Windows 10: Who broke my user GPOs?

Discus and support Who broke my user GPOs? in Windows 10 News to solve the problem; Hi folks. From Orlando, Florida, Sean Greenbaum here with some news about a recent set of security patches released on June 14, 2016. If you’re reading... Discussion in 'Windows 10 News' started by Brink, Jul 5, 2016.

  1. Brink
    Brink New Member

    Who broke my user GPOs?


    That’s it! You’ve just added the “Domain Computers” group for the current domain to have GPORead permissions on all your GPOs currently in the domain. If you have other domains and are cross linking GPOs to the other domains, don’t forget to add the “Domain Computers” groups for those domains as well.

    Option 2: I want to be more detailed than that. Can I get a list of all the GPOs that need my attention?

    Of course. In fact, our product group published this very fine script here. This script searches for GPOs that are missing the “Authenticated Users” permissions, and prompts you to automatically fix them. Looking at the code, you could easily adjust this to use “Domain Computers” or whatever group you find appropriate in your environment.

    Option 3: I prefer the personal touch with my policies

    That’s the same way I prefer my fresh home baked cookies. No machinery or automation here. Start from the Delegation tab of the policy. Click Add, find the group, and make sure the permissions are Read. Easy. Now do that for each user policy.


    Who broke my user GPOs? [​IMG]


    Option 4: AGPM! Wait, I have AGPM!

    AGPM (Advanced Group Policy Management)

    If you already use AGPM to manage your policies, you can use the Production Delegation tab in AGPM to update the security on any GPOs you deploy going forward. See the AGPM section below for details.

    Ok I fixed it, so I’m done right?

    Temporarily. Our group policy tools GPMC and AGPM will continue to create GPOs using the default permissions I showed at the beginning of this article. As you create new user GPOs, and you scope them to specific user groups, you’ll need to continue to remember to add the appropriate groups to those GPOs before it can be processed.

    If you are using a 3rd party tool to create and manage your GPOs, you’ll want to reach out to that vendor to see how their product is affected and if any change is needed to your policy creation and deploy process.

    Remember: If you didn’t use “Authenticated Users” and you add additional domains to your forest, and if you are cross-linking GPOs between domains in your forest (the GPO exists in Domain1 and is linked to OUs in Domain2), be sure to remember you will need to grant the new domains “Domain Computers” or your custom group to the policy before it will have access in the new domain.

    Do you use Deny:Read permissions on some of your GPOs? Read this.

    When you grant the computer the ability to Read the GPOs, if your user account is in a group that grants apply rights, and in a group that denies read rights, previous to MS16-072 the user would not get the policy. Since the Read is now done by the computer context, there is a possibility that the user will now get the GPO when that is not your intention.

    To fix this, update the permissions on any GPO where you are doing Deny:Read to also include Deny:Apply.


    Who broke my user GPOs? [​IMG]


    Using AGPM? Look here for some important information

    Once you’ve installed the patches for MS16-072, if you are using AGPM you’ll want to make some changes here as well.

    First, very important, make sure you reimport your GPOs into the AGPM database. Trust me, do this. We’ve already received reports from customers that did NOT do this step, and it caused some serious problems when they went to deploy later. This makes sure we have the latest copy of the production GPOs. Do it. Right now. I’ll wait.


    Who broke my user GPOs? [​IMG]


    All reimported? Good.

    Now that you’ve reimported your GPOs in AGPM, lets configure AGPM so that it knows of the new permissions and deploys the correct security settings going forward.

    From the AGPM module, select the Production Delegation tab. We need to grant “Domain Computers” Read permissions.


    Who broke my user GPOs? [​IMG]


    Only grant Read permissions.


    Who broke my user GPOs? [​IMG]


    Confirm the settings.


    Who broke my user GPOs? [​IMG]


    Now that the delegation settings are correct, redeploy your GPOs. This will make sure the permissions apply. Select all the GPOs you need, right click and Deploy.


    Who broke my user GPOs? [​IMG]


    Boom. Victory! We see that “Domain Computers” is here, “User Group 1” is the group that is scoped to apply these settings, and “User Group 2” is the group we specifically Denied Read and Apply permissions earlier.


    Who broke my user GPOs? [​IMG]


    One more thing


    We also released MS16-075 / KB 3161561 in June 2016 to patch some SMB items. SYSVOL and Netlogon use SMB. There have been reports of users getting Access Denied when trying to access \\domain.fqdn\sysvol or \\domain\sysvol.

    If you are experiencing this error, the current workaround is to set the SmbServerNameHardeningLevel registry value to 0 on the DCs. It is not needed on the other servers. If you experience this issue on other DFS servers, see the KB for the updated workaround info for those servers. Specifics are detailed in the KB 3161561 article.

    More Info

    Our Directory Services team has also published information about this update on their blog. If you have any questions, be sure to check there too.

    Until next time,

    Sean Greenbaum

    Premier Field Engineer, Secure Infrastructure

    [/quote]
    Source: Who broke my user GPOs? | Ask Premier Field Engineering (PFE) Platforms

    :)
     
    Brink, Jul 5, 2016
    #1

  2. Synaptics touchpad settings goes to default in reboot/shut down

    This process did return the touchpad on my computer to pre-Win10 upgrade. Thank you.

    The point is that the upgrade broke it in the first place. Very few users who experience this issue or problem will be fortunate enough to stumble upon this fix. MS should release a fix or patch so to remedy the issue for the many who won't find a fix.
     
    NewUser21233992, Jul 5, 2016
    #2
  3. Google Maps voice search broken on s60v3

    Getting same error on my N82 mobile - who broke it??? My guess is Google did.
     
    kircheis---01, Jul 5, 2016
    #3
Thema:

Who broke my user GPOs?

Loading...
  1. Who broke my user GPOs? - Similar Threads - broke user GPOs

  2. 24h2 update broke my user profile?

    in Windows 10 Gaming
    24h2 update broke my user profile?: Whilst playing a game windows must have tried to update because I noticed my Windows C: Drive being around 5gb heavier once I exited the game. I ruled it being caused by the game since it is installed on my D: Drive Whilst in Settings, looking around for Windows Security To...
  3. 24h2 update broke my user profile?

    in Windows 10 Software and Apps
    24h2 update broke my user profile?: Whilst playing a game windows must have tried to update because I noticed my Windows C: Drive being around 5gb heavier once I exited the game. I ruled it being caused by the game since it is installed on my D: Drive Whilst in Settings, looking around for Windows Security To...
  4. Deleted my user inside of C:\Users\ and everything in my PC basically broke.

    in Windows 10 Gaming
    Deleted my user inside of C:\Users\ and everything in my PC basically broke.: So, I was trying to move my files from one user profile to another one, I had copied all files inside the original user profile and already made the new one and when it was deleted, I put the files in new one but it didn't let me, I closed out of file explorer and my...
  5. Deleted my user inside of C:\Users\ and everything in my PC basically broke.

    in Windows 10 Software and Apps
    Deleted my user inside of C:\Users\ and everything in my PC basically broke.: So, I was trying to move my files from one user profile to another one, I had copied all files inside the original user profile and already made the new one and when it was deleted, I put the files in new one but it didn't let me, I closed out of file explorer and my...
  6. Deleted my user inside of C:\Users\ and everything in my PC basically broke.

    in Windows 10 Installation and Upgrade
    Deleted my user inside of C:\Users\ and everything in my PC basically broke.: So, I was trying to move my files from one user profile to another one, I had copied all files inside the original user profile and already made the new one and when it was deleted, I put the files in new one but it didn't let me, I closed out of file explorer and my...
  7. ChatGPT Broke my User Account

    in Windows 10 Gaming
    ChatGPT Broke my User Account: Yeah, I'm not even lying. Last night, I asked my brother to find a way to automatically log in into my account so Chrome Remote Desktop can work. He did, sort of, he asked ChatGPT to find code to automatically log in. If you're curious, here's the code, but PLEASE, DO NOT RUN...
  8. ChatGPT Broke my User Account

    in Windows 10 Software and Apps
    ChatGPT Broke my User Account: Yeah, I'm not even lying. Last night, I asked my brother to find a way to automatically log in into my account so Chrome Remote Desktop can work. He did, sort of, he asked ChatGPT to find code to automatically log in. If you're curious, here's the code, but PLEASE, DO NOT RUN...
  9. GPOs to Disable Account Settings are not working

    in User Accounts and Family Safety
    GPOs to Disable Account Settings are not working: Hello, I need to disable the below settings. I have tried using the below GPO settings, ran gpupdate /force and restarted 2 domain computers. I then logged into each computer with a different domain account. The live tiles were still changing. I am still able to add a PIN...
  10. change who is the primary user of the computer

    in Windows 10 Support
    change who is the primary user of the computer: when you have 2+ users on the computer, it seems to boot the computer with either the oldest account, or (i assume this is the correct one) the highest level account (local admin > admin > standard) so if you're like me and have 2 account, an admin and a standard user, it'll...