All Questions

Filter by
Sorted by
Tagged with
0 votes
1 answer
63 views

GPO - Missing "Manage updates offered from Windows Server Update Service"

in our Windows Server 2019 DC we are missing the following Administrative Template: Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > ...
Duncan_McCloud's user avatar
0 votes
1 answer
70 views

Cannot limit file access auditing on Windows Server 2019

I'm trying to implement file access auditing on a Windows Server 2019 machine with mixed success. The server in question is a member server, but not a domain controller. I have enabled success ...
CatchAsCatchCan's user avatar
-1 votes
1 answer
180 views

assign AD GPO to a specific set of computers: what mechanism?

(In exploratory mode: not sure what is the right question to ask, and how to ask it. Also, new to AD GPOs: please forgive lack of clarity in the question.) Question: how do I assign an Active ...
kindzmarauli's user avatar
0 votes
1 answer
231 views

Event 1202 when trying to run a scheduled task GPO under NT Authority\System

I'm trying to get a barcode font installed on machines for a enterprise application. The GPO is being served from a Windows Server 2019 Standard version 1809 OS build 17763.4252 server. The GPO in ...
Liam Chaney's user avatar
0 votes
0 answers
35 views

Password Policy Changes On Non-PDC Domain Controllers

I have a DC I just added to my domain as a backup so it does not have a PDC role. I have the password policy set on the Default Domain policy. There are no Fine Password Policies setup. When I check ...
JukEboX's user avatar
  • 835
0 votes
1 answer
485 views

Kerberos settings in GPO never seem to apply in spite of the GPO otherwise working

Server 2019 Domain Environment. Issue is related to the DCs themselves. I've a self-created GPO on my DC OU that sets a bunch of things, several of which are Kerberos settings: Curiously, while ...
The ITea Guy's user avatar
0 votes
1 answer
2k views

Handling GPO Policies between different domains

I have a handful of changes in a policy that I'd like to apply to other domains. I am wanting to copy this policy to these other domains so I do not have to create them for every dc. Most of what I've ...
ErocM's user avatar
  • 226
1 vote
1 answer
364 views

Stumped on why my Startup GPO Script isn't executing BCDEdit correctly

Environment: MS Server 2019 DC, Windows 10 Workstations joined to the Domain. The goal here is to set the Data Execution Prevention on a bunch of machines to OptOut. The way to do this via a command ...
The ITea Guy's user avatar
0 votes
0 answers
93 views

Complex Password GPO Security Filtering Access Denied

We are just trying to apply a password policy to a set of users of a security group, we've added the security group to the Security Filtering, but when running the Group Policy Modeling with a user ...
Ronald Simmons Jr's user avatar
0 votes
0 answers
113 views

How do I limit Remote Desktop Connection access using GPO's in Active Directore

I am pretty new to designing Active Directory domains and using GPO to make settings ont he local machine. However, I have been set a task and am struggling. I have a Server 2019 virtual instance ...
ICSOTSecurityEngineer's user avatar
0 votes
1 answer
296 views

Why Get-GPResultantSetOfPolicy doesn't show all the settings

I'm trying to verify GPO settings on the Windows Server 2019 machine. To do this, I export GPO settings using PowerShell Get-GPResultantSetOfPolicy command: Get-GPResultantSetOfPolicy -ReportType Xml -...
Savetree Eatbeaver's user avatar
1 vote
2 answers
2k views

Customize start menu from Windows through GPO not working

I am trying to implement through a GPO, a new Start Menu Layout but no matter what I do it simply dont apply. This is the XML of this Layout: <?xml version="1.0" encoding="utf-8"...
marafado88's user avatar
0 votes
1 answer
2k views

Group Policy scheduled task for running .bat file applies, but task does not create

I am trying to add a scheduled task to run a batch file that updates / installs software. I created a GPO to create the task, using these settings: Task Settings Task settings 2 Task settings 3 For ...
Dylan Skyler Miller's user avatar
-1 votes
2 answers
2k views

Can't logon to domain controllers

We have 2 domain controllers with 2019 server, system administrator made something with GPO which deny access for group "Domain Admins" to workstations, now it is distributed throughout the ...
cozby's user avatar
  • 7
0 votes
0 answers
2k views

Windows Server 2019 GPO - "User Policy Update Failed"

My clients environment is a mix of Windows 2012, 2016 and 2019 servers. Recently we had a few additional Windows 2019 servers provisioned and added to our domain. When I run gpupdate /force from the ...
jrd1989's user avatar
  • 688
-1 votes
1 answer
2k views

Windows Server 2019 GPO won't copy fonts to C:\Windows\Fonts

Link to picture: https://gcdnb.pbrd.co/images/pwQHQ7qj8ere.png I'm trying to deploy Fonts via GPO but they refuse to be installed inside the Window folder. I tried just about every method. I also did ...
Adephx's user avatar
  • 3
0 votes
1 answer
1k views

RDP Windows server 2019

I'm connecting to one windows server 2019 from another windows server 2019 through RDP, when i close the connection using the "X" button and then try to open new RDP connection i get a ...
Zarkos.Fina's user avatar
0 votes
1 answer
1k views

Not defined state of the `Network security: Restrict NTLM: NTLM authentication in this domain` GPO

Is NTLM by default disabled on domain controllers with Windows Server 2019? My current tests show that the GPO Network security: Restrict NTLM: NTLM authentication in this domain does not work as ...
bahrep's user avatar
  • 687
0 votes
1 answer
2k views

Removing certain entries from start menu on server 2019

I've been trying to find a method to remove entries from the start menu. I've found a GPO that removes all the entries, which is not what I want. I've found that some shortcuts can be removed by ...
Alb's user avatar
  • 3
1 vote
1 answer
2k views

When do changes to the group policy take affect for remote desktop idle times?

I was setting up idle time settings for remote desktop services since I have users that are leaving themselves logged in at night with programs open. This is a Windows 2019 Standard server with remote ...
ErocM's user avatar
  • 226
0 votes
1 answer
657 views

Use cmd when "Run only specified Windows applications" policy is in effect

I am trying to restrict the applications usage on the VM Windows Server 2019. In Local Group Policy editor (gpedit.msc), i modified the policy, on the left pane, click/tap on to expand User ...
King Freak's user avatar
0 votes
1 answer
432 views

Group Policy Object (GPO) - bypass Computer Configuration for a specific AD Group (Admins)

is it possible to bypass a GPO "Computer Configuration" (Firewall Settings) for a specific AD Group ? We want a specific AD group to be able to disable the firewall. Currently this GPO ...
Maverick128's user avatar
0 votes
2 answers
11k views

Create a Windows Schedule Task via GPO to run as specified user

I am trying to create a Scheduled Task via Group Policy (Computer Configuration\Preferences\Control Panel Settings\Scheduled Tasks), to run as a specified domain service account. However, when Group ...
user3580480's user avatar
0 votes
1 answer
110 views

text file created on all terminal servers (unable to find where to disable)

I have strange problem in Windows Server 2019 environment with 2 domain controllers and 2 terminal servers. On every logon of new user, a text file is created on the user's desktop on both of TS's. I'...
culter's user avatar
  • 507
1 vote
0 answers
37 views

How to make printers installed by GPO/GPP have server-side settings?

I have a Windows Server 2019 domain controller which has some network printers installed using TCP/IP Port 9100 and publishes all of those printers as shares. The important thing to note is that while ...
Thorsten Schöning's user avatar
1 vote
0 answers
421 views

Grant database access through GPO

I have a domain in which I have couple servers with dedicated SQL Server databases. I also have couple external companies that need access to this servers and databases on different permission level (...
AnJ's user avatar
  • 151
2 votes
0 answers
2k views

Allow user/group to start/stop/restart windows service

I have 4 services. All of them are run by an individual user. All 4 users are part of a group I created (ServiceWorkers) which has the Log on as a service user rights assigned. Each service needs to ...
Alex's user avatar
  • 121
1 vote
0 answers
793 views

2019 Server GPO Not Applying to Windows 10 Systems

I am having an issue with a freshly built 2019 Active Directory Domain. I built this domain from the ground up in parallel to the existing and very broken 2008 r2 domain and so far everything has been ...
OldTexasBiker's user avatar
0 votes
0 answers
95 views

Active Directory cn=IP Security read data

I am trying to read cn=IP Security,cn=System,dc= from the domain controller. Although, i have the highest read permissions (as a user) and can read from other containers (such as Computers, Users etc) ...
Wood Chipper's user avatar
0 votes
1 answer
443 views

Need Group Policy to only to apply to users when logging into RDS Farm

I am trying to get a GPO to apply to users only when they login to the RDS Farm. Specifically I need to set their Outlook caching to a shorter period of time. I created the RDS GPO and added my ...
dmonks's user avatar
  • 3
1 vote
2 answers
2k views

Unexpected Folder Redirection: Why are user 'Documents' folder contents being redirected to \%username% rather than \%username%\Documents?

I have successfully implemented a Folder Redirection group policy for a specific user group in our organization; however, the folders are not being redirected as expected. My goal is to implement the ...
person0's user avatar
  • 111
2 votes
1 answer
3k views

"Access is denied" error when starting the Web Management Service

I am trying to set up Web Deploy on an IIS 10 server running on Windows Server 2019. The Web Management Service must be running in order for this to occur, but it will not start. I installed the ...
EJoshuaS - Stand with Ukraine's user avatar
0 votes
1 answer
1k views

Windows Server 2019 auditing removed as soon as applied

I've got a Windows Server 2019 domain controller with a GPO applying auditing on logon events. RSOP shows it is applied, however, if I look at the event logs, the moment it applies I can see that it ...
user568733's user avatar
0 votes
3 answers
29k views

Access Denied to SYSVOL from DC when using UNC path

I'm trying to solve an issue for a customer and I'm running out of ideas. We've upgrading all the hardware and server OS's. The domain now has two new Server 2019 DC's. The old DC's have been ...
Rhys W's user avatar
  • 1
4 votes
2 answers
2k views

Group Policy application on Domain Controllers

I am building a test Active Directory forest in a virtual environment. I will be part of a team in the future that will build a new Forest for our organization. I don't have experience managing a ...
user3271408's user avatar
1 vote
1 answer
1k views

How to restore Default Domain Policy?

I accidentally deleted "Default Domain Policy" in Group Policy Management -> Forest: mydomain -> Domain -> mydomain Actually I clicking Delete Link(s) thinking that only the link will be deleted; ...
Qeeet's user avatar
  • 123
0 votes
1 answer
20k views

How to access group policy of a Windows server 2019 Active Directory DC?

Before I enable AD DC in my Windows server 2019, I had modified some objects in group policy editor (gpedit), but after turning the server into an active directory domain controller, i don't know how ...
user avatar
2 votes
2 answers
13k views

Finding GPO policy which set's LocalAccountTokenFilterPolicy to 0 on startup

I've got a Windows Server 2019 with Windows Server 2019 Security Baseline settings applied to it. Then I enable WinRM on the server and set the registry key HKLM:\SOFTWARE\Microsoft\Windows\...
Gamlor's user avatar
  • 121
1 vote
1 answer
2k views

How to use member of trusted domain in GPO?

I have two test domains and one trusts another. On trusting domain GPO I need to add a group from trusted domain to remote desktop users group which will apply to all computer objects in trusting ...
sys's user avatar
  • 11