Policy Security on 2003 vs. 2000

I

itreman

On Windows 2000 Server, you have the ability to completely customize
the security settings for a GPO. By right clicking on the GPO and
choosing properties, you can go to the security tab and tell Windows
who that that GPO should run for and who it shouldn't (via "deny"). In
Windows 2003 Server, you use the Group Policy Management console to
manage group policies and it doesn't have a method for adjusting the
security like 2K. You can add users, computers, or groups to the
filtering section, but this doesn't allow you to deny the GPO from
running on an Admin, or other AD group. Does anyone know how to do
this? I've been creating policies on my XP workstation via the GPO
Management console, but when I need to adjust the security for those
policies, I go to a Windows 2000 server and do it there. Seems lame.
Any ideas??
 
G

Guest

In the 2003 group policy management tool, if you click on the policy, then
click the delegation tab on the right hand pane you can set your deny
permission there. I had mixed success with it. It worked when I denied
permission to apply for the domain admin group, but not for a group that I
created. Hope this helps.

Andy
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top