Re: Default Domain Controllers Policy



Hi,

Steven Hutchinson schrieb:
It would seem that our Default Domain Controllers Policy is being applied to
all computers in our domain.

No good idea.

As far as I know this should not be the case and should only be applied to
Domain Controllers.

Absolutly right.

Can anyone confirm this to me as it is causing a few problems?

For sure. Because a domain controller is much more restrictiv configured
like "logon locally" and other permissions it is not recommended to
apply the DefDomConPol to the clients, becaus ea "user" needs to work
on a client.
If you want to allow a user logon on that client and you edit the
DefDomConPol, then he is able to logon locally on a DC aswell.
In most cases you don´t wnat that.

Mark
--
Mark Heitbrink - MVP Windows Server
Homepage: www.gruppenrichtlinien.de
extend GPO: www.desktopstandard.com
PM: Vorname@Homepage, Versende-Adresse wird nicht abgerufen.
.



Relevant Pages

  • Re: Need access to Windows SBS 2003 from DOS client
    ... You have to change the Default domain controllers policy and LOWER the security level to allow DOS authentication with server 2003. ... The client and server can communicate, but the client gets an "Error ...
    (microsoft.public.windows.server.networking)
  • Re: Hidden recipient visible in OAB
    ... folder for whatever reason the outlook clients logic will go backwards to v3 ... I manually checked all the domain controllers and they all have the ... that my outlook 2003 sp2 client runs in Unicode mode so it should use the ... MSExchange\OAL Generator and regenerate the OAB. ...
    (microsoft.public.exchange.admin)
  • Re: Port 1025 RPC /Lsass.exe
    ... Clients use DNS to locate all domain controllers in domain. ... Next thing -- client will try to talk to the DC it chose. ... from command line to see which server authenticated the client. ... We have a branch office with approx 40 users. ...
    (microsoft.public.windows.server.networking)
  • Re: Windows 2003 Subordinate Certification Authority
    ... network because I can't reproduce the problem now. ... the replication between the domain controllers is OK. ... logon to the domain via a wired client. ... and all the client machines are configured to use both of them for DNS ...
    (microsoft.public.windows.server.networking)
  • Re: IPSec / domain isolation: confusing MS documents
    ... The reason behind this is that when client connects to DC and if you set up ... Client can't authenticate to DC with Kerberos since IPSec is not up;-). ... domain controllers can't be protected at all. ...
    (microsoft.public.windows.server.security)

Loading