Group Policy

  • Thread starter Thread starter Frankie
  • Start date Start date
F

Frankie

This goes out to any networking people. I'm stuck on a problem w/
administering Group Policies (GP).
I'll first explain the setup I have:

The Domain Controller is running 2000 Server (Server1)
The member system is running 2000 Pro (galvatron)
The domain is cybertron.com

I have a user on the Pro system (user1) who logs onto cybertron.com as
([email protected]) which it has no problem doing.

I installed Active Directory (AD) on the Server system.

I go into Active Directory Users and Computers (ADUC) where I created an
Organizational Unit (OU) named ONE. I added user1 into that OU and created a
GP in that OU named REMOVERUN. I then went to Edit that GP and enabled the
REMOVE RUN FROM START MENU. I've tried running secedit /refreshpolicy
user_policy /enforce from Server1 which it says it has refreshed the policy,
I've evrn restarted the Pro system and then log back into the domain as
(e-mail address removed) and the Run command is still present.

Now I've also added a GP at the Domain level of cybertron.com and removed
the Run command then I log onto Server1 w/ the Administrator account and the
Run command is gone.

I'm not sure what I'm doing incorrect. I've followed the Windows textbooks,
I follow my cbtnuggets videos and still no luck. I'm thinking its something
minor but not sure what it could be.

If anyone has any experience running a 2000 Network Environment and can lend
a hand please let me know. This is on a test network in my home. Both
systems are connected to a Router and I use a KVM to switch from each
system. I set this up about a week ago to get more hands on w/ AD and
doesn't seem to be working for me. Thanks for any input.
 
Hi Frankie. First, go into Event Viewer on the Win2k Pro machine and look
in the application log for Userenv errore (Event ID 1000). If they are
there, please post the text of the message.

Some things to look at:
- check the TCP/IP settings on the client machine and make sure it is
pointing to the domain controller for it's preferred DNS server.
- look in the Domain Controller Security Policy under Computer
Configuration\Security Settings\Local Policies\User Rights Assignment and
make sure the Everyone group is included in the "Access this computer from
the network" right.
- Download gpresult.exe from
http://www.microsoft.com/windows2000/techinfo/reskit/tools/existing/gpresult
-o.asp and run the following from a cmd prompt:

gpresult /s >c:\gpresult.txt

The gpresult.txt file will show what group policies are being applied to
this computer.

Jimmy Harper [MSFT]
Directory Services
This posting is provided "AS IS" with no warranties, and confers no rights
 
Back
Top