question on default settings and scope

D

djc

by default the Read and Apply Group Policy permissions are enabled for the
Authenticated Users security principle on new GPOs. And you can filter the
scope by adding/removing users/groups for a GPO using these permissions. My
question is then how do computer-specific GPO settings apply by default?

1) For example, I can set computer-specific settings in the default domain
GPO or a new GPO linked to the domain and they apply to all domain computer
accounts even though nothing is on the Security tab of the GPO properties to
indicate this, right?

2) Whether this is a valid question depends on the answer to number 1 but
I'll ask anyway. I know moving computer accounts into OUs and linking GPOs
to the OUs you can control GPOs. But what about the Read and Apply Group
Policy permissions? Can they be used to further filter scope of GPOs for
computer-specific settings?

any info would be greatly appreciated. Thanks.
 
S

Steven L Umbach

You can filter computer configuration portion of GPO's. Computers are also members of
authenticated users. You would have to add your computers to a global group and give
that global group apply permissions instead of authenticated users. If you run
gpresult on a computer it will list the group membership for the users and
computers. --- Steve
 
D

djc

Thank you!

Steven L Umbach said:
You can filter computer configuration portion of GPO's. Computers are also members of
authenticated users. You would have to add your computers to a global group and give
that global group apply permissions instead of authenticated users. If you run
gpresult on a computer it will list the group membership for the users and
computers. --- Steve
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top