GPO not applying to Clients

active-directorygroup-policywindows 7windows-server-2008-r2

I am having issues applying the below GPOs to clients.

Computer Configuration \ Policies \ Administrative Templates \ System \ Remote assistance \ "Offer Remote Assistance"

Computer Configuration \ Policies \ Administrative Templates \ Windows Components \ Autoplay Policies \ "Turn off Autoplay"

These policies are applied against specific containers, but are not applying in both our production environment and our VMWare test lab, even with clean installs.

I have tried with the Firewall and AV disabled on both client and server, without success, and gpupdate /force has no effect either. RSOP on the client is seeing the required policy changes but they are not applying for some reason. I have also added client names to the Security Filtering of that policy and have tried logging on to client with a Domain Admin account, also without success.

At the same time, other policies like "Logon Scripts" and "Encrypting File System" apply fine.

This is from a Windows Server 2008R2 Enterprise server, to Windows 7, SP1 Enterprise clients.

Here is the link to the output of /gpresult on the client.

RSOP on the client:

enter image description here

GPMC settings:
enter image description here

Does anyone have an idea what's going wrong here?

Best Answer

What you're seeing is perfectly normal. The Local Group Policy editor is for viewing and configuring the Local group policy object and its settings, not for viewing domain based Group Policy settings.

Domain based Group Policies override Local Group Policy settings, they do not overwrite Local Group Policy settings.

RSOP is the tool for viewing settings that are being applied to the computer and user from domain based Group Policy objects.

Your RSOP results show that the domain based Group Policy settings are in fact being applied to the computer.