Default Domain Controller GPO Question

From: adfreak (rtivnan_at_comcast.net)
Date: 07/01/04


Date: Thu, 1 Jul 2004 15:35:17 -0400

Here is my situation. The "Default Domain Controller Policy" for my
production AD has been modified numerous times (just the user rights
section). We are going to be moving to native mode from mixed mode shortly.
We would like to link a newly created DC Security policy.inf file via a GPO
to the Domain Controllers Container.

For now, we want to keep the existing settins for the default DC GPO
(because we're not sure what will happen if we delete it because previous
admins added numerous users/groups to certain user rights policies). How
should we go about linking the newly created .inf? Do we simply "add" a GPO
and precede it before the Default DC one? What happens when some of the
user rights management settings conflict between the two as I know they
will? Which one will take affect? or will both?

Is it bad to have two of them?

Please advise



Relevant Pages

  • Re: Default Domain Controller GPO Question
    ... You can add a new GPO to the domain controller container and configure it to ... defined settings though as it will override any like defined setting in the ... GPO's below it which in your case would be the default domain controller GPO ... The links below may be helpful on configuring user rights and other ...
    (microsoft.public.win2000.group_policy)
  • Re: Unable to promote a new server
    ... I noticed the Default Domain Controller policy ... to recommend that you utilize Windows Server 2003 Default Group Policy ... Dcgpofix tool, Microsoft recommends that as soon as you run it, you review ... Q267553 How to Reset User Rights in the Default Domain Controllers GPO ...
    (microsoft.public.windows.server.active_directory)
  • Re: SCW question.
    ... That gives a "middle ground" stance, where GPO does ... does also (I do not use Iusr_/Iwam_ but always define custom accounts). ... not populated into the minimum required user rights upon startup if needed. ... still see the IUSR and IWAM users in the local security policy. ...
    (microsoft.public.windows.server.security)
  • RE: dcpromo fails
    ... computer account ESDC1$ on the remote domain controller ... user rights being applied to the ESDC2 DC. ... domain controller in directory partition ...
    (microsoft.public.windows.server.general)
  • Re: SCW question.
    ... I think that what you are seeing can be explained by the fact that a GPO ... when the accounts were added directly in the local policy into the ... for the user rights is one way that I handle this issue. ... I am noticing some interesting results when using the SCW and Group ...
    (microsoft.public.windows.server.security)