Active Directory User w/ NT Policy in NetLogon Share?

From: BillB (anonymous_at_discussions.microsoft.com)
Date: 04/01/04


Date: Thu, 1 Apr 2004 13:26:05 -0800

Hi,
We have an Active Directory environment with no PDCs. However, we have a number of NT machines. I need to have an AD use logon to an NT machine, but lock down the NT desktop with a NT policy for that user (The user does not roam).

When I create an NT policy, store it in a Local NetLogon share, lockdown works for a local user, but not an AD domain user. Note the users AD account does run a login script, off the AD DC, specified in their account.

Now this same account does NOT lock down if I put the NT policy in the folder holding the login script.

Does I need to put the NTconfig.Pol file in the Netlogon share on the AD DC? Or can I somehow still maintain the policy on
the local machine? Our corporation is extremely large and many sites globally share that Netlogon share on the AD DC servers.

Thanks,
Bill

 



Relevant Pages

  • Re: Concurrent Logins
    ... policy. ... to limit accounts to a single concurrent login. ... account shares are each defined to allow one connection. ... login script checks if the mapping was successful, ...
    (microsoft.public.windows.group_policy)
  • Re: GPO causing client security logs to fill?
    ... a virus in play. ... settings to be applied on your client workstations. ... Group Policy is a complex and often misunderstood beast. ... I modified the account ...
    (microsoft.public.windows.server.sbs)
  • Re: The local policy of this system does not permit you to logon i
    ... Security policies were propagated with warning. ... Error 0x534 occurs when a user account in one or more Group Policy objects ... I have checked the security policies & the administrator profile is not ...
    (microsoft.public.windows.server.sbs)
  • Re: GPO causing client security logs to fill?
    ... Unlink the Default Domain Controller Policy (As it was not previously ... settings to be applied on your client workstations. ... I modified the account ... So basically, the Account lockout threshold, account lockout ...
    (microsoft.public.windows.server.sbs)
  • Re: GPO causing client security logs to fill?
    ... Possibly delete the Default Domoan Controller Policy (As it did not ... issues as it was about recoverying from a virus which appears to ... with client logon failures. ... I modified the account ...
    (microsoft.public.windows.server.sbs)