Updated GPO hasn't applied to all computers in OU

Daisy Zhou 20,791 Reputation points Microsoft Vendor
2020-07-15T06:24:02.027+00:00

Hi,
In my domain we have a group policy deployed for the 'Computers' OU as a workstation policy to configure some things. Recently we've added an item within this GPO to remove local admin access for domain users by configuring a restricted group for builtin/administrators.
From the looks of it, the majority of users are no longer admins and the policy has applied to their computers, however there are reports of some users still with admin permissions. It's like these computers haven't updated group policy and applied the new setting.
I was under the impression that when the users come back on site and login, group policy would update and remove local admin access...
All computers are in the correct OU for the GPO. The GPO does not have enforced checked if this makes a difference.
I know I can run gpresult, etc on individual computers, but is there a way or a tool where I can see which computers within this OU haven't updated GP and received the restricted group item so I can address? Or is the easiest way for this to right click on the GPO and force gpo update for the OU - I think the issue with this will be computers that are powered off, etc wont get the forced gp update though.

Thank you

Source link:
https://social.technet.microsoft.com/Forums/windowsserver/en-US/5e27b202-9a19-448d-8e66-9778529d4bcc/updated-gpo-hasnt-applied-to-all-computers-in-ou?forum=winserverGP

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,998 questions
0 comments No comments
{count} votes

Accepted answer
  1. Fan Fan 15,321 Reputation points Microsoft Vendor
    2020-07-15T06:35:29.37+00:00

    Hello,

    According to your description, we have applied a Group policy to the OU which contains computers. Later we applied a restricted group policy within this GPO. But it seems that the GPO has not applied to all the computers. Here we would like to check with you about the following points.

    To better understand our question, would you please tell us the following information:

    1. According to “In my domain we have a group policy deployed for the 'Computers' OU as a workstation policy to configure some things.”, do we mean we have an OU called “Computers”?

    If so, by default, I know we all have a built-in container called “Computers”, so if I create a new OU called “Computers”, but I cannot create the OU with “Computers” name, and I receive the following error message.
    12247-10.png

    1. According to“Recently we've added an item within this GPO to remove local admin access for domain users by configuring a restricted group for builtin/administrators.”, have we configured to add domain users or groups to local Administrators on the clients via GPO restricted group policy settings before? If so, we can try to edit the corresponding GPO and removed the settings to remove local admin access for domain users on the clients.
      12379-11.png
    2. According to “I was under the impression that when the users come back on site and login, group policy would update and remove local admin access...”

    Because Restricted group is computer configuration, as for the computer policy, it will be applied once it starts up. Besides, only the admins could see the computer policy.

    4, According to our question “ I know I can run gpresult, etc on individual computers, but is there a way or a tool where I can see which computers within this OU haven't updated GP and received the restricted group item so I can address? “, we could logon each computer to have a check by running “gpresult /h” if possible.

    For the computer policy, if the computers are running and are connected to the domain and the users are logged on, the GPO settings will be refreshed by any one of the following three methods:

    Method 1. All the computer group policy settings will be applied when we restart the machines,
    Method 2. We can run gpupdate /force command to refresh GPO settings manually.
    Method 3. If we do not do anything, the GPO settings will be refreshed after 90-120 minutes.

    For the computer policy, if the computers are powered off, they cannot apply the GPO settings.

    Hope the information is helpful. If you still have problems, please contact with us.

    0 comments No comments

0 additional answers

Sort by: Most helpful