Cross-forest GPO between 2003 and 2008 Denied Beacuse it's "Inaccessible"
- by j.rightly
I have a two-way, non-transitive trust between two forests and domains, "W2003" and "W2008".
In W2008 I have a GPO with user settings linked to a machine OU containing machine "Server". The GPO applies to Authenticated Users.
Cross-forest loopback processing is enabled in merge mode.
When I log onto Server as User (whose account exists in the W2003 domain), the GPO does not apply.
I run RSoP and see that the GPO is "Denied" for the reason "Inaccessible." The GPO name is not listed, but the GUID is.
I have checked the file-level permissions on the DC to ensure that User has access to read the GPO's folder and all its contents.
What is going on?