Lab: Group :Policy Troubleshooting

Lab: Group :Policy Troubleshooting
Hi

I already tried this lab a few times

  • Made sure that the user has access to the msi
  • Moved the Policy to the domain level
  • Created a new user
  • Deleted and created the policy again
  • Checked gpresult /r (and I do see that the policy is being applied)
    Nothing works, it does not install

P.S. when I make the policy under the computer settings it works right away

Please help

1 Like

This is the command output

Microsoft Windows [Version 10.0.14393]
© 2016 Microsoft Corporation. All rights reserved.

C:\Users\Administrator>gpresult /r

Microsoft ® Windows ® Operating System Group Policy Result tool v2.0
© 2016 Microsoft Corporation. All rights reserved.

Created on 7/2/2021 at 9:15:36 AM

RSOP data for AD\Administrator on SADC01 : Logging Mode

OS Configuration: Primary Domain Controller
OS Version: 10.0.14393
Site Name: Default-First-Site-Name
Roaming Profile: N/A
Local Profile: C:\Users\Administrator
Connected over a slow link?: No

COMPUTER SETTINGS

CN=SADC01,OU=Domain Controllers,DC=ad,DC=serveracademy,DC=com
Last time Group Policy was applied: 7/2/2021 at 9:13:35 AM
Group Policy was applied from:      SADC01.ad.serveracademy.com
Group Policy slow link threshold:   500 kbps
Domain Name:                        AD
Domain Type:                        Windows 2008 or later

Applied Group Policy Objects
-----------------------------
    Default Domain Controllers Policy
    Default Domain Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
    Local Group Policy
        Filtering:  Not Applied (Empty)

The computer is a part of the following security groups
-------------------------------------------------------
    BUILTIN\Administrators
    Everyone
    BUILTIN\Users
    BUILTIN\Pre-Windows 2000 Compatible Access
    Windows Authorization Access Group
    NT AUTHORITY\NETWORK
    NT AUTHORITY\Authenticated Users
    This Organization
    SADC01$
    Domain Controllers
    NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
    Authentication authority asserted identity
    Denied RODC Password Replication Group
    System Mandatory Level

USER SETTINGS

CN=Administrator,CN=Users,DC=ad,DC=serveracademy,DC=com
Last time Group Policy was applied: 7/2/2021 at 9:14:54 AM
Group Policy was applied from:      SADC01.ad.serveracademy.com
Group Policy slow link threshold:   500 kbps
Domain Name:                        AD
Domain Type:                        Windows 2008 or later

Applied Group Policy Objects
-----------------------------
    N/A

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
    Local Group Policy
        Filtering:  Not Applied (Empty)

The user is a part of the following security groups
---------------------------------------------------
    Domain Users
    Everyone
    BUILTIN\Administrators
    BUILTIN\Users
    BUILTIN\Pre-Windows 2000 Compatible Access
    NT AUTHORITY\INTERACTIVE
    CONSOLE LOGON
    NT AUTHORITY\Authenticated Users
    This Organization
    LOCAL
    Group Policy Creator Owners
    Domain Admins
    Schema Admins
    Enterprise Admins
    Authentication authority asserted identity
    Denied RODC Password Replication Group
    High Mandatory Level

C:\Users\Administrator>gpupdate /force
Updating policy…

Computer Policy update has completed successfully.
User Policy update has completed successfully.

C:\Users\Administrator>gpresult /r

Microsoft ® Windows ® Operating System Group Policy Result tool v2.0
© 2016 Microsoft Corporation. All rights reserved.

Created on 7/2/2021 at 9:18:08 AM

RSOP data for AD\Administrator on SADC01 : Logging Mode

OS Configuration: Primary Domain Controller
OS Version: 10.0.14393
Site Name: Default-First-Site-Name
Roaming Profile: N/A
Local Profile: C:\Users\Administrator
Connected over a slow link?: No

COMPUTER SETTINGS

CN=SADC01,OU=Domain Controllers,DC=ad,DC=serveracademy,DC=com
Last time Group Policy was applied: 7/2/2021 at 9:17:51 AM
Group Policy was applied from:      SADC01.ad.serveracademy.com
Group Policy slow link threshold:   500 kbps
Domain Name:                        AD
Domain Type:                        Windows 2008 or later

Applied Group Policy Objects
-----------------------------
    Default Domain Controllers Policy
    Default Domain Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
    Local Group Policy
        Filtering:  Not Applied (Empty)

The computer is a part of the following security groups
-------------------------------------------------------
    BUILTIN\Administrators
    Everyone
    BUILTIN\Users
    BUILTIN\Pre-Windows 2000 Compatible Access
    Windows Authorization Access Group
    NT AUTHORITY\NETWORK
    NT AUTHORITY\Authenticated Users
    This Organization
    SADC01$
    Domain Controllers
    NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
    Authentication authority asserted identity
    Denied RODC Password Replication Group
    System Mandatory Level

USER SETTINGS

CN=Administrator,CN=Users,DC=ad,DC=serveracademy,DC=com
Last time Group Policy was applied: 7/2/2021 at 9:17:52 AM
Group Policy was applied from:      SADC01.ad.serveracademy.com
Group Policy slow link threshold:   500 kbps
Domain Name:                        AD
Domain Type:                        Windows 2008 or later

Applied Group Policy Objects
-----------------------------
    7zip Deployment

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
    Local Group Policy
        Filtering:  Not Applied (Empty)

The user is a part of the following security groups
---------------------------------------------------
    Domain Users
    Everyone
    BUILTIN\Administrators
    BUILTIN\Users
    BUILTIN\Pre-Windows 2000 Compatible Access
    NT AUTHORITY\INTERACTIVE
    CONSOLE LOGON
    NT AUTHORITY\Authenticated Users
    This Organization
    LOCAL
    Group Policy Creator Owners
    Domain Admins
    Schema Admins
    Enterprise Admins
    Authentication authority asserted identity
    Denied RODC Password Replication Group
    High Mandatory Level

C:\Users\Administrator>

Here you can see that even the event viewer is saying that it was successful

Log Name: System
Source: Application Management Group Policy
Date: 7/2/2021 9:30:14 AM
Event ID: 301
Task Category: None
Level: Information
Keywords: Classic
User: AD\Administrator
Computer: SADC01.ad.serveracademy.com
Description:
The assignment of application 7-Zip 19.00 (x64 edition) from policy 7zip Deployment succeeded.
Event Xml:



301
4
0
0x80000000000000

1994
System
SADC01.ad.serveracademy.com



7-Zip 19.00 (x64 edition)
7zip Deployment

1 Like

Hope these shots help

1 Like

No
You made a computer policy which I know that works
I wanna make it as a user policy

1 Like

I don’t see any RSOP data - just gpresult /r data - which is good, but different.

Also, you were very good about providing troubleshooting info but you didn’t prove that it wasn’t installed. Did you check the directory where the MSI installs the app? Also - under RSOP.msc see if you can see any errors listed under Software Deployment.

Not exactly sure what you want me to check, however here are some additional snips

Here you can see that it wasn’t installed

Here is a snip of the RSOP.msc data

Here you can see that I do have access to the msi