PC Review


Reply
Thread Tools Rate Thread

Assiging Group Policy to 1 GROPUP

 
 
=?Utf-8?B?RHdheW5lIFI=?=
Guest
Posts: n/a
 
      22nd Jul 2005
Im trying to install a group policy (or use poledit) to lock down settings
for users using Terminal Server within Windows 2000. When i modify the policy
it applies to the Administrators group which i do not want it to do.

I have Win2000 Server in a domain non-active directory. Im trying to assign
this policy to users from the doman that will be accessing the Terminal
Server on this system.

Thnaks in advance.
 
Reply With Quote
 
 
 
 
Bruce Sanderson
Guest
Posts: n/a
 
      22nd Jul 2005
I'm a bit confused; Group Policies, by definition require an Active
Directory (Windows 2000 or 2003) domain. So what does "a domain non-active
directory" mean?

See if any of these articles helps:
http://support.microsoft.com/kb/192794/ - about policies for TS in NT 4
domain
http://support.microsoft.com/?kbid=260370 - about Group Policies for TS in
AD domain (see in particular "Method 2")

--
Bruce Sanderson MVP Printing
http://members.shaw.ca/bsanders

It is perfectly useless to know the right answer to the wrong question.



"Dwayne R" <(E-Mail Removed)> wrote in message
news:E032185A-A071-4B11-A1A4-(E-Mail Removed)...
> Im trying to install a group policy (or use poledit) to lock down settings
> for users using Terminal Server within Windows 2000. When i modify the
> policy
> it applies to the Administrators group which i do not want it to do.
>
> I have Win2000 Server in a domain non-active directory. Im trying to
> assign
> this policy to users from the doman that will be accessing the Terminal
> Server on this system.
>
> Thnaks in advance.



 
Reply With Quote
 
=?Utf-8?B?RHdheW5lIFI=?=
Guest
Posts: n/a
 
      22nd Jul 2005
This is a server in a domain config but its not in a active directory model.
Basicly what im trying to do is assign users from the domain to a group on
this server and lock that 1 group down (disable run, shutdown etc) when they
user Terminal Services.

Is this possible ?

"Bruce Sanderson" wrote:

> I'm a bit confused; Group Policies, by definition require an Active
> Directory (Windows 2000 or 2003) domain. So what does "a domain non-active
> directory" mean?
>
> See if any of these articles helps:
> http://support.microsoft.com/kb/192794/ - about policies for TS in NT 4
> domain
> http://support.microsoft.com/?kbid=260370 - about Group Policies for TS in
> AD domain (see in particular "Method 2")
>
> --
> Bruce Sanderson MVP Printing
> http://members.shaw.ca/bsanders
>
> It is perfectly useless to know the right answer to the wrong question.
>
>
>
> "Dwayne R" <(E-Mail Removed)> wrote in message
> news:E032185A-A071-4B11-A1A4-(E-Mail Removed)...
> > Im trying to install a group policy (or use poledit) to lock down settings
> > for users using Terminal Server within Windows 2000. When i modify the
> > policy
> > it applies to the Administrators group which i do not want it to do.
> >
> > I have Win2000 Server in a domain non-active directory. Im trying to
> > assign
> > this policy to users from the doman that will be accessing the Terminal
> > Server on this system.
> >
> > Thnaks in advance.

>
>
>

 
Reply With Quote
 
lforbes
Guest
Posts: n/a
 
      23rd Jul 2005
>This is a server in a domain config but its not in a active directory
>model.


Hi,

You can’t have a "Domain config" without Active Directory installed
unless
You are running NT 4 and the server you refer to is just a Windows
2000 Member Server in the domain (like a workstation). In the case of
NT 4.0 domain you would need to use poledit.

If you are running a Windows 2000 Domain then you have an Active
Directory Model because AD is the essence of the Domain. In this case
you can use Group Policies and put the Domain Users in an OU and apply
the Group Policy to it. (GP’s don’t apply to groups)

Cheers,

Lara

--
Posted using the http://www.windowsforumz.com interface, at author's request
Articles individually checked for conformance to usenet standards
Topic URL: http://www.windowsforumz.com/Group-P...ict399313.html
Visit Topic URL to contact author (reg. req'd). Report abuse: http://www.windowsforumz.com/eform.php?p=1319368
 
Reply With Quote
 
=?Utf-8?B?RHdheW5lIFI=?=
Guest
Posts: n/a
 
      23rd Jul 2005
ok thats where i was confused... so when using GPO i set the policy i want to
excude the Administrators group from inheriting the policy. does anyone know
how to do this ?

"lforbes" wrote:

> >This is a server in a domain config but its not in a active directory
> >model.

>
> Hi,
>
> You can’t have a "Domain config" without Active Directory installed
> unless
> You are running NT 4 and the server you refer to is just a Windows
> 2000 Member Server in the domain (like a workstation). In the case of
> NT 4.0 domain you would need to use poledit.
>
> If you are running a Windows 2000 Domain then you have an Active
> Directory Model because AD is the essence of the Domain. In this case
> you can use Group Policies and put the Domain Users in an OU and apply
> the Group Policy to it. (GP’s don’t apply to groups)
>
> Cheers,
>
> Lara
>
> --
> Posted using the http://www.windowsforumz.com interface, at author's request
> Articles individually checked for conformance to usenet standards
> Topic URL: http://www.windowsforumz.com/Group-P...ict399313.html
> Visit Topic URL to contact author (reg. req'd). Report abuse: http://www.windowsforumz.com/eform.php?p=1319368
>

 
Reply With Quote
 
Member
Join Date: Jun 2005
Posts: 88
 
      23rd Jul 2005
Hi

put the users you want it to apply to in an OU and link the gpo there or put them in a group and use the security filtering to apply it to that group

Voila!

Si
 
Reply With Quote
 
=?Utf-8?B?RHdheW5lIFI=?=
Guest
Posts: n/a
 
      23rd Jul 2005
does this apply to Local Computer Policy as well ?

"pscyime" wrote:

>
> Hi
>
> put the users you want it to apply to in an OU and link the gpo there
> or put them in a group and use the security filtering to apply it to
> that group
>
> Voila!
>
> Si
>
>
> --
> pscyimePosted from http://www.pcreview.co.uk/ newsgroup access
>
>

 
Reply With Quote
 
lforbes
Guest
Posts: n/a
 
      24th Jul 2005
>ok thats where i was confused... so when using GPO i set the policy i
>want to excude the Administrators group from inheriting the policy.
>does anyone know how to do this ?


Hi,

You just create an OU and put the users in that OU. Create a GPO on
that OU and make the settings. The Settings will only apply to the
users in that OU. I have 2400 Users in two domains. I have never
needed to set security on my GPO’s because I just organize via OU. I
just have an Upper level OU for Administrators and it doesn’t have
any GPO’s on it. I don’t set any "restrictive" settings at all in
the Default Domain Policy. I use custom GPO’s instead.

Why do you want to set any Local Computer settings? They get
overridden by the domain anyway. Computer settings are usually not
the ones that are restrictive. Ususally it is the User Configuration
settings where all the lockdown is done.

My users are pretty much locked down as tight as possible with NTFS
and Group Policies.

What specific settings are you looking at? Maybe if you post them I
can be more specific.

Cheers,

Lara
 
Reply With Quote
 
Bruce Sanderson
Guest
Posts: n/a
 
      25th Jul 2005
If you want different User Configuration settings to apply when users log on
to a Terminal Server as opposed to a workstation, use Loopback processing
and put the settings into the User Configuration part of a GPO that is
applied to the OU containing the Terminal Server computer accounts - see
http://support.microsoft.com/?kbid=260370 for information about Loopback
processing. The local Administrators group on the Terminal Server can not
be used to control what users get or don't get the GPO settings; you need to
have a Domain Group that has all of the "Terminal Servers administrators"
domain user accounts in it - the existing Domain Admins might do for this,
but you probably want to have a Domain group that specifically contains the
user accounts you want to be "administrators" on the Terminal Server. Add
this domain group to the local Administrators group rather than individual
domain user accounts. Then, deny this Domain group the Apply GPO
permission:

1. open GPMC
2. click on the GPO that has user settings you don't want administrators to
have
3. select the Delegation tab in the right pane
4. click Advanced... (bottom right of GPMC's right pane)
5. if the group containing the Terminal Server's administrator user accounts
is not present in the list, click Add and add it
6. select the Terminal Servers administrators group
7. remove the check mark from Allow column on the Apply Group Policy row
8. add a check mark to the Deny column on the Apply Group Policy row
9. click OK

If you want exactly the same settings to apply to users whether they log on
to a Terminal Server, a workstation or some other server, then do as lforbes
suggests and segregate the administrator user accounts into a different OU
that does not have the GPO with the User Configuration settings applied.

--
Bruce Sanderson MVP Printing
http://members.shaw.ca/bsanders

It is perfectly useless to know the right answer to the wrong question.



"Dwayne R" <(E-Mail Removed)> wrote in message
news:9479D0EE-3A09-4A74-BC83-(E-Mail Removed)...
> ok thats where i was confused... so when using GPO i set the policy i want
> to
> excude the Administrators group from inheriting the policy. does anyone
> know
> how to do this ?
>
> "lforbes" wrote:
>
>> >This is a server in a domain config but its not in a active directory
>> >model.

>>
>> Hi,
>>
>> You canâ?Tt have a "Domain config" without Active Directory installed
>> unless
>> You are running NT 4 and the server you refer to is just a Windows
>> 2000 Member Server in the domain (like a workstation). In the case of
>> NT 4.0 domain you would need to use poledit.
>>
>> If you are running a Windows 2000 Domain then you have an Active
>> Directory Model because AD is the essence of the Domain. In this case
>> you can use Group Policies and put the Domain Users in an OU and apply
>> the Group Policy to it. (GPâ?Ts donâ?Tt apply to groups)
>>
>> Cheers,
>>
>> Lara
>>
>> --
>> Posted using the http://www.windowsforumz.com interface, at author's
>> request
>> Articles individually checked for conformance to usenet standards
>> Topic URL:
>> http://www.windowsforumz.com/Group-P...ict399313.html
>> Visit Topic URL to contact author (reg. req'd). Report abuse:
>> http://www.windowsforumz.com/eform.php?p=1319368
>>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Can't get correct group policy to Vista machine - using wrong group policy jm Microsoft Windows 2000 Active Directory 1 20th Dec 2006 11:12 AM
Group Policy Management Console - Group Policy Results XP Sp2... Michael J. Davis Microsoft Windows 2000 Group Policy 2 17th Jun 2005 02:28 AM
Today's Group Policy Webcast (Group Policy Processing) Mark Williams [MSFT] Microsoft Windows 2000 Group Policy 0 10th Nov 2004 06:46 PM
group policy editors + other resources of group policy information ... Akhlaq Khan Microsoft Windows 2000 Active Directory 0 24th Jul 2003 11:29 AM
group policy editors + other resources of group policy information ... Akhlaq Khan Microsoft Windows 2000 Group Policy 0 24th Jul 2003 11:29 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 06:17 PM.