Re: Domain Controller Security Policy

From: Andrew Mitchell (amitchell_at_removecasey.vic.gov.au)
Date: 04/28/04


Date: Wed, 28 Apr 2004 03:12:47 -0700

George Barley <georgebarleyit_nospam@yahoo.com> said

> Darren,
>
> My goal is to let a couple of users log on to the Domain Controller
> machine with ability to do nothing but run this one application, which
> is a RIP (Raster Image Processor).
>
> I understand I have to do it in the Domain Controller Security Policy,
> but I don't understand how to differentiate between Administrators, and
> say a group called "Rip_Users," to where Adminis can do anything, and
> "Rip_Users" can't do but run the RIP app. Where, how, do I do this? I
> need step-by-step instructions. I am very new to Group Policy.
>

You need to create an OU that contains the domain controllers and apply your
GPO to that OU. Make the GPO a loopback policy and to ensure that all
settings are applied to users that login to machines in that OU.
You can then use security on the GPO to deny the 'Apply Group Policy'
permission to the domain admins security group.

Andy.



Relevant Pages

  • Re: GPO - Access denied after changing a GP setting
    ... You are about to restore Default Domain policy and Default domain Controller po ... This may render some server applications to fail. ... Unable to open the GPO due to access denied. ... You are about to restore Default Domain controller policy for the following domain ...
    (microsoft.public.windows.server.security)
  • Re: GPO - Access denied after changing a GP setting
    ... This may render some server applications to fail. ... y Unable to open the GPO due to access denied. ... This tool was unable to re-create the EFS Certificates in the Default D omain Policy GPO Access is denied. ... You are about to restore Default Domain controller policy for the following domain Do you want to continue: ...
    (microsoft.public.windows.server.security)
  • Re: Help with GPO problem!! PLEASE!!
    ... > Reposting as we tried in the GPO thread, but after an exhausted attempt, I ... I am racking my brain on this problem with a Windows 2003 Standard ... > Controller Security Policy or the GPO. ... > Domain Controller Security Policy: Failed to open the Group Policy Object. ...
    (microsoft.public.windows.server.active_directory)
  • Adding GPOs to Default Domain Controllers Policy
    ... In an effort to setup this GPO, I attempted to edit the Default Domain ... Controllers Policy Object by adding the firewall configuration settings ... While the adjusted policy did get applied to the "primary" DC where I ran ... Is adding this type of addition to the Default Domain Controller Policy ...
    (microsoft.public.windows.group_policy)
  • RE: Block Policy Inheritance not working as anticipated
    ... >> I have a Domain Controller running Windows 2000 Server. ... The Domain container has a GPO (Default Domian ... Policy) with password policies defined (complexity, ... >> I am still unable to create a new user account in the EM ...
    (microsoft.public.win2000.group_policy)

Loading