[Samba] GPO Filtering Denied

durwin at mgtsciences.com durwin at mgtsciences.com
Fri Apr 19 14:00:32 UTC 2019


I followed Part 1, Part 3, and Part 4 at this url

https://www.tecmint.com/install-samba4-active-directory-ubuntu/

Domain Controller is Fedora 29 with samba-dc-4.9.6-0 installed, the other 
Windows 10 Pro version 1809 with RSAT installed.

The Domain Controller is named dcprimary.  I am connected to the domain 
from the Windows named wks2.

In part 4 it steps through configuring a logon banner.  I do this and 
force an update.  The output from the command 'gpresult /z' is below.

I did find this url in the archives, but found no answer.  I found many 
others, also no resolution.  It seems I have addressed everything yet I 
get Filtering denied.

https://lists.samba.org/archive/samba/2018-August/217667.html

I wanted to include the export of 'Logon Banner' report (from Part 4), but 
it made the email too large in size.


=== gpresult ===

Microsoft (R) Windows (R) Operating System Group Policy Result tool v2.0
c 2018 Microsoft Corporation. All rights reserved.

Created on ?4/?18/?2019 at 2:31:29 PM



---------------------------------------------------------------

OS Configuration:            Member Workstation
OS Version:                  10.0.17763
Site Name:                   Default-First-Site-Name
Roaming Profile:             N/A
Local Profile:               C:\Users\Administrator
Connected over a slow link?: No


COMPUTER SETTINGS
------------------
    CN=WKS2,CN=Computers,DC=mydomain,DC=com
    Last time Group Policy was applied: 4/18/2019 at 2:03:08 PM
    Group Policy was applied from:      dcprimary.mydomain.com
    Group Policy slow link threshold:   500 kbps
    Domain Name:                        MYDOMAIN
    Domain Type:                        Windows 2008 or later

    Applied Group Policy Objects
    -----------------------------
        N/A

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Logon Banner
            Filtering:  Denied (Security)

        Local Group Policy
            Filtering:  Not Applied (Empty)

        Default Domain Policy
            Filtering:  Denied (Security)

    The computer is a part of the following security groups
    -------------------------------------------------------
        NULL SID
        NT AUTHORITY\NETWORK
        This Organization
        Untrusted Mandatory Level
 

USER SETTINGS
--------------
    CN=Administrator,CN=Users,DC=mydomain,DC=com
    Last time Group Policy was applied: 4/18/2019 at 2:03:09 PM
    Group Policy was applied from:      dcprimary.mydomain.com
    Group Policy slow link threshold:   500 kbps
    Domain Name:                        MYDOMAIN
    Domain Type:                        Windows 2008 or later
 
    Applied Group Policy Objects
    -----------------------------
        N/A

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Local Group Policy
            Filtering:  Not Applied (Empty)

        Default Domain Policy
            Filtering:  Not Applied (Empty)

    The user is a part of the following security groups
    ---------------------------------------------------
        Domain Users
        Everyone
        BUILTIN\Users
        BUILTIN\Administrators
        REMOTE INTERACTIVE LOGON
        NT AUTHORITY\INTERACTIVE
        NT AUTHORITY\Authenticated Users
        This Organization
        LOCAL
        Domain Admins
        Denied RODC Password Replication Group
        Schema Admins
        Enterprise Admins
        Group Policy Creator Owners
        High Mandatory Level
 


More information about the samba mailing list