Cross-forest GPO between 2003 and 2008 Denied Beacuse it's "Inaccessible"
Posted
by
j.rightly
on Server Fault
See other posts from Server Fault
or by j.rightly
Published on 2011-06-29T15:41:51Z
Indexed on
2011/06/29
16:24 UTC
Read the original article
Hit count: 316
I have a two-way, non-transitive trust between two forests and domains, "W2003" and "W2008".
In W2008 I have a GPO with user settings linked to a machine OU containing machine "Server". The GPO applies to Authenticated Users.
Cross-forest loopback processing is enabled in merge mode.
When I log onto Server as User (whose account exists in the W2003 domain), the GPO does not apply.
I run RSoP and see that the GPO is "Denied" for the reason "Inaccessible." The GPO name is not listed, but the GUID is.
I have checked the file-level permissions on the DC to ensure that User has access to read the GPO's folder and all its contents.
What is going on?
© Server Fault or respective owner