GPOS do not apply locally through MMC.

Marcelo Fares 21 Reputation points
2021-02-22T12:12:56.283+00:00

Hello everybody.
I'm from Brazil and my English is not very good.
I have a problem on a specific computer that uses local GPOS in the user profile without administrative powers.

Basically, I used mmc.exe to add a snap-in for local group policies, linked to users without administrative powers because, I want to block access to the various functions within WINDOWS 10. Having done that, I always copied the files located within System32 as pictured below, in order to replicate the same policies and settings for all other computers. Unfortunately this company is small and does not have any domain controller. Until then, everything was ok because on other computers, the policies (copy and paste) were applied and accepted, however, on only one computer there is no way to do the same to apply the defined policies completely.

70681-1052175857-capturadetela2021-02-10as13-23-11png26c.png

I'll give you an example:
I created restrictions on access to the control panel;
Start menu run;
Access to the CMD prompt, and others.

Many of these policies that I created to block user access, do not work only on this specific computer, and all others apply. It is as if the GPOs were applied by part and not completely because many functions that I defined as blocked are respected, but others are not and it ends up being released for this specific computer. The only way that I managed to apply the restrictions to these rules above, was through GPEDIT.MSC
I ask, do you have any tips or methods to avoid or solve this problem?
I even created a new user on this computer and even then, the problem continues. I even corrected errors with chkdsk, sfc / scannow and used the dism, but nothing solved it.
Does anyone have any light for this?

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,723 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Fan Fan 15,291 Reputation points Microsoft Vendor
    2021-02-23T01:23:55.427+00:00

    Hi,

    I would recommend you check if there are any computer configuration on this PC.
    You can check that by the gpresult command: gpresult /h report.html.
    If no other configuration , you can check more details for the GPOs on the specific computer through the GPSVC.log, for more information ,you can refer to:
    https://blogs.technet.microsoft.com/askds/2015/04/17/a-treatise-on-group-policy-troubleshootingnow-with-gpsvc-log-analysis/

    Best Regards,


  2. Marcelo Fares 21 Reputation points
    2021-03-11T21:24:08.123+00:00

    I noticed that, when I applied the policies through GPEDIT.MSC while logging in as ADMINISTRATOR, the policies were not validated for my user without administrative rights but for the administrator's profile, that is, it seems inconsistent / crazy

    0 comments No comments