Hello everyone.
I'm having an issue with a policy not being applied for a reason i can't understand.
Some context:
I need to create a GPO to deny/hide/disallow the use of Administrative tools from control panel, GPO that is actually already done through User config -> Pref. -> Start Menu -> General -> System administrative tools Do not display this item.
The GPO is named "admt" and is being applied under the OU where my account is, within the sec. filter there is a sec group (that i have created) called also "admt" where my account is member, and the WMI filter is set to "xp or 7 or 8 or 8.1 or 10".
I ran locally at my computer a gpupdate /force but i was still seeing the Admin tools within.
Ran a gpresult, and i saw that the "admt" policy is under "Denied GPO's" reason: Access Denied (Security Filteriing). Then i've enforced the GPO and ran another gpupdate, still nothing. Now i read somewhere that this only works if you run the gpupdate form an elevated state, so i opened the cmd as administrator and ran it again. Now i wasnt able to see admin tools.
But then i tried to uncheck the enforcement, run a gpupdate again, and suddenly i was able to see admin tools, so i thought the problem might be that aswell. Went to GPMC, enforced the GPO once again but now i cant hide admin tools, it's still under Denied GPO's.
Quite strange since my account is member of the security group where this GPO should be applying, and the first enforcement worked correctly...
Any thoughts on this?