Troubleshooting / symptôme

A GPO does not apply to a position

A group strategy is not applied to a user or computer.

⌚ About 4 min read
View my favorites
Real-world problem · V2

Quick troubleshooting view

What you are seeing

A group strategy is not applied to a user or computer.

Likely causes
  1. Bad OR
  2. Safety filtering
  3. WMI filter
First checks
  1. Generate a strategy result
  2. Check the OR of the object
  3. Check filter
Recommended actions
  1. Link GPO to the correct OR
  2. Correcting security filtering
  3. Correct replication or access if necessary SysVOL
Start Symptom → Cause →
Active DirectoryIntermediate.

A group strategy is not applied to a user or computer.

Important: relevez toujours le message d’erreur exact et l’heure du problème avant de modifier la configuration. Les actions proposées doivent être adaptées à votre environnement.

Causes probables

  • Bad OR
  • Safety filtering
  • WMI filter
  • AD/SYSVOL replication
  • DNS
  • Conflict/priority between GPO

Diagnostic étape par étape

  1. 1

    Generate a strategy result

    Use gp in 2002 to see GPOs applied and rejected.

  2. 2

    Check the OR of the object

    Control the user account, location or computer.

  3. 3

    Check filter

    check out Security Filtering and possible WMI filters.

  4. 4

    Realizing strategies

    Run gpupdate /force after correction.

Commands utiles

gp - 2002 /h C: -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -/ -// -/ -/ -/ -/ -/ -// -/ -/ -/ -/ -/ -/ -// -//// -/ -/ -/ -/ -////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
gpupdate /force.

Solutions possibles

  • Link GPO to the correct OR
  • Correcting security filtering
  • Correct replication or access if necessary SysVOL
Quand escalader ?

Clash if different GPOs fail on multiple domain controllers.

♡ 0