09/30/2009 3482 views
Our servers and AD world are all Windows 2003. Our workstations are all XP SP3.

On a 2003 Server I open up the Group Policy Management tool. Inside of that I open up the Group Policy Objects. I create a new GPO that is a Machine policy. This policy will copy down 1 file. I set the file copy here: Under Computer Configuration\Preferences\Windows Settings I click on FILE and then "new file" Here are the properties of my new file:

Action: Replace
Source files: \\server\share\folder\MyFile
Destination file: c:\program files\MyApp\MyFile (note: here I do specify the file name. The online help says you need too but I have tried it without the file name and get the same results)

I save this. Then, I navigate to my COMPUTERS container and then I right click and pick "Link an existing GPO" My policy is there and "Link Enabled" is setup by default. I double click on this new linked GPO and here are the properties that get set.

Under the DETAILS tab: User Configuration Settings Disabled
Under the SCOPE tab: I target 1 machine under the Security Filtering.

I then log into this target machine and the file never gets copied. On this XP workstation I have run the following:

I have run GPUATE /Force and then rebooted

The file never gets copied.

I ran GPRESULT /v > c:\gp.txt

In this .txt file I see no trace of my GPO.

I have waited 10 min and then re-run all of the GPUDATE commands and even rebooted again and the file still does not copy.

I am missing something but not sure where to look. Any hints would be great. Thank you.
0 Comments   [ + ] Show comments


Rating comments in this legacy AppDeploy message board thread won't reorder them,
so that the conversation will remain readable.

All Answers

I can't think of a single GP-using client I've worked for where that technique has been used to copy files. Why not use an MSI to install or, more simply, execute a script? Either way, you could have the activity logged and, with MSI, a built-in uninstall capability.

Assuming that your method would actually work, have you run the GP Modelling Wizard against the computername to see if the policy would get applied?

BTW, there is a specific 'Group Policy' forum here at AppDeploy. A moderator may well move this thread to it.
Answered 10/01/2009 by: VBScab
Red Belt

If the GPO is not listed in the gp.txt file that got generated then it sounds like the machine is not in the scope of the policy. Was the policy listed in the " The following GPOs were not applied because they were filtered out" section ? Are there any deny ACL's or WMI filters on the GPO that could possibly cause the policy to fall out of scope ? Are other policy changes being applied to the machine ... maybe it's just failing to process any policy changes ?

I think VBScab's idea of running the Group Policy modelling wizard might also throw some light on this

Hope this is of some help
Answered 12/14/2009 by: y2k
Senior Yellow Belt