microsoft, TechNet Magazine, Windows ITPro and industry gurus. There are 70+ sessions and interactive panels with networking opportunities.

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes and add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Get SQL Server 2008 at WinConnections
Don’t miss Microsoft Exchange and Windows Connections conferences, the premier events for Microsoft IT Professionals in Las Vegas, November 10-13. Every attendee will receive a copy of SQL Server 2008 Standard Edition with one CAL.



Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing