AGPM needs to contact the root of the forest even if you are only managing GPOs in a child domain. Possible reasons include security filtering or permissions on GPOs referencing groups or users in another domain. GPOs linked to sites is another possible reason. MS was never able to tell me exactly what AGPM was looking for in the our forest root, but the issue occurred simply because our forest root was unavailable at the time. I was not aware of this. We now have a forest root DC locally.


LinkBack URL
About LinkBacks
Reply With Quote