RE: Group policy help needed!!!

From: Rob McShinsky (Rob_at_McShinsky.com)
Date: 12/14/04

  • Next message: Bourque Daniel: "RE : Secondary Storage Device Policy"
    To: <bayoglu@uekae.tubitak.gov.tr>, <laurarobinson@verizon.net>, "'Peter Rodger'" <prodger2008@yahoo.com>, <focus-ms@securityfocus.com>
    Date: Tue, 14 Dec 2004 15:52:22 -0500
    
    

    Some simple gotchas with Application of GPO's

    1. Make sure an administrator other than your self did not setup a deny
    group. True if you setup a policy to apply to all systems within an OU, the
    should get it, but if there is a group of servers within the OU you are
    applying to that you want to not get the server, common practice is to put
    these into a group and deny apply policy to them.

    2. Sorry if this is too simple, but I have had this happen before. You
    apply the policy to Authenticated Users instead of Domain Computers or to
    the specific group of computer objects.

    -----Original Message-----
    From: Burak Bayoglu [mailto:bayoglu@uekae.tubitak.gov.tr]
    Sent: Friday, December 10, 2004 5:46 AM
    To: laurarobinson@verizon.net; 'Peter Rodger'; focus-ms@securityfocus.com
    Subject: RE: Group policy help needed!!!

    It is *technically* true that any server in the corresponding OU should
    receive the group policy but I saw many many examples where some group
    policy settings are not successfully applied *for some reason* altough it
    should. It is certain that if everything is OK group policy is successfully
    applied to all servers but it may be interrupted by a plenty of technical
    reasons that we mostly meet in large enterprise systems.( replication
    problems, time synchronzation, DNS problems, connectivity etc.) As Laura
    says, " Any server that is **supposed** to receive a policy should receive
    the policy.". Unfortunately we can only
    **suppose** that all the servers will apply the policy in the time interval
    we expect in a large and distributed domain.

    B.B.

    -----Original Message-----
    From: Laura A. Robinson [mailto:laurarobinson@verizon.net]
    Sent: Friday, December 10, 2004 5:21 AM
    To: bayoglu@uekae.tubitak.gov.tr; 'Peter Rodger'; focus-ms@securityfocus.com
    Subject: RE: Group policy help needed!!!

    > It is an expected result that not all the servers in the
    > domain successfully apply the policy in a w2k active
    > directory domain.

    No, it isn't. Any server that is supposed to receive a policy
    *should* receive the policy.

    Laura

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Bourque Daniel: "RE : Secondary Storage Device Policy"

    Relevant Pages

    • Cannot add domain user into admin group for local computers
      ... SP1 and client computers some with Windows 2000 Pro SP4 and Windows XP ... the server by replacing a 20 GB HDD with a 80 GB HDD. ... Under group policy ... after the Win 2K3 server was setup - it was in the default mode that is ...
      (microsoft.public.win2000.group_policy)
    • Re: How to allow users to create groups and shares
      ... Add the user/group to the Computer configuration, windows settings, security settings, Local policies, "Allow logon locally" in the Default domain controllers policy and on a existing or new created policy for the member servers. ... Filtering: Not Applied ... check with GPMC on the server or from a client the policy settings. ...
      (microsoft.public.windows.server.active_directory)
    • Domain Controller Security Policy errors
      ... Security Policy or the Domain Controller Security Policy. ... The DC is also a print and file server. ... The domain controller for Group Policy operations is not available. ...
      (microsoft.public.win2000.active_directory)
    • RE: Cant set Local Security policies. They fail to save
      ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
      (microsoft.public.windows.server.sbs)
    • Re: Move W2K3 server to its own OU seperate from SBS (MyBusiness) OU
      ... OU and move the member server to so that it does not inherit it's GPO from ... policies from inheriting the default domain policies of the SBS ... section of the default domain policy. ... In direct answer to your question, you would need to filter this ...
      (microsoft.public.windows.server.sbs)