Re: Exchange OWA 2003 Trusted Root Certificate

From: Smurfman (Smurfman_at_discussions.microsoft.com)
Date: 02/15/05


Date: Tue, 15 Feb 2005 10:37:07 -0800

Not based on this - "The Authenticated Users group includes both users and
computers. " See below. I think I have a pretty good working knowledge of
how this should work, I admit, I don't know it all...but I do know that if a
GPO is created, and the default setting for security and applying that
security is Authenticated Users, then this will in fact apply to the computer.

Give me some credit...

"Security Filtering
Security filtering is a way of refining which users and computers will
receive and apply the settings in a GPO. Using security filtering, you can
narrow the scope of a GPO so that it applies only to a single group, user, or
computer by specifying that only certain security principals within a
container where the GPO is linked apply the GPO. Security filtering
determines whether the GPO as a whole applies to groups, users, or computers;
it cannot be used selectively on different settings within a GPO.

In order for the GPO to apply to a given user or computer, that user or
computer must have both Read and Apply Group Policy (AGP) permissions on the
GPO, either explicitly, or effectively though group membership.

By default, all GPOs have Read and AGP both Allowed for the Authenticated
Users group. The Authenticated Users group includes both users and computers.
This is how all authenticated users receive the settings of a new GPO when it
is applied to an organizational unit, domain or site. Therefore, the default
behavior is for every GPO to apply to every Authenticated User. By default,
Domain Admins, Enterprise Admins, and the local system have full control
permissions, without the Apply Group Policy ACE. However, administrators are
members of Authenticated Users, which means that they will receive the
settings in the GPO by default. "

"Paul Adare" wrote:

> In article <6AAFFDB5-6B9E-4CB5-BE75-9E0FB3938DE4@microsoft.com>, in the
> microsoft.public.win2000.security news group, =?Utf-8?B?U211cmZtYW4=?=
> <Smurfman@discussions.microsoft.com> says...
>
> > By the way, you never answered my original question, rather you attacked how
> > YOU might have done something or how you thought it should have been done.
> >
>
> I didn't attack anything, you're still missing some fundamentals on how
> Group Policy works. For example, setting in the computer configuration
> section of a GPO are not processed when a user account processes a GPO
> and settings in the user configuration section are not processed when a
> computer account processes a GPO.
>
> I strongly suggest that you do some reading up on Group Policy.
>
> Have fun.
>
> --
> Paul Adare
> "On two occasions, I have been asked [by members of Parliament],
> 'Pray, Mr. Babbage, if you put into the machine wrong figures,
> will the right answers come out?' I am not able to rightly apprehend
> the kind of confusion of ideas that could provoke such a question."
> -- Charles Babbage (1791-1871)
>



Relevant Pages

  • Re: GPO for IE home page
    ... Place your users in a suitable OU and link GPO to OU. ... Let's name it Graphics Settings. ... add security group of your Graphics department. ... Repeat the procedure as above configuring different home page and setting Security filtering as necessary. ...
    (microsoft.public.windows.server.general)
  • Re: user have multiple PCs
    ... Security Filtering then it works. ... > do not want it to apply to tech support then give tech support deny ... > permission for that GPO. ... >> to standard users then the settings do not get applied when a user logs ...
    (microsoft.public.windows.group_policy)
  • Re: How to control Windows XP SP2 Windows Firewall via Active Directory
    ... authenticated users should also have apply GPO ... settings in an OU will apply to all computers in that OU. ... About the scope, for the authenticated users, I have the permission to allow read access. ...
    (microsoft.public.win2000.active_directory)
  • Security Filtering for specific "Links" instead of "GPO"
    ... The GPO is linked to an OU that has two ... The settings in the GPO are behaving as intended - the ... settings apply to every user except members of the group that has the Deny ... the first except for the difference in the Security Filtering? ...
    (microsoft.public.win2000.group_policy)
  • Re: Group Policy Help
    ... In addition to the advice from Steve, using Security Filtering is quite ... A GPO will be applied to all of the objects in the OUto which it applies ... to PREVENT the settings in a GPO from applying to a subset of the objects to ... > to setup a group policy just to test on 1 test user. ...
    (microsoft.public.windows.group_policy)