Re: Group Policy - Defining Security Policies Using Variables?

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 10/28/04


Date: Thu, 28 Oct 2004 08:13:11 -0700

Unextended GP does not have ability to use a meta-like level
in the policy settings. Some things however, if set in GPO at
the OU level can be used to name accounts that only exist at the
local machine level if you do this with care and the account
or group to be named is a well-known, predefined in Windows.
Otherwise, look at use of a startup script defined in GPO that,
in your case, invokes such as NTrights tool from the reskit.
Also, there are third-party products that extend the GP mechanics
so they can accommodate meta-info that is expanded on the target
client in client specific fashion.

-- 
Roger Abell
"Jason Cook" <JasonCook@discussions.microsoft.com> wrote in message
news:BED93E2B-782A-4AB8-AF8C-7100CDAD926D@microsoft.com...
> Problem:
> When setting up a new GPO, is there a method for using variables such as
> %computername%\LocalServiceAccount when defining security permissions such
as
> "Deny log on locally"
>
> Background:
> I'm monitoring hundreds of local server accounts with common names and
> adminstrative access.  These accounts run services and applications but do
> not need console access.  I need to find an effective method for setting
the
> permission "Deny Logon Locally."


Relevant Pages

  • Re: Loopback policy enabled, seems to cause login script to run twice
    ... GPO containing it applies to, regardless of which actual GPO it is included ... the description of how Loopback processing works is NOT ... enables loopback processing appears and where the relevant computer accounts ... Sounds like you have included the setting that runs the Logon Script so high ...
    (microsoft.public.windows.group_policy)
  • Re: Disabling Interactive Logon Against Security Group
    ... Essentially this is to secure half a dozen guest accounts on domain of ... question "disable interactive logon privilages against specific OU/User ... If you set this in a GPO then the list that is to be denied that you ... One route to avoid this is to cause a machine local group to be ...
    (microsoft.public.security)
  • Re: Domain password policy problems
    ... password policies within a single domain. ... Password Policy done right ... If a GPO linked at the domain level applies to all accounts and Gpos ...
    (microsoft.public.windows.group_policy)
  • Re: Basic Sec Template Design
    ... defined in a GPO linked to the domain object to impact domain accounts ... allowed to impact machines then these impact the machine local ... Have you also reviewed the security guides? ...
    (microsoft.public.windows.server.security)
  • Re: Disabling Interactive Logon Against Security Group
    ... Essentially this is to secure half a dozen guest accounts on domain of ... question "disable interactive logon privilages against specific OU/User ... Where I follow least privilege this is a total non-issue, as the machines ... If you set this in a GPO then the list that is to be denied that you ...
    (microsoft.public.security)