Computing.Net > Forums > Windows Server 2003 > Group policy

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Group policy

Reply to Message Icon

Name: Chris (by Chris Kirk)
Date: May 23, 2008 at 10:38:28 Pacific
OS: server 2003 XP pro
CPU/Ram: _
Product: _
Comment:

Hello,
The problem i have is that group polciy on the domain dose not apply to any user on any client PC. (It works fine on the server [DC]).
I have tried RSoP from MMC on a client and after running it, a box comes up that the lates version of the ADm files were not found and is using local copies of the ADM files.

it then says
system.adm
location - Domain.local\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
Error - The network path was not found.

Then the same for; conf.adm, wmplayer.adm

I thing this is the problem whay the GP dose not apply?

when i put Domain.local\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
in to explore address bar it can not be found.
When i change the first Domain.local to the server name.

Server-1\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
It can be found.

What is the problem, and do i need to change something to get it to work

Any help,
Thanks.



Sponsored Link
Ads by Google

Response Number 1
Name: guapo
Date: May 23, 2008 at 19:02:10 Pacific

Response Number 2
Name: Chris (by Chris Kirk)
Date: May 24, 2008 at 07:51:28 Pacific
Reply:

This is not helping explain why GP dose not apply. I have tried coping the .adm files to %windir%\Inf myself but they the GP still did not apply to the users it should.
Any Help please


0

Response Number 3
Name: guapo
Date: May 24, 2008 at 20:32:07 Pacific
Reply:

There is a chance that another policy is overriding your GP. I read an article in WinIT Pro explaining that once. It said something about policies in an OU having the last word.


0

Response Number 4
Name: Chris (by Chris Kirk)
Date: May 25, 2008 at 13:47:22 Pacific
Reply:

There is not GPO at linked to an OU. They are are all linked at the domain level.


0

Response Number 5
Name: guapo
Date: May 25, 2008 at 14:52:53 Pacific
Reply:

I read your original post again. You mentioned an error message when you use domain.local and the error doesn't occur when you use Server-1.

When I used to manage a small domain for a mortgage company, it was called mortgage.local but the domain name shown on the login screen on the workstations was mortgage0. There were times I had to use mortgage0 instead of mortgage.local. Do you see a difference like that on the workstations?

Also, you might try adding some entries in the host file to point one to the other.


0

Related Posts

See More



Response Number 6
Name: Chris (by Chris Kirk)
Date: May 26, 2008 at 13:39:03 Pacific
Reply:

well to the domain name is 'Domain.local' on the log on screen it is always Domain.

What i meant is the RSoP shows an error that it can not access the gp .adm files and will use the local ones. The address it uses to fins the .adm files is
Domain.local\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
When i copy this in the address bar, itcan not be found.
When i change this address to
Server-1\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
I can find the .adm files

And i don't know if this is why it can not find and apply GP.

Thanks,


0

Response Number 7
Name: guapo
Date: May 26, 2008 at 18:41:03 Pacific
Reply:

Test it by using domain instead of domain.local or the IP address in the path. See if you still get the error.


0

Response Number 8
Name: Chris (by Chris Kirk)
Date: May 27, 2008 at 05:57:56 Pacific
Reply:

What (and how) should i change, because the problem is with GP and i get an error saying that .adm files can not be found when running RSoP on a client, and where GP looks for theses files i think is the problem.

When I TYPE THE ADDRESS it give me (where it can not find the .adm files) Domain.local\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
in to win Explore it can not find the files
But WHEN I TYPE
Server-1\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
IN TO WINDOWS EXPLORE it can find the .adm file


0

Response Number 9
Name: guapo
Date: May 27, 2008 at 08:11:44 Pacific
Reply:

What happens if you use domain instead of domain.local or Server-1 in the path?


0

Response Number 10
Name: Chris (by Chris Kirk)
Date: May 27, 2008 at 13:00:02 Pacific
Reply:

\\Domain.local\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
Dose not work

\\Domain\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
Dose not work

\\Server-1\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
WORKS


0

Response Number 11
Name: guapo
Date: May 27, 2008 at 18:48:43 Pacific
Reply:

My only guess is to add entries to the hosts file.


0

Response Number 12
Name: rajoo_sh
Date: May 28, 2008 at 07:27:13 Pacific
Reply:

Chris,

All I understand by your post is that your GP is not applied. So if this is the case then go to the command prompt, type ipconfig /all and let me know if you see the DNS server(s) IP address.

If your clients are not configured to your local DNS server, then the GP will not be applied.

Rajeev


0

Response Number 13
Name: Chris (by Chris Kirk)
Date: May 28, 2008 at 12:04:34 Pacific
Reply:

On the Server it looks like this (ipconfig /all)
Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

P:\>ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : fileserver-1
Primary Dns Suffix . . . . . . . : Domain.local
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : Domain.local
home

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . : home
Description . . . . . . . . . . . : Realtek RTL8139 Family PCI Fast Ethernet
NIC
Physical Address. . . . . . . . . : 00-50-FC-ED-41-78
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.123
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.1
Lease Obtained. . . . . . . . . . : 28 May 2008 03:37:40 PM
Lease Expires . . . . . . . . . . : 29 May 2008 03:37:40 PM

P:\>


On one client it looks like this
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\Chris.DOMAIN>ip config/all
'ip' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\Chris.DOMAIN>ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : PC-2
Primary Dns Suffix . . . . . . . : Domain.local
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : Domain.local
home

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . : home
Description . . . . . . . . . . . : Intel(R) 82562V 10/100 Network Conne
ction
Physical Address. . . . . . . . . : 00-16-76-E3-06-D4
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.5
Subnet Mask . . . . . . . . . . . : 255.255.255.0
IP Address. . . . . . . . . . . . : fe80::216:76ff:fee3:6d4%4
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.1
fec0:0:0:ffff::1%1
fec0:0:0:ffff::2%1
fec0:0:0:ffff::3%1
Lease Obtained. . . . . . . . . . : 28 May 2008 17:07:33
Lease Expires . . . . . . . . . . : 29 May 2008 17:07:33

Tunnel adapter Teredo Tunneling Pseudo-Interface:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-FB-EE-A9-7E-C5-88
Dhcp Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 2001:0:d5c7:a2ca:0:fbee:a97e:c588
IP Address. . . . . . . . . . . . : fe80::ffff:ffff:fffd%5
Default Gateway . . . . . . . . . : ::
NetBIOS over Tcpip. . . . . . . . : Disabled

Tunnel adapter Automatic Tunneling Pseudo-Interface:

Connection-specific DNS Suffix . : home
Description . . . . . . . . . . . : Automatic Tunneling Pseudo-Interface

Physical Address. . . . . . . . . : C0-A8-01-05
Dhcp Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : fe80::5efe:192.168.1.5%2
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
fec0:0:0:ffff::2%1
fec0:0:0:ffff::3%1
NetBIOS over Tcpip. . . . . . . . : Disabled

C:\Documents and Settings\Chris.DOMAIN>

What should i chage on the client.
What should i set to what of the server.

Any Help Please
Thanks


0

Response Number 14
Name: guapo
Date: May 28, 2008 at 20:40:27 Pacific
Reply:

Could the fact that IPv6 is enabled on the client be causing all your problems?


0

Response Number 15
Name: Chris (by Chris Kirk)
Date: May 29, 2008 at 10:02:27 Pacific
Reply:

I have uninstalled IPv6 from that client and GP still dose not apply.


0

Response Number 16
Name: guapo
Date: May 29, 2008 at 21:27:48 Pacific
Reply:

http://support.microsoft.com/kb/816662
http://support.microsoft.com/kb/228460

I don't know if those sites will help but I don't have much more to offer as a possible solution, except to look at the event viewer.

Did you just add a service pack?


0

Response Number 17
Name: Jennifer SUMN
Date: May 30, 2008 at 10:20:14 Pacific
Reply:

Chris, I'm offering no advice here; just asking a question. Do you intentionally misspell those words, or are you just a poor typist, or other? :)

Life's more painless for the brainless.


0

Response Number 18
Name: Chris (by Chris Kirk)
Date: May 30, 2008 at 12:05:34 Pacific
Reply:

No i did not just add a servics pack (the Server is 2003 SP1) which it has always been and i have never had GP working on it.

The two links did not help.

But what should be the location the RSoP looks for (and where the GPO is stored to be applied)
Should it be
Domain.local\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
OR SHOULD IT BE
Server-1\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
WHICH ONE OF THESE IS THE CORRECT ONE (domain.local being the domain name and Server-1 being the server name)?

Also when i run RSoP on a workstation (For a user) i get the error i said about (inthe first post) and it shows no GP that i set for that user.When i run RSoP on the server for the same user it shows all the GP set and no errors.
So i think that there must be a problem on the computers (where it looks for GP or something that stops it applying).

ANY HELP,
THANKS.


Jennifer SUMN - Sorry about the bad spelling, it is a bit that i am not great at spelling, a bit bad typing and not checking that well.


0

Response Number 19
Name: guapo
Date: May 30, 2008 at 20:45:34 Pacific
Reply:

I looked at at few MS sites and one of them warns not to confuse the SYSVOL and sysvol folders.

Another says that the default path is: C:\Windows\Sysvol\Domain folder but that it can be changed and that a new tree can be created.

If you search for sysvol where is it?


0

Response Number 20
Name: Chris (by Chris Kirk)
Date: May 31, 2008 at 09:22:49 Pacific
Reply:

I could not find the correct network location of the sysvol folder, but from what i have read i think that
Domain.local\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
is right.

One thig that i came up with is if i could change the location GP on each workstation looks for these .adm files.
(because it say
Domain.local\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm
can not be found, shown by PSoP)
I don't know if i could change the location that the computer looks for the .adm files.
(I can not use the domain GPO, but i can user Local GP.)

If this is possible, please tell me how, or any things that could help to fix this.

Any help,
Thanks


0

Response Number 21
Name: guapo
Date: May 31, 2008 at 13:10:41 Pacific
Reply:

I meant the location of sysvol on the server, such as what MS says is the default - C:\windows\sysvol.

Wouldn't a network location have \\ at the beginning of the path?

\\Server_machine_name\blah\blah1....


0

Response Number 22
Name: Chris (by Chris Kirk)
Date: June 2, 2008 at 08:39:28 Pacific
Reply:

The shared SYSVOL folder is C:\windows\sysvol
That is the folder is C:\windows\sysvol\sysvol

The folder can be accesed from
\\Server-1\sysvol

The folder that RSoP says 'Error - the network path was not found is
\\Domain.local\Sysvol\Domain.local\Polcies\{GP No}\Adm\system.adm


0

Response Number 23
Name: guapo
Date: June 2, 2008 at 17:26:54 Pacific

Response Number 24
Name: Chris (by Chris Kirk)
Date: June 3, 2008 at 13:27:32 Pacific
Reply:

net start in command prompt there is no Lanmanserver or Service Service.
How do you start it (if it is needed) as it is not in services in computer management.

What is ment by;
Make sure that AutoShareServer and AutoShareWks are set to 1 on all computers.


0

Response Number 25
Name: guapo
Date: June 3, 2008 at 21:29:47 Pacific
Reply:

http://support.microsoft.com/kb/245117
That explains auto share.

The lanman service is just called 'server' in services.


0

Response Number 26
Name: Chris (by Chris Kirk)
Date: June 4, 2008 at 08:15:29 Pacific
Reply:

The Server service is started.

The shares like C$, D$ and admin$ 3exsist and work.

I can not find
AutoShareServer and AutoShareWks
in regedit under
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters
(Probely because that artical is for win 2000 server not 2003)


0

Response Number 27
Name: guapo
Date: June 4, 2008 at 09:01:52 Pacific
Reply:

I thought the article said that you had to create that key.


0

Response Number 28
Name: Chris (by Chris Kirk)
Date: June 4, 2008 at 10:04:03 Pacific
Reply:

no it just says
'configure the AutoShareServer and AutoShareWks registry values to use the value data 1 (one)'
which to me means change the value to 1

But should i try crateing the keys, would that work?


0

Response Number 29
Name: guapo
Date: June 4, 2008 at 19:13:21 Pacific
Reply:

No, don't create the keys. I think your're right about it not applying to Server 2003.

Instead, let me direct you to a more technical forum. It's at www.minasi.com

Those guys have far more server experience than the forum members here, including myself. Join that forum and post your question there.


0

Response Number 30
Name: Chris (by Chris Kirk)
Date: June 11, 2008 at 05:19:00 Pacific
Reply:

Thanks for all your help,
But i have now fix the problem - itr was a problem with the DNS setup and now GP applies fine


0

Response Number 31
Name: guapo
Date: June 11, 2008 at 17:13:18 Pacific
Reply:

I'm glad you hear it's finally solved.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows Server 2003 Forum Home


Sponsored links

Ads by Google


Results for: Group policy

Group policy www.computing.net/answers/windows-2003/group-policy/4664.html

Thin Clients & AD Group Policies www.computing.net/answers/windows-2003/thin-clients-amp-ad-group-policies/3176.html

Win 2003 Serv Group Policy www.computing.net/answers/windows-2003/win-2003-serv-group-policy/1996.html