Sign in
|
Join
|
Help
in
James Thompson at myITforum...
myITforum User Blogs
(Entire Site)
myITforum.com
Site Home
Home
Bloggers List
Blogs
Photos
Downloads
This Blog
Home
Contact
Syndication
RSS
Atom
Comments RSS
Recent Posts
Secondary Install Failure KB
Treo 700w on Sprint
Vista CTP on VMWare
Systems Mangement Server
Sprint to get Razr Like Phone?
Tags
Active Directory
Anti-Virus
Hardware
Humor
Linux
Microsoft
Microsoft Office
Much Ado About Nothing
Security
Systems Management
Tools
Windows
James Thompson at myITforum.com Blogging...it's whats for dinner
News
Yours Truly. I look normal, right?
</div <script type="text/javascript"><!-- google_ad_client = "pub-7129151953752155"; google_ad_width = 120; google_ad_height = 600; google_ad_format = "120x600_as"; google_ad_type = "text_image"; google_ad_channel =""; google_page_url = document.location; google_color_border = "000000"; google_color_bg = "F0F0F0"; google_color_link = "0000FF"; google_color_url = "008000"; google_color_text = "000000"; //--></script> <script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"> </script>
Extra Curricular Stuff
Chamber of Commerce--Technical Chairman
Sites I Visit
myITforum
The Network Administrator
Archives
April 2006
(1)
March 2006
(2)
February 2006
(1)
November 2005
(3)
August 2005
(12)
June 2005
(1)
March 2005
(6)
February 2005
(9)
January 2005
(5)
December 2004
(4)
James Thompson at myITforum.com
Blogging...it's whats for dinner
XP and delayed GP
Read this on Rod Trent's blog courtesy of Bruce Vangrouw: I recently ran into an issue with Windows XP and group policy. I am not sure if you have noticed but after installing Windows XP, group policy based software distribution does not always occur with the first or second reboot. In addition, even though you may not have noticed, other group policies are not applied. I realized this while trying to configure the Windows Firewall group policy settings. In group policy, there are two sets of identical policies for the firewall: Domain Profile and Standard Profile. As the names imply, while connected to the domain, the Domain Profile policies apply and while disconnected the Standard Profile policies apply. The computer determines if it connected to the domain by checking whether its current domain matches the domain name in the “HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Group Policy\History\NetworkName” registry setting. This setting is populated the last time the group policies were successfully applied (a good Cable Guy article explains this in detail.) To tie this all together, because of the issue mentioned in the beginning of the article, group policies are not successfully applied until the second or third reboot. It is hit or miss. In our case, we needed all group policy settings to be applied the first time the computer was rebooted after the image was applied. In searching through policies, I ran across the following setting: “Always wait for the network for computer startup and logon. It is located under “Computer Configuration\Administrative Templates\System\Logon”. The explanation of the policy reads, “Determines whether Windows XP waits for the network during computer startup and user logon. By default, Windows XP does not wait for the network to be fully initialized at startup and logon. Existing users are logged on using cached credentials, which results in shorter logon times. Group Policy is applied in the background once the network becomes available. Note that because this is a background refresh, extensions such as Software Installation and Folder Redirection take two logons to apply changes. To be able to operate safely, these extensions require that no users be logged on. Therefore, they must be processed in the foreground before users are actively using the computer. In addition, changes that are made to the user object, such as adding a roaming profile path, home directory, or user object logon script, may take up to two logons to be detected. If a user with a roaming profile, home directory, or user object logon script logs on to a computer, Windows XP always waits for the network to be initialized before logging the user on. If a user has never logged on to this computer before, Windows XP always waits for the network to be initialized. If you enable this setting, logons are performed in the same way as for Windows 2000 clients, in that Windows XP waits for the network to be fully initialized before users are logged on. Group Policy is applied in the foreground, synchronously. If you disable or do not configure this setting, Windows does not wait for the network to be fully initialized and users are logged on with cached credentials. Group Policy is applied asynchronously in the background. Note: If you want to guarantee the application of Folder Redirection, Software Installation, or roaming user profile settings in just one logon, enable this setting to ensure that Windows waits for the network to be available before applying policy. Note: For servers, the startup and logon processing always behaves as if this policy setting is enable
Published
Mar 22 2005, 07:59 AM
by
jthompson
Filed under:
Windows
,
Microsoft
,
Active Directory
Comments
TrackBack
said:
XP and delayed GPooeess
May 31, 2005 12:04 PM
Copyright - www.myITforum.com, Inc. - 2007 All Rights reserved.