Trouble with GPO security filtering

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Drazen (drazen_petrek_at_yahoo.com)
Date: 07/26/04


Date: 26 Jul 2004 12:58:07 -0700

This is our configuration:
- w2k DC having simple domain with default containers intact (Users, Computers...)
- one global security group (group "A") dwfined on level of domain
  itself (same level where containers Users and Computers are)
  whose members are two domain computers (listed in Computers container).
- group policy "B" defined on whole domain (under Default domain policy)
- for group policy B, Authenticated users were removed under
  "Security" settings and our group "A" was added with "Read" and
  "Apply group policy".

THe problem is that policy "B" is not applied to security group "A".
Actually the policy is not applied to *ANY* computers.
When GPREsULT is run on machines in security group "A" there is
"Filtering: Denied (Security)". GPRESULT shows NO sign of those two
computers being in security group "A" (and I suppose thats why policy
is not applied to them).

What have I done wrong?
If I remove group "A" from policies "Security" and add those
two computers manually (and set Read, and Apply policy to each of them),
the policy is applied successfully but I'm not satisfied with this
solution. Who can explain this? I hope that everything is explained well...

Thank you,
Drazen



Relevant Pages

  • Proxy GPO will not apply
    ... with a new security group containing 3 test computers. ... Made the proxy settings per-machine instead of per-user. ... Made the policy be Enforced. ...
    (microsoft.public.windows.group_policy)
  • Re: local policy exception to group policy
    ... Create a security group and add computers you want to override the policy on. ... Apply the group policy only to the security group you created above instead of the default of everything/everyone. ... And check the option to enforce it so it overrides other settings. ...
    (microsoft.public.windows.server.sbs)
  • Problem with security GPO filtering
    ... itself (same level where containers Users and Computers are) ... whose members are two domain computers. ... group policy "B" defined on whole domain ... When GPREsULT is run on machines in security group "A" there is ...
    (microsoft.public.win2000.group_policy)
  • Re: Group Policies - not working?
    ... make sure that the 'Domain Computers' security group has read & apply ... I am pretty sure I created the policy in the Active ... >> Apply the policies from Active Directory Users and Computers. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Problem with security GPO filtering
    ... > itself (same level where containers Users and Computers are) ... > whose members are two domain computers. ... Authenticated users were removed under ... >two computers manually (and set Read, and Apply policy to each of them), ...
    (microsoft.public.win2000.group_policy)