Mark
On Oct 4, 2004, at 12:50 PM, [EMAIL PROTECTED] wrote:
I've had a similar problem. In digging through the problem, I found some of the following, usually by tracing through the eventlog on the respective machine.
• Computer account had a problem in the domain - just needed to be removed and put back in
• GPO policy processing - changed respective templates to always apply even if no changes had occurred
• NIC/Switch Port config - Found that there were cases that the computer would come up for login before the network connection was fully initialized. Once discovered it was simple to test. Simply boot up, logon..wait for everything to settle down. Then unplug the NIC and plug it back in. The network connection should come back immediately. If it doesn't then its possible that the computer may also be starting up before there's an available connection to a DC. This would cause inconsistent processing of user policies and prevent application of computer policies, other than those that had already been applied
• Local Policies on the computer - Local policies seem inert and possibly unimportant once on the AD domain, but....not in our environment. It was a 'twisted' implementation of local policies...scripts...and other things to ensure that local polices applied, reapplied...and couldn't be unapplied. So when we migrated the machines to AD, we experienced an unbelievable series of unpredictable results. Needless to say, one of which, was the lack of consistent GPO application - One of the permanent fixes was to automate the application of "Setup Security.inf" to all the respective clients upon their migration of AD
The biggest problem by far was simply getting consistent failures to troubleshoot or getting the exact details of the respective occurrence from the desktop people in the field.
When all else fails...turn up GPO and Winlogon logging, turn on failure auditing...get a fine tooth comb and settle in for a nice long debug session...
Hope this helps.
Eric Jones, Senior SE
Intel Server Group
(W) 336.424.3084
(M) 336.457.2591
www.vfc.com
<x-tad-smaller><[EMAIL PROTECTED]></x-tad-smaller><x-tad-smaller> </x-tad-smaller>
<x-tad-smaller>Sent by: [EMAIL PROTECTED]</x-tad-smaller>
<x-tad-smaller>10/04/2004 11:52 AM</x-tad-smaller>
<x-tad-smaller>Please respond to</x-tad-smaller>
<x-tad-smaller> [EMAIL PROTECTED]</x-tad-smaller>
<x-tad-smaller>To</x-tad-smaller>
<x-tad-smaller>[EMAIL PROTECTED]</x-tad-smaller>
<x-tad-smaller>cc</x-tad-smaller>
<x-tad-smaller>Subject</x-tad-smaller>
<x-tad-smaller>Re: [ActiveDir] GPO's not always applied.</x-tad-smaller>
<x-tad-smaller>Hey Mark...</x-tad-smaller>Mark Orlando
<x-tad-smaller> You can try /computer configuration/administrative templates/system/group</x-tad-smaller>
<x-tad-smaller> policy/scripts policy processing</x-tad-smaller>
<x-tad-smaller> You can set to always process over slow connections, and even if the GPO</x-tad-smaller>
<x-tad-smaller> hasn't changed.</x-tad-smaller>
<x-tad-smaller> HTH</x-tad-smaller>
<x-tad-smaller> John</x-tad-smaller>
<x-tad-smaller> </x-tad-smaller>
<x-tad-smaller> Mark Orlando </x-tad-smaller>
<x-tad-smaller> <[EMAIL PROTECTED] </x-tad-smaller>
<x-tad-smaller> com> To </x-tad-smaller>
<x-tad-smaller> Sent by: Active Directory Mailing List </x-tad-smaller>
<x-tad-smaller> [EMAIL PROTECTED] <[EMAIL PROTECTED]> </x-tad-smaller>
<x-tad-smaller> ail.activedir.org cc </x-tad-smaller>
<x-tad-smaller> </x-tad-smaller>
<x-tad-smaller> Subject </x-tad-smaller>
<x-tad-smaller> 10/04/2004 10:46 [ActiveDir] GPO's not always </x-tad-smaller>
<x-tad-smaller> AM applied. </x-tad-smaller>
<x-tad-smaller> </x-tad-smaller>
<x-tad-smaller> </x-tad-smaller>
<x-tad-smaller> Please respond to </x-tad-smaller>
<x-tad-smaller> [EMAIL PROTECTED] </x-tad-smaller>
<x-tad-smaller> tivedir.org </x-tad-smaller>
<x-tad-smaller> </x-tad-smaller>
<x-tad-smaller> </x-tad-smaller>
<x-tad-smaller> I am having issues with GPO's not being fully applied at every login.</x-tad-smaller>
<x-tad-smaller> I need to change this. I know it might have something to do with the</x-tad-smaller>
<x-tad-smaller> volume of LAN traffic but I need to find away around this.</x-tad-smaller>
<x-tad-smaller> I also have some add printer login scripts that don't always work</x-tad-smaller>
<x-tad-smaller> either. I have the scripts running synchronously and slow link</x-tad-smaller>
<x-tad-smaller> detection set to 0. Does anyone have any ideas?</x-tad-smaller>
<x-tad-smaller> Mark Orlando</x-tad-smaller>
<x-tad-smaller> Systems Administrator</x-tad-smaller>
<x-tad-smaller> I.T. Department</x-tad-smaller>
<x-tad-smaller> Linden Public Schools</x-tad-smaller>
<x-tad-smaller> List info : http://www.activedir.org/mail_list.htm</x-tad-smaller>
<x-tad-smaller> List FAQ : http://www.activedir.org/list_faq.htm</x-tad-smaller>
<x-tad-smaller> List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/</x-tad-smaller>
<x-tad-smaller> List info : http://www.activedir.org/mail_list.htm</x-tad-smaller>
<x-tad-smaller> List FAQ : http://www.activedir.org/list_faq.htm</x-tad-smaller>
<x-tad-smaller> List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/</x-tad-smaller>
Systems Administrator
I.T. Department
Linden Public Schools