目前,我刚刚添加到域中的一台新机器上有 2 个 GPO。第二个 GPO(stagingGPO)未显示在 gpresult /r 中。第一个(Power SettingGPO)是报告中的唯一结果。但是,当我检查 StagingGPO 的本地策略设置时,它们在新添加的 PC 上设置正确。第一个 GPO 确实设置了环回处理,我已将其重新设置为默认的“未配置”。我运行了 gpupdate /force,然后运行 gpresults,结果相同。为什么 StagingGPO 不会显示在 gpresults 的结果中?
这也是 gpresult /r /v 的输出,为什么它们与屏幕上显示的不同。
Microsoft (R) Windows (R) 操作系统组策略结果工具 v2.0 c 2016 Microsoft Corporation。保留所有权利。
创建于 2017/1/11 下午 2:12:46
WKST02 上 DOMAIN\xxxxxxxx 的 RSOP 数据:日志记录模式
操作系统配置:成员工作站操作系统版本:10.0.14393 站点名称:Default-First-Site-Name 漫游配置文件:N/A 本地配置文件:C:\Users\xxxxxxxxxxx 通过慢速链路连接?:否
电脑设置
CN=WKST02,OU=Staging,DC=xxxxx,DC=xxx
Last time Group Policy was applied: 1/11/2017 at 1:44:59 PM
Group Policy was applied from: dc2.xxxxxx.xxxxxx
Group Policy slow link threshold: 500 kbps
Domain Name: xxxxxx
Domain Type: Windows 2008 or later
Applied Group Policy Objects
-----------------------------
password
disable ipv6
root CA
Prod-StagingOU
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Local Group Policy
Filtering: Not Applied (Empty)
power settings
Filtering: Not Applied (Unknown Reason)
The computer is a part of the following security groups
-------------------------------------------------------
BUILTIN\Administrators
Everyone
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
This Organization
WKST02$
Domain Computers
Authentication authority asserted identity
System Mandatory Level
Resultant Set Of Policies for Computer
---------------------------------------
Software Installations
----------------------
N/A
Startup Scripts
---------------
N/A
Shutdown Scripts
----------------
N/A
Account Policies
----------------
GPO: password
Policy: LockoutDuration
Computer Setting: 30
GPO: password
Policy: MaximumPasswordAge
Computer Setting: 90
GPO: password
Policy: MinimumPasswordAge
Computer Setting: 1
GPO: password
Policy: ResetLockoutCount
Computer Setting: 30
GPO: password
Policy: LockoutBadCount
Computer Setting: 5
GPO: password
Policy: PasswordHistorySize
Computer Setting: 10
GPO: password
Policy: MinimumPasswordLength
Computer Setting: 8
Audit Policy
------------
N/A
User Rights
-----------
GPO: Prod-StagingOU
Policy: RemoteInteractiveLogonRight
Computer Setting: xxxxxx\ROL_RemoteDesktop_ADM
Security Options
----------------
GPO: password
Policy: PasswordComplexity
Computer Setting: Enabled
GPO: password
Policy: ClearTextPassword
Computer Setting: Not Enabled
GPO: password
Policy: ForceLogoffWhenHourExpire
Computer Setting: Not Enabled
GPO: password
Policy: RequireLogonToChangePassword
Computer Setting: Not Enabled
GPO: password
Policy: LSAAnonymousNameLookup
Computer Setting: Not Enabled
GPO: password
Policy: @wsecedit.dll,-59058
ValueName: MACHINE\System\CurrentControlSet\Control\Lsa\NoLMHash
Computer Setting: 1
N/A
Event Log Settings
------------------
N/A
Restricted Groups
-----------------
N/A
System Services
---------------
N/A
Registry Settings
-----------------
N/A
File System Settings
--------------------
N/A
Public Key Policies
-------------------
N/A
Administrative Templates
------------------------
GPO: Prod-StagingOU
Folder Id: SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall
Value: 0, 0, 0, 0
State: Enabled
GPO: Prod-StagingOU
Folder Id: SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall
Value: 0, 0, 0, 0
State: Enabled
GPO: Prod-StagingOU
Folder Id: SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\fWritableTSCCPermTab
Value: 0, 0, 0, 0
State: Enabled
GPO: root CA
Folder Id: Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots\Flags
Value: 0, 0, 0, 0
State: Enabled
GPO: disable ipv6
Folder Id: SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\DisabledComponents
Value: 255, 0, 0, 0
State: Enabled
GPO: Prod-StagingOU
Folder Id: SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\fDenyTSConnections
Value: 0, 0, 0, 0
State: Enabled
用户设置
CN=xxxxxxxxx,OU=Users,OU=Prod,DC=xxxxxx,DC=xxxxx
Last time Group Policy was applied: 1/11/2017 at 1:20:42 PM
Group Policy was applied from: dc2.xxxxxx.xxxxx
Group Policy slow link threshold: 500 kbps
Domain Name: xxxxxx
Domain Type: Windows 2008 or later
Applied Group Policy Objects
-----------------------------
power settings
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Local Group Policy
Filtering: Not Applied (Empty)
Resultant Set Of Policies for User
-----------------------------------
Software Installations
----------------------
N/A
Logon Scripts
-------------
N/A
Logoff Scripts
--------------
N/A
Public Key Policies
-------------------
N/A
Administrative Templates
------------------------
N/A
Folder Redirection
------------------
N/A
Internet Explorer Browser User Interface
----------------------------------------
N/A
Internet Explorer Connection
----------------------------
N/A
Internet Explorer URLs
----------------------
N/A
Internet Explorer Security
--------------------------
N/A
Internet Explorer Programs
--------------------------
N/A