Posts tagged ‘GPMC’

Updated: Group Policy Hotfix’s in Windows 7 and Windows Server 2008 Service Pack 1

Microsoft today  announced (after what seems to be a very long time) they have RTM’d Windows 7 / Windows Server 2008 R2 Service Pack 1 and it will be released to the public on February 22nd.

Update: Service Pack 1 is now available for download for TechNet and MSDN subscribers.

image

Previously I had listed the hotfixes in the beta version of the service pack, so I have again combed through the hotfix list for you convenience and I have updated the list to include the release candidate hotfixes. While this is not the final list of hotfixes Ned Pyle [MSFT] says “it’s very doubtful that the lists below will be altered much” so you can pretty much take the following list as final. In any case I will review the list when the final list of fixes is out but for now here is the list of issues.

Updated: The final list of hotfixes is now out ( Here ) and after a quick look they appear to be the same as expected.

If you have anything to do with supporting group policy in your organisation then I recommend that you at least take a look at the articles to see if you have encountered any of the problem described.

KB Article / Link KB Description

http://support.microsoft.com/kb/969867

FIX: You cannot import or paste some group policies across domains by using the "Group Policy Management" MMC snap-in

http://support.microsoft.com/kb/970840

Some settings in Group Policy Preferences for Internet Explorer 7 do not deploy correctly to computers that are running Windows Server 2008 or Windows Vista

http://support.microsoft.com/kb/972069

A terminal server that is running Windows Server 2008 cannot obtain terminal licenses from a Terminal Server license server that is running Windows Server 2008 after you enable the "License Server Security Group" Group Policy setting

http://support.microsoft.com/kb/976398

LDAP filters in the Group Policy preference settings do not take effect on a computer that is running Windows Server 2008 R2 or Windows 7

http://support.microsoft.com/kb/976399

FIX: You cannot apply Group Policy settings on a computer that is running Windows 7 or Windows Server 2008 R2 when security group filters are used in Group Policy preference settings

http://support.microsoft.com/kb/977353

A Group Policy Immediate Task preference item does not run on a client computer that is running Windows 7 or Windows Server 2008 R2

http://support.microsoft.com/kb/977695

The SceCli 1202 events are logged when some Group Policy settings are refreshed in Windows Server 2008 R2 and in Windows 7

http://support.microsoft.com/kb/977944

The "Desktop Wallpaper" Group Policy setting is not applied in Windows 7 or in Windows Server 2008 R2

http://support.microsoft.com/kb/978489

Logoff process stops responding after you create a logoff Group Policy script on a client computer that is running Windows Vista or Windows Server 2008

http://support.microsoft.com/kb/978837

The Group Policy Management Editor window crashes when you apply some changes for NRPT policy settings

http://support.microsoft.com/kb/979039

Error message when you view or modify the migrated Group Policy objects in Windows Server 2008 R2: "Attribute cannot be empty"

http://support.microsoft.com/kb/979731

Some Group Policy preferences are not applied successfully on computers that are running Windows Vista, Windows Server 2008, Windows 7 or Windows Server 2008 R2

http://support.microsoft.com/kb/980259

The SNMP service does not respond to any SNMP requests after a Group Policy refresh in Windows Vista or in Windows Server 2008

http://support.microsoft.com/kb/980628

The "Load a specific theme" Group Policy setting is not applied correctly on a computer that is running Windows 7 or Windows Server 2008 R2

http://support.microsoft.com/kb/981054

The Group Policy preference settings for the "Terminal Session" item-level targeting item are not applied in Windows 7 or in Windows Server 2008 R2

http://support.microsoft.com/kb/981177

You can still unpin a program from the taskbar unexpectedly when you enable the "Do not allow pinning programs to the Taskbar" Group Policy on a computer that is running Windows 7 or Windows Server 2008 R2

http://support.microsoft.com/kb/981265

You cannot create a software installation Group Policy setting on a read-only domain controller in Windows Server 2008 R2

http://support.microsoft.com/kb/981750

Error message occurs when you use GPMC to view a software restriction Group Policy setting in Windows 7 and in Windows Server 2008 R2: "An error has occurred while collecting data for Software Restriction Policies"

http://support.microsoft.com/kb/982606

The value of the "State" registry item is changed after a Group Policy preferences setting is applied in Windows Server 2008, in Windows Vista or in Windows Server 2008 R2

http://support.microsoft.com/kb/982709

Only the first search term is searched for when you configure the "Pin Internet search sites to the ‘Search again’ links and the Start menu" Group Policy setting in Windows 7 or Windows Server 2008 R2

http://support.microsoft.com/kb/983618

Some Group Policy settings are not displayed in the Group Policy Results report in Windows Server 2008, in Windows Vista, in Windows Server 2008 R2, or in Windows 7

http://support.microsoft.com/kb/2096902

Virtual machines in a VDI environment are not rolled back as expected if the disconnected Remote Desktop connections on the virtual machines are stopped by Group Policy

http://support.microsoft.com/kb/2284538

"Apply once and do not reapply" Group Policy setting is never applied after the first GPO deployment fails on a client computer that is running Windows 7 or Windows Server 2008 R2

http://support.microsoft.com/kb/2254754

You experience a GPO report-generation issue in the GPMC window when you try to generate the report in a localized version of Windows 7 or of Windows Server 2008 R2

http://support.microsoft.com/kb/2258620

You cannot find the "Find Now," "Stop," and "Clear All" buttons in the GPMC snap-in on a computer that is running Windows 7 or Windows Server 2008 R2

http://support.microsoft.com/kb/979383

After you apply a WMI filter, the GPO does not take effect on a client computer that is running Windows 7 or Windows Server 2008 R2

http://support.microsoft.com/kb/2028960

The Offline Files Disk Usage Limits settings do not reflect the settings that are defined in the GPO in Windows 7

 

You can also see the complete list of Active Directory Hotfix’s at Ask the Directory Services Team blog posting SP1 and Directory Services: What’s New .

Group Policy FAQ #1: What are the Group Policy Preferences Prerequisites?

Even though Group Policy Preference have been out for a number of years (since Windows Server 2008) it is still a relatively unknown feature of group policy. Therefore this is the first of a few articles I am going to be writing about some of the basic features of Group Policy Preferences. So to start off with I am going to cover a few FAQ on what you need to do start using all the Group Policy Preference goodness.

Do I need to extend the schema to use Group Policy Preferences?

NO. There are no schema extensions required to support Group Policy Preferences as they work by only creating a folder called “Preference” under the User and/or Computer folder in the SYSVOL.

What are the minimum version of domain mode or domain controllers I need to support Group Policy Preferences?

Unofficially Windows 2000 Domain Mode with Windows 2000 DC’s will work fine. However officially it is what ever the minimum support OS and domain mode of Active Directory is at the time.

What software do I need to install to use Group Policy Preference?

To make it easy the table below outlines what software you need to install to enabled group policy preference on the client and to make changes to the

Operating System Client Side Extensions Required Group Policy Management Console
Windows XP Yes (SP2 also requires XmlLite) Not Supported
Windows Server 2003 Yes (SP2 also required XmLite) Not Supported
Windows Vista Yes Yes (via Remote Server Admin Tools)
Windows Server 2008 Included Yes
Windows 7 Included Yes (via Remote Server Admins Tools)
Windows Server 2008 R2 Included Yes

How do I get the client side extensions?

Below is a list of links to the download page for the client side extensions for the versions of Windows that do not have it install out of the box.

If you are still running Windows XP or Windows Server 2003 Service Pack 2 (OMG THAT IS SO BAD) then you will also need to install the XmlLite to make preference work.

How do I install the client side extensions?

You can install the client side extensions a number of ways in your environment:

Tip: If you want to do limited testing of Group Policy Preference in your environment and you are still running Windows XP or Vista then you can selectively just rollout the extensions to the computer you want to do testing. This is because there will be no affect in applying a preferences setting to a computer that does not have the client side extensions installed.

Do I need to install the client side extensions for Windows Server 2008, Windows 7 or Windows Server 2008 R2?

No. It is part of the operating system.

Why cant I edit Group Policy Preference from Windows XP or Windows Server 2003?

While the client side extensions for Group Policy Preferences are supported on Windows XP and Windows Server 2003 the version of Group Policy Management Console (GPMC) for XP/2003 has not been updated and therefore does not allow the editing of GPP’s in any way shape or form. This therefore means you need at minimum at least 1 Windows Vista (yuck) or Windows Server 2008 server with Group Policy Management Console installed to edit Group Policy Preferences in your environment even if every other server and workstation is running 2003 and XP.

How do I install the Group Policy Management Console?

GPMC is a component of the Remote Server Admin Tools for Windows 7 / Vista and is an optional feature that needs to be installed with Windows Server 2008 & R2. See my instructions for installing GPMC on Windows 7 and 2008 R2 at How to download and install the Group Policy Management Console (GPMC)

Summary

So if you are thinking about using Group Policy Preference in your environment don’t stress… Its a really simple process and as soon as you have GPMC on one or two computers and the client side extensions install on all the computers you want to apply preference to then you ready to go…

Tip: How to ensure Organisation Unit are protected from accidental deletion

This is a simple tip that I want to share about the right way to Organisation Units  to ensure that you always have them protected from accidental deletion.

Ever since Windows Server 2008/Vista there has been an option in ADUC called “Protect container from accidental deletion” (see image below).

image 

The affect of ticking this check box was that the “Everyone” group would be granted deny delete permission (see below) on the object so that it would be very hard for you to accidently delete an OU (and all of its contents) even if you are a Domain Admin. NICE!!!

image

image

This is a very handy option to have enabled on all you OU’s (groups and users) as we all know that it quite easy to accidently delete something when you are working late or just under the pump with a million things on your plate.

However…

You may also be aware that the Group Policy Management Console also has as option to create new new Organisation Unit (see below).

image

image

The problem with using GPMC is that the tool does not implement “Protect container from accidental deletion” deny security permission on the OU as the ADUC tool does (see below).

image

So in summary, even though it might be really convenient to create OU’s in GPMC I recommend that you do NOT do this as you might end up regretting you ever did when you accidently pressed delete one to many times…

Internet Explorer 9 (Beta) Group Policy Settings

IE9-banner2

Microsoft has now released to the public (download it here) the newest version of Internet Explorer 9 Beta to the public. If you want to know more about the new features in IE9 then i recommend that you check out http://www.beautyoftheweb.com/ to see some of the fantastic stuff that this browser enables. If the new functionality alone is not enough to get you to use it is just remember that it is now a Fully Hardware accelerated which makes it much faster than any other browser on the market!!!

With any new version IE there comes new features and with new features comes new group policy settings so below I go through the new policy settings and how you can get started right now with managing IE9 using Group Policy.

To get started you will need to download and install IE9 on whatever computer you are using Group Policy Management Console (a.k.a. GPMC) to edit your Group Policy settings as with anything to do with Group Policy it is normally best to make changes from a systems that has the newest software on it in your organisation.

WARNING: This software is still Beta so you are strongly recommended to isolate any testing you do with IE9 and Group Policy from your production environment.

Continue reading ‘Internet Explorer 9 (Beta) Group Policy Settings’ »

Group Policy Search

Here is another video from Lilia Gutnik (Program Manager with the Group Policy Team) on TechNet Edge about the search features in the Group Policy Management Console. If you have every lost a Group Policy Object or just made an edit and was not sure which GPO you were in then this video will show you how to use the advanced search features in GPMC. Very AWESOME!

 

I recommend you watch to the end to the very end… Winking smile