Why doesn't Group Policy work if I put a local group in the affected OU instead of the actual user account?



Windows 2003 Server. AD domain. Created an OU so that I can apply a Group
Policy to a collection of users. As per Msoft instructions, I created a
Local Group, and put that local group inside the OU. Created a Global
Group, added users to the Global Group, and then added the Global Group to
this local group. I then created a Group Policy - User Config, and set up
the restrictions. I applied the GP to the OU, and did a GPUPDATE / FORCE.

The result is that this GP doesn't affect the pc where the user above logs
in. If I take the local group out of the OU, and just put the individual
user account into the OU (instead of the local group), the GP works fine
when that user logs into a PC.

Any ideas why this won't work when I use groups to add users to the OU, and
thus to the Global Policy world?

Thanks
CS



.



Relevant Pages

  • Re: LOCAL POLICY Filtered (Stand alone PC)
    ... permission last night. ... reset security policy was what did it. ... You are GREAT, no reinstall here. ... Then use gpedit.msc to bring up Local Group ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Adding AD Account to NT Global
    ... > accounts from other domains while global group is used to be added in other ... The local group in NT is only accessible within the controllers and can't be ... I have already done some successful migrations from nt4 to w2k3 root domain. ...
    (microsoft.public.windows.server.migration)
  • Hi.
    ... Each global group belongs to one or more: ... the local group. ... rather than giving rights at the login level. ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
    (Security-Basics)
  • Re: Cannot add users from trusted domain on a domain controller
    ... Did you enable and try out this policy: ... Start Menu location for a global group from another domain in a GPO, ... "Meinolf Weber" wrote: ... Please describe how you setup the trust, what kind of trust and how ...
    (microsoft.public.windows.server.active_directory)
  • Re: Local GPO refreshes outside of refresh interval
    ... are changed via the GPO or local policy. ... > policies are getting reapplied only after what seems to be certain changes ... we are talking about one particular policy: ... > which was still set via local Group Policy. ...
    (microsoft.public.windows.group_policy)