Re: Possible to enforce LP over GP?



You cannot "enforce" local policy. AD delivered policy
always overrules what may be set in local policy.
Someone that has admin access to a machine can however
prevent all policy from being applied. Also, since much of
policy is applied when it is seen as having changed, settings
that only get reapplied in that fashion can be changed directly
if there is an available method to do so and those changes
will remain effective until the policy settings are reapplied.

Roger

"schmultzburger" <SPAMburger@xxxxxxxxx> wrote in message
news:132eugq2eqegb68@xxxxxxxxxxxxxxxxxxxxx
I was told once by a naysayer that GP was worthless as long as a domain
user had local admin rights because they could get around any settings.
Other than removing a computer from the domain, the only way I can think of
that this might be possible is by setting a LP that is counter to the GP
settings and somehow enforcing the LP. I haven't found anything to either
confirm or deny that this is possible. What I do read though is that
LSD-OU applies with later policy settings overriding earlier ones, except
for enforced settings. That says to me that IF you can enforce LP, it can
always override GP. Can anyone here speak to this?

TIA

S-


.



Relevant Pages

  • Re: scripted logon
    ... Why can't you launch all the scripts from a Group Policy based Logon script. ... Here's the policy settings (I sure hope word wrap doesn't mess it up too ... Windows Components/Windows Installer ...
    (microsoft.public.windows.terminal_services)
  • Re: New Password Policy Implementation Problem
    ... Default Domain Group Policy object. ... > able to implement the following settings via the Default Domain ... > Enforce Password History ... > These policies were enforced for all domain users and we verified the ...
    (microsoft.public.win2000.group_policy)
  • Re: New Password Policy Implementation Problem
    ... Default Domain Group Policy object. ... > able to implement the following settings via the Default Domain ... > Enforce Password History ... > These policies were enforced for all domain users and we verified the ...
    (microsoft.public.windows.group_policy)
  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... Server Security and Auditing Policy ... This list only includes links in the domain of the GPO. ... The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)
  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... > Server Security and Auditing Policy ... > This list only includes links in the domain of the GPO. ... > The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)

Loading