Hi folks, I have been playing around with implementing and applying GPOs on a Samba AD DC, using the RSAT tools. It seems that any changes take their time (at least 5 minutes, maybe more), and are not immediately active. I experienced problems when logging in on the affected computers (Windows 10), that the GPOs seemed to be incompletely applied. After a while, it worked though. It's not a critical problem, and you could live with it. However, it is necessary to take this into account. If somebody has got any information, I would be grateful. Best regards, Peter CentOS 7.6 (1810), Samba 4.9.1
Hai Peter, Small enlightment on this. Normal GPO update interval is 30 min, so what you see is normal to me. Also, for some policies, you need to reboot the computer twice. First time is to add the policy, second to apply the policy, this is depending on the use policy, by design of MS. For testing you should increase the update frequenty, but i dont recommmend that. Use the defaults as as possible, what works fine, at least for me. Greetz, Louis> -----Oorspronkelijk bericht----- > Van: samba [mailto:samba-bounces at lists.samba.org] Namens > Peter Milesson via samba > Verzonden: maandag 8 april 2019 8:35 > Aan: samba at lists.samba.org > Onderwerp: [Samba] Newly applied GPO not immediately active > > Hi folks, > > I have been playing around with implementing and applying GPOs on a > Samba AD DC, using the RSAT tools. It seems that any changes take their > time (at least 5 minutes, maybe more), and are not immediately active. I > experienced problems when logging in on the affected computers (Windows > 10), that the GPOs seemed to be incompletely applied. After a while, it > worked though. It's not a critical problem, and you could live with it. > However, it is necessary to take this into account. > > If somebody has got any information, I would be grateful. > > Best regards, > > Peter > > CentOS 7.6 (1810), Samba 4.9.1 > > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba > >
Hi Louis, Thanks for the explanation. That's completely in line with my experiences. Windows server AD DC displays similar behavior. I wish you a nice day. Peter On 08.04.2019 10:48, L.P.H. van Belle via samba wrote:> > Hai Peter, > > Small enlightment on this. > > Normal GPO update interval is 30 min, so what you see is normal to me. > Also, for some policies, you need to reboot the computer twice. > First time is to add the policy, second to apply the policy, this is > depending on the use policy, by design of MS. > > For testing you should increase the update frequenty, but i dont recommmend that. > Use the defaults as as possible, what works fine, at least for me. > > Greetz, > > Louis > > > >> -----Oorspronkelijk bericht----- >> Van: samba [mailto:samba-bounces at lists.samba.org] Namens >> Peter Milesson via samba >> Verzonden: maandag 8 april 2019 8:35 >> Aan: samba at lists.samba.org >> Onderwerp: [Samba] Newly applied GPO not immediately active >> >> Hi folks, >> >> I have been playing around with implementing and applying GPOs on a >> Samba AD DC, using the RSAT tools. It seems that any changes take their >> time (at least 5 minutes, maybe more), and are not immediately active. I >> experienced problems when logging in on the affected computers (Windows >> 10), that the GPOs seemed to be incompletely applied. After a while, it >> worked though. It's not a critical problem, and you could live with it. >> However, it is necessary to take this into account. >> >> If somebody has got any information, I would be grateful. >> >> Best regards, >> >> Peter >> >> CentOS 7.6 (1810), Samba 4.9.1 >> >> >> -- >> To unsubscribe from this list go to the following URL and read the >> instructions: https://lists.samba.org/mailman/options/samba >> >> > >