PC Review


Reply
Thread Tools Rate Thread

Different group, different active directory group policy

 
 
=?Utf-8?B?anN0aWMwNEBjcC5jZW50ZW5uaWFsY29sbGVnZS5j
Guest
Posts: n/a
 
      27th May 2006
I have done this once, and it somewhat worked. Okay.
I first kept the default group policy, which is rather liberal. I assign
this one to the normal system users. I want another group policy, which
contains entries for custom user interface, and an otherwise locked down
system. I loaded up the dsa.msc program, right-clicked properties, clicked
the group policy tab. I added the user group to which the strict policy was
to be applied. This user group is "family" and has two members. My own user
account is not a member of this group. It is a member of the domain users
group, which is supposed to obtain the default domain policy. However, when
logging in with my account, the strict group policy is applied.

Any ideas how to do this? One group has one policy assigned, the other
group has a different policy assigned. Neither group is to obtain values
from either groups policy.

 
Reply With Quote
 
 
 
 
Roger Abell [MVP]
Guest
Posts: n/a
 
      28th May 2006
<(E-Mail Removed)> wrote in message
news:B640DAC1-5462-4302-BD7F-(E-Mail Removed)...
>I have done this once, and it somewhat worked. Okay.
> I first kept the default group policy, which is rather liberal. I assign
> this one to the normal system users. I want another group policy, which
> contains entries for custom user interface, and an otherwise locked down
> system. I loaded up the dsa.msc program, right-clicked properties,
> clicked
> the group policy tab. I added the user group to which the strict policy
> was
> to be applied. This user group is "family" and has two members. My own
> user


Did you also remove the Read/Apply for Authenticated Users ??
(which includes all accounts)

> account is not a member of this group. It is a member of the domain users
> group, which is supposed to obtain the default domain policy. However,
> when
> logging in with my account, the strict group policy is applied.
>
> Any ideas how to do this? One group has one policy assigned, the other
> group has a different policy assigned. Neither group is to obtain values
> from either groups policy.
>


Normally, security group filtering is a second choice way to do this, and
also, normally the other GPOs are left in place applying to all accounts,
and then the GPO with different settings that are to apply to only some
accounts is used to overwrite the settings from the baseline all accounts
policies.
Instead of using security group filtering, make an OU for the accounts
that are to receive the "special" settings and move those accounts into
that OU. Then link the special settings GPO to that OU. This way you
do not need to deal with the security settings on the GPO, just move
accounts into the OU and you can leave the GPO set to apply to
Authenticated Users (which then means all accounts in the OU)


 
Reply With Quote
 
=?Utf-8?B?anN0aWMwNEBjcC5jZW50ZW5uaWFsY29sbGVnZS5j
Guest
Posts: n/a
 
      28th May 2006
Yes, that seems to be a way better approach.
On the group policy for the OU i make, would it make
sense to click "block policy inheritance" and "prevent overiding"
so that the default domain policy never applies to this OU?




"Roger Abell [MVP]" wrote:

> <(E-Mail Removed)> wrote in message
> news:B640DAC1-5462-4302-BD7F-(E-Mail Removed)...
> >I have done this once, and it somewhat worked. Okay.
> > I first kept the default group policy, which is rather liberal. I assign
> > this one to the normal system users. I want another group policy, which
> > contains entries for custom user interface, and an otherwise locked down
> > system. I loaded up the dsa.msc program, right-clicked properties,
> > clicked
> > the group policy tab. I added the user group to which the strict policy
> > was
> > to be applied. This user group is "family" and has two members. My own
> > user

>
> Did you also remove the Read/Apply for Authenticated Users ??
> (which includes all accounts)
>
> > account is not a member of this group. It is a member of the domain users
> > group, which is supposed to obtain the default domain policy. However,
> > when
> > logging in with my account, the strict group policy is applied.
> >
> > Any ideas how to do this? One group has one policy assigned, the other
> > group has a different policy assigned. Neither group is to obtain values
> > from either groups policy.
> >

>
> Normally, security group filtering is a second choice way to do this, and
> also, normally the other GPOs are left in place applying to all accounts,
> and then the GPO with different settings that are to apply to only some
> accounts is used to overwrite the settings from the baseline all accounts
> policies.
> Instead of using security group filtering, make an OU for the accounts
> that are to receive the "special" settings and move those accounts into
> that OU. Then link the special settings GPO to that OU. This way you
> do not need to deal with the security settings on the GPO, just move
> accounts into the OU and you can leave the GPO set to apply to
> Authenticated Users (which then means all accounts in the OU)
>
>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Active directory and group policy integration Gary Spyware Discussion 0 9th Jul 2005 04:12 AM
Active Directory Group Policies not showing in Group Policy editor Chupacabra Microsoft Windows 2000 Group Policy 2 9th Dec 2004 05:18 PM
Group Policy and Active Directory Bruce Microsoft Windows 2000 Networking 2 31st Mar 2004 11:08 AM
Re: Active Directory Group Policy Brian Desmond [MVP] Microsoft Windows 2000 Active Directory 0 14th Sep 2003 09:14 PM
Group Policy & Active Directory for SUS Cooper Microsoft Windows 2000 Security 0 13th Aug 2003 09:05 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:59 PM.