GPO with MPS

Last post 11-04-2009 10:28 AM by nrico77. 4 replies.

Sort Posts:

  • GPO with MPS

    03-16-2006, 5:43 AM
    • Member
      5 point Member
    • Gmeul
    • Member since 03-16-2006, 10:03 AM
    • Posts 1

    We have created a group policy  in AD on an OU outside the OU=Hosting managed by MPS.

    That OU on which the GPO is applied groups computer (server) objects. In the GPO we use Loopback processing in 'replace mode' to apply user settings when a user does a logon to that server

    Our problem is  that the GPO user settings are not applied for users located under the OU=Hosting managed by MPS. For users outside the OU=Hosting the GPO is applied correctly.

    In the eventlog of the server we have the following error:

    Source: Userenv

    Event id:1101

    Windows cannot access the the object OU=Hosting,DC=exo,DC=net in Active Directory. The access to the object may be denied. Group Policy processing aborted.

    All ideas are welcome

     

     

     

     

     

     

  • Re: GPO with MPS

    03-21-2006, 1:48 AM
    • Participant
      1,134 point Participant
    • mkostersitz
    • Member since 04-13-2004, 1:18 PM
    • somewhere in Europe (mostly in Austria)
    • Posts 248
    • Moderator
    This happens because the user does not get access to the CN=System Container in the root of the domain in AD you will have to selectively grant read access to the Group Policy Container underneath CN=System to the AllUsers Group from that customer so that they can access the actual GPO Object as well grant them more then the list object access on the Hosting Org they get today. The Problem with this si that then the users in that OU will be able to discover other objects under Hosting and the System Container they should not have access to. Doing this will break the isolation we build when creating the OUs.

    You will have to carefully determine the changes needed or find another way to get the GPO onto the user.

    HTH

    Mike
    Mike Kostersitz
    Microsoft Customer Support Services

    This posting is provided "AS IS" with no warranties, and confers no rights. Script samples are subject to the terms at http://www.microsoft.com/info/cpyright.htm"
  • Re: GPO with MPS

    03-31-2006, 1:33 PM
    • Member
      10 point Member
    • JohanW
    • Member since 03-03-2006, 7:19 AM
    • Posts 2

    Is there any easy way to work around this, I have the same problem to solve. One idea I had was to grant the "read access to the Group Policy Container underneath CN=System" to selected customers. The question is how much and what access do they need to the hosting org? Would one way be to put one customer into uniuqe reseller OUs and grant them more rights within that reseller OU?

    //Johan

  • Re: GPO with MPS

    10-30-2007, 4:22 AM
    • Member
      7 point Member
    • petjez
    • Member since 09-09-2007, 2:41 PM
    • Apeldoorn, Netherlands
    • Posts 13

    Hi,

    are there other ways to apply the GPO to the users under the Hosting container? We've got the same situation here. We like to set some policies on the users beneath the hosting container!

    Please advice,

    Thanks in advance, Patrick

  • Re: GPO with MPS

    11-04-2009, 10:28 AM
    • Member
      2 point Member
    • nrico77
    • Member since 11-04-2009, 10:21 AM
    • Posts 1

    Hi,

     

    we just fixed this annoying problem; you need to set the following permissions on your Hosting and reseller OU's (customer OU's inherit them from the reseller OU):

    • Authenticated users

    Read cn

    Read distinguisedName

    Read GPLink

    Read GPOptions

    I set the scope to 'This object only'.

     

    The Userenv errors are now gone and GPO usersettings are applied succesfully.

     

    I hope this helps!

     

    Regards,

    Enrico Klein

    ApplicationNet B.V.

    Netherlands

Page 1 of 1 (5 items)