VNX/Unity follows standard ldap queries and apply the GPOs that it has access to.
1) Queries LDAP for CIFS Servers OU
2) Queries for all policies listed under that OU using "cifs server" account
3) Above should list only what is permitted and gets applied as per GPO link order
In customer case, cifs200_only_gpo is returned for other cifs server's query as well, which is why it got applied.
Customer recently patched the domain controller and that impacted how GPOs applied on (specifically Microsoft) Servers
This is documented in Microsoft
KB 3159398 :
MS16-072 changes the security context with which user group policies are retrieved. This by-design behavior change protects customers computers from a security vulnerability. Before MS16-072 is installed, user group policies were retrieved by using the user s security context. After MS16-072 is installed, user group policies are retrieved by using the computer's security context
The KB suggested following workaround:
To resolve this issue, use the Group Policy Management Console (GPMC.MSC) and follow one of the following steps:
- Add the Authenticated Users group with Read Permissions on the Group Policy Object (GPO).
- If you are using security filtering, add the Domain Computers group with read permission.
In customer case, he added "Authenticated Users" group under GPO's delegation (below is from a lab example):