Skip to main content

Logon Scripts in Group Policy not running

Problem 

Was having difficulty with a logon script I had created and was deploying to users via Group Policy.

The script was to customise printer settings for certain users.

But it just wasn't running when the users would logon to their PCs.

The GPO was applying properly, and I could run the script manually without issue.

Cause

It turns out that it was happening because, by default, logon scripts don't run for 5 mins after logon occurs on a Windows client PC.

Solution

This can be adjusted by setting the "Configure Logon Script Delay policy" to "Enabled" and then configuring a better delay.

Note: if this policy is set to disabled or not configured, the default delay of 5 mins will apply.

I initially set this delay to "0" but found that wasn't successful.  Perhaps the script needed a small delay.

So I set it to "1" (1 minute) and it worked nicely.

I must also note that during the troubleshooting process, I read many recommendations to enable the "Always wait for the network at computer startup and logon" policy.  I already had this policy enabled, along with the "Specify startup policy processing wait time" policy - these may also have helped the logon script run properly.



Comments

Popular posts from this blog

Resolve WSUS Server issue that gives "Cannot save configuration because the server is still processing"

This is a pretty infuriating error and can sometimes crop up as a result of running a "wsusutil reset" command. First of all, give the server some time, and then a bit more...  but you've probably already done this. These steps may help to resolve the situation: - Install Microsoft SQL Management Studio (free download) - Run SQL Management Studio and start to connect to the WSUS database - Enter this in the "Server Name" box:  \\.\pipe\MICROSOFT##WID\tsql\query - Expand the "Databases" tree - Right-click on "SUSDB" and choose "New Query" - Paste this query in:     UPDATE tbSingletonData     SET ResetStateMachineNeeded = 0 - You should see a message like "1 row affected", which is good - Quit SQL Management Studio - Open "Services" and restart the "WSUS Service" - Now, open WSUS

Re-arm ESXI Evaluation License

Needed to get a little more time out of my ESXI trial so that I could migrate it to Hyper-V. This pair of commands came in very handy and gave another 60 days: rm -f /etc/vmware/vmware.lic /etc/vmware/license.cfg reboot To use them, you need to: Put your ESXI server into Maintenance Mode Enable Secure Shell access (SSH) Enable Console Access Then ssh to the server (in Windows 11 you can just type ssh username@serveripaddress and then enter password) Otherwise, you could use something like PuTTY ( https://www.putty.org/ ) Hope this helps.  

Turn off "BitLocker waiting for activation"

This can be a pain when attempting to "sysprep" a PC's storage drive (usually the C: drive) or take an image of it using something like Acronis SnapDeploy.  In such cases, the software will complain about this BitLocker status. I keep forgetting about this every time I go to take an image! It isn't immediately obvious how to get around the issue... do you go for "Turn on BitLocker" and then turn if off when it has finished encrypting the drive?  Well you probably could if you had the time, but there's an easier way. Using the "manage-bde" tool via an administrative command line gives lots more options, and allows this to be turned off. Tip: handy way to open an admin command line is to hit  W  + R, then type "cmd" and then hit CRTL + Shift + Enter. Typing "manage-bde -status" will show you some more detail, but the command you need is: manage-bde -off c: This may take some time, depending on how much of the drive has already...