GPO wont apply to computer

group-policywindows-server-2008

I have created a GPO and linked to an OU. but somehow the computer settings wont be able to applied.

When I run gpupdate or gpupdate /force, I got 2 messages.

  1. The Group Policy Client Side Extension Folder Redirection was unable to apply one or more settings because the changes must be processed before system startup or user logon. The system will wait for Group Policy processing to finish completely before the next startup or logon for this user, and this may result in slow startup and boot performance.

  2. The processing of Group Policy failed. Windows attempted to read the file \domain.com\SysVol\domain.com\Policies{34DB7A96-8089-4EBC-B161-A1D7C0BCB2B0}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:

    a) Name Resolution/Network Connectivity to the current domain controller.

    b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller).

    c) The Distributed File System (DFS) client has been disabled.

So I tested, I can have access to {34DB7A96-8089-4EBC-B161-A1D7C0BCB2B0} from

\\dc1\sysvol\domain.com\Policies

\\dc2\sysvol\domain.com\Policies

But I can't find the same GPO by accessing share

\\domain.com\sysvol\domain.com\Policies

This issue happened on some Win2008R2 server, but other Win2012R2 servers has no such issue.

The user GPO was applied but Computer GPO wont. The GPO was applied from DC2. All the GPOs were replicated between DCs, DFS is running OK.

Any idea?

Best Answer

Need to fix fix sysvol replication with your RODC's or the client's will be unable to access the current policies.

Related Topic