question

JL-1199 avatar image
0 Votes"
JL-1199 asked DonPickard-7259 answered

The winning GPO is shown as "[Default Settings]"

I have a GPO to enable the PKI certificate autoenrollment for both computers and users.
After I have the GPO applied, most computers are working fine. However some computer won't auto enroll the cert.
So I used gpresult to generate the report. Under the computer section, the auto enrollment GPO did show among the list of applied GPO. However when check the PKI setting node, the winning GPO is shown as [Default Settings] and the value is not matching with GPO.
I tried gpupdate /force and also reboot the computer but symptom is the same.

Any suggestions?

windows-group-policy
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LimitlessTechnology-2700 avatar image
0 Votes"
LimitlessTechnology-2700 answered JL-1199 commented

Hello @JL-1199

This is the same behavior described in: https://social.technet.microsoft.com/Forums/en-US/f002c93f-c52d-4dba-917a-c66ea52827ee/default-setting-as-winning-gpo?forum=winserverGP

Could you try the steps included?

Hope this helps,
Best regards,

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

I read that post before posting question here. It is different to my situation. In my case, I have ruled out this is the leftover from a previous applied GPO. The PKI enrollment GPO is controlling this setting and the GPO does show among the "Applied GPOs" list in the gpresult report. However when checking the settings in the report, the winning GPO simply showing as [Default Settings]

0 Votes 0 ·
DonPickard-7259 avatar image
0 Votes"
DonPickard-7259 answered

in my experience it IS an artefact from previously applied GPOs.
you can delete the file C:\Windows\System32\GroupPolicy\Machine\Registry.pol
and then reboot the pc, this will rebuild the Machine policy.

see if that resolves for you

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.