your deploying using a wsus server? oh well.
You are running computer policies so giving authenticated users access to the gpo wont make any difference as they are run before logon when the computer connects to the domain which is why you need domain computer permissions.
You would be better doing this direct in ADS i think, we haven't introduced a WSUS server yet tho as we couldn't justify the sever cost until we go virtualised this summer but I thought they were mainly just for windows updates more than to be used like a SMS Server as was.
to check if the policy is being deployed properly you should run 'resultant set of policies' from a group policy snap in, from mmc you need the adminpak and groupadm (think thats its name ) then you can run the report on a pc and see what policies have run which have failed and for what reason.
|