Hi all,
It's been a while since I've used Group Policies and I thought what I wanted to do was simple enough, however it doesn't seem to be working and I can't figure out why, which is now confusing me even more!!
Basically, I want to install a piece of software via a policy to a specific group of people. These users are setup in AD across multiple OUs, therefore the policy I created was put in at domain level, expecting it to inherited by the OUs below.
In a nutshell this is what I did:
1. Create a new group policy. For Computer settings (I want the software to install at start-up) I created a new software installation and pointed it the the server share that contains the software msi file. This share has read permissions for evey user set up (as well as security permission on the actual folder.)
2. Attached the policy at domain level and set it to 'Enforced' so any OUs blocking inheritence is overwritten.
3. Created a security group in AD, and added all the relevant users as members.
4. Added the new security group with read and apply group policy permissions on the new group policy (and removed apply group policy on the authenticated users group)
When I run Group Policy results in GPMC and look at the results it tells me the policy is denied "Access Denied (Security Filtering)"..... which is where I am stuck; the permissions to read and apply the policy are applied to the group so why is access denied?
I'm probably missing something simple but I just can't put my finger on it.
Any ideas please?
Many thanks.
James
It's been a while since I've used Group Policies and I thought what I wanted to do was simple enough, however it doesn't seem to be working and I can't figure out why, which is now confusing me even more!!
Basically, I want to install a piece of software via a policy to a specific group of people. These users are setup in AD across multiple OUs, therefore the policy I created was put in at domain level, expecting it to inherited by the OUs below.
In a nutshell this is what I did:
1. Create a new group policy. For Computer settings (I want the software to install at start-up) I created a new software installation and pointed it the the server share that contains the software msi file. This share has read permissions for evey user set up (as well as security permission on the actual folder.)
2. Attached the policy at domain level and set it to 'Enforced' so any OUs blocking inheritence is overwritten.
3. Created a security group in AD, and added all the relevant users as members.
4. Added the new security group with read and apply group policy permissions on the new group policy (and removed apply group policy on the authenticated users group)
When I run Group Policy results in GPMC and look at the results it tells me the policy is denied "Access Denied (Security Filtering)"..... which is where I am stuck; the permissions to read and apply the policy are applied to the group so why is access denied?
I'm probably missing something simple but I just can't put my finger on it.
Any ideas please?
Many thanks.
James