Re: Group Policy - Computer Policy - When does this get applied?



Michelle,

I will try to sort this, but the phrasing you used is, well, a little
twisted to my ears, so I may miss the mark.

Computer policies are applied when the machine boots and then
periodically (default for client system is randomized about 90 minutes),
but note that applied actually means check for changes and do what is
needed.

Now, most policies (a GPO is a collection of policies) are either User
policies or Computer policies. As such, it is a little hard to see the
sense
in what you say, that you want to apply the same policy but using the
computer account instead of the user account.

User polices are applied at login by a user account to which the GPO
is applied if that user account is within scope (ex. in the OU to which
the GPO is linked) of the GPO.
Similarly, computer policies are applied to systems to which the GPO
is set to apply and that are within scope of the GPO (ex. computer
object is within OU to which GPO is linked)

Does that help any ?
You may want to repost in one of the Group Policy newsgroups, like
microsoft.public.windows.group_policy


"Michelle" <Michelle@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:BC402D77-AC54-4650-B636-41629423C61D@xxxxxxxxxxxxxxxx
I know that when you deploy software through GPO and assign the security
group to a user account that policy gets applied after the user has
supplied
there network credentials and are logging into there PC.

What I would like to know is at which stage would this same policy be
applied if it is added to the computer account instead.

The reason why I am asking this question is that I have a remote user who
I
have added his PC to a security group and I need this policy to apply
itself
when he authenticates on the network using Cisco VPN client in the "Start
before windows logon" mode. For some reason computer based polcies dont
"appear" to be applying although user account polices do when logging on
like
this


.



Relevant Pages

  • RE: Block Policy Inheritance not working as anticipated
    ... >> I have a Domain Controller running Windows 2000 Server. ... The Domain container has a GPO (Default Domian ... Policy) with password policies defined (complexity, ... >> I am still unable to create a new user account in the EM ...
    (microsoft.public.win2000.group_policy)
  • Re: Setting up the user
    ... I assume this user account resides in an OU to which the policy is applied. ... Navigate to the OU to which the GPO is linked. ... Open the Properties dialog for that OU and select the Group Policy tab. ...
    (microsoft.public.windows.group_policy)
  • Re: import list of an OU (gpo)
    ... Most likely the user account is NOT in that OU. ... reside in the OU where the GPO is linked. ... > I set the folder redirection policy on an OU. ... >>To get to this, use the MMC, then select Security Templates. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Group Policy Question
    ... You can not have a different password policy linked to each OU. ... >> domain user account objects that might be located in that OU. ... >> link the desired GPO to the correct OU. ... >> I might suggest that you check out the GPMC. ...
    (microsoft.public.windows.server.active_directory)
  • Re: GPO Useage
    ... account user or for a power user account. ... a GPO for a single user or does it have to be done for a group? ... does not matter if the effort involved to administer for a single user ...
    (microsoft.public.windows.server.active_directory)