Tip

Troubleshooting group policies

This tip originally appeared on SearchWin2000.com, a sister site of SearchSmallBizIT.com.


Troubleshooting issues arising out of local security policy or group policy can be a challenge.

If a change does not seem to take effect on

    Requires Free Membership to View

a system, first log out then back on. Next, reboot the system. If the change still fails to take effect, examine the RSoP for the local system or access Help and Support Center (see the previous tip on RSoP for details). It is possible that some other GPO setting is overriding your intended change. This will be especially true if you made your change only to a local security policy when the system is a domain client.

I can't count the times these RSoP viewers have saved me. Being able to quickly find the effective setting on a specific policy element and know immediately in which exact GPO that setting was defined will save you hours of blind searching.

And don't forget the new Group Policy Management Console for Windows 2003 Active Directory domains. I discussed that tool in a tip a few weeks ago.

Many problems arise from the fact that changes to the local security policy may take immediate effect, only to be repealed once the domain (site or OU) GPO is refreshed after 90 minutes. Changes that seem to work immediately but get lost after an hour and a half are usually due to this artifact. Once again, only make changes to an AD container GPO for domain clients and to the local security policy for standalone or workgroup clients.

When troubleshooting a GPO-related issue, first attempt to boot the system without a domain connection using a local user account. Check the local security policy to see if it has conflicting or incorrect settings. Keep in mind that GPOs are applied in LSDOU order, so even if there is a bad setting in the local security policy, it may be overwritten by an AD container-level GPO.


James Michael Stewart is a partner and researcher for ITinfopros, a technology-focused writing and training organization.

Do you have comments on this tip? Let us know.


This was first published in November 2004

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to:

Disclaimer: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.