Okay, I've been testing deployment of several apps via GPO in a small lab environment. Setup and deployment work ok. Under the Computers OU, I have three other ones, Servers, Workstations - NoGPO and Workstations - GPO. Only Workstations - GPO has a policy for installing apps. I placed specific computer accounts into that OU. Then, under the groups OU, I created groups for each app, such as SW-Adobe7.0, SW-Lotus6.5.4, SW-Winzip, etc.
I added software installs for each app, pointing to the appropriate MSI. I then edited the security for each app install, unchecking the security inheritance, but selecting to copy the existing settings. I set the Servers OU to deny access, and then if I was editing the one for Winzip, I'd give the SW-Winzip group read access to that software install. I did the same for each app.
Everything was working perfectly. Then I setup a laptop on my lab network, joining it to the domain. I placed the computer account in the Workstation - GPO OU, and then placed the computer account in the SWLotus6.5.4 user/computer group. I then rebooted so that GPO could push Lotus onto the PC. When I did so, it installed every application from that GPO. The odd thing is, I rebooted the other workstations (of which two others were also in the SWLotus6.5.4 group) and no other workstation reacted the same. Just that one PC.
Anyone ever seen this? I can post a representation of the ACL for the software install, they're all configured the same for each app.
I added software installs for each app, pointing to the appropriate MSI. I then edited the security for each app install, unchecking the security inheritance, but selecting to copy the existing settings. I set the Servers OU to deny access, and then if I was editing the one for Winzip, I'd give the SW-Winzip group read access to that software install. I did the same for each app.
Everything was working perfectly. Then I setup a laptop on my lab network, joining it to the domain. I placed the computer account in the Workstation - GPO OU, and then placed the computer account in the SWLotus6.5.4 user/computer group. I then rebooted so that GPO could push Lotus onto the PC. When I did so, it installed every application from that GPO. The odd thing is, I rebooted the other workstations (of which two others were also in the SWLotus6.5.4 group) and no other workstation reacted the same. Just that one PC.
Anyone ever seen this? I can post a representation of the ACL for the software install, they're all configured the same for each app.