Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Internet Explorer Maintenance GPO Weirdness

Status
Not open for further replies.

mhiney

IS-IT--Management
May 30, 2003
79
IE
Here's the scenario:

Domain is Server 2003 SP1/2000 Server SP4 at 2000 Functional Level, clients are mixed 2000 SP4 and XP SP2.

I have 2 GPOs at the root of my Domain: Default Domain Policy and Internet Settings. The latter is kept separate so that I can implement a "No Internet Access" security group.

I'm aware of the XP SP2 bug where Application Data Folder Redirection kills IE Maintenance policies, and that does not apply in my case.

Default Domain Policy contains no Internet Explorer Maintenance settings. I've verified this a number of ways, including the absence of an IEAK folder in the GPO folder under Sysvol.

I need to change some settings in the Trusted Sites security zone, and have mode the necessary modifications in my Internet Settings GPO. All is well so far.

Yet these settings do not come down onto PCs. Using RSOP I can see that - for some reason - Default Domain Policy takes precedence for these settings, and deploys the defaults to my users.

Linking my Internet Access policy to other OUs further down the tree does nothing to change this situation. Nor does switching it to "enforced". My AD replication is fine, everything has just been recently health checked and there are no errors. Windows Firewall is definitely switched off.

I could put the security zones settings into my Default Domain Policy, but that would mean having to split related settings across two different GPOs, which I really don't wish to do.

Anybody know what on earth is going on there?

________________________
Prevention is better than cure - fix it before it becomes broken.
 
I have had problems with IE Maintenance policies, and have seen many others have issues as well. When I first set mine up, it seemed to work. Then I made a change, and everything broke. I even created a new GPO from scratch, to no avail. I got impatient and couldn't deal with the non-working policy any longer, so I just scripted everything out and wrapped it up into a user logon script policy on it's own (seperate from other logon policies).

This took care of my issues immediately. If I make a change, the user get's the change at next logon regardless of any other factors.

Needless to say, I don't user IE Maintenance policies any longer...at least until MS provides decent documentation and fixes current issues.

Hope This Helps,

Good Luck!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top