Re: Restricted Groups in OU

From: Mike Schmidt (mikesc_at_hynixeugene.com)
Date: 05/19/04


Date: Wed, 19 May 2004 13:14:47 -0700

That did the trick. The Default Domain Policy was "enforced". As soon as I
set it to not "enforce", then the OU policy did take effect. Thanks!

"Derek Melber [MVP]" <derekm@braincore.net> wrote in message
news:u3TvcIdPEHA.4036@TK2MSFTNGP12.phx.gbl...
> The OU policies do supersede the domain policies. Make sure the Def Domain
> POlicy does not have no override set.
>
> Also, you will need to configure the lower level GPO with ALL members in
the
> group. Restricted groups will not append to one another. It is all or
> nothing as they compile the list. So, at the OU level, configure the GPO
> with the Domain Admins and the other group you desire.
>
> --
> Derek Melber
> BrainCore.Net
> derekm@braincore.net
> "Mike Schmidt" <mikesc@hynixeugene.com> wrote in message
> news:uJKPzYcPEHA.620@TK2MSFTNGP10.phx.gbl...
> > We have a default domain policy that puts the Domain Admin group in the
> > local Administrators group. What I need to do is make a restricted
group
> on
> > a particular OU so that another domain group would be put in the local
> Admin
> > group as well as the Domain Admin. It's all set up, but when I try it,
it
> > is not applying. When I use the GPMC modeling it is not showing the
other
> > group in the local admin group.
> >
> > I thought that the OU policies would override the default domain policy?
> >
> >
>
>



Relevant Pages

  • RE: Local security getting overwritten
    ... I am the Domain Admin on our production and test networks. ... I don't want the installation of our application to be a trial for our ... the Domain Policy conflicts with your server application ... Writing a configuration tool to change the domain policy is not the best ...
    (microsoft.public.platformsdk.security)
  • Re: Group Policy not applying over Network to XP users
    ... >> I've modified the screen saver policies in the Default Domain Policy. ... >> these Domain admin accounts. ... I tried the second domain admin account but the policy had not ... >> roaming profile configured. ...
    (microsoft.public.win2000.active_directory)
  • Re: I implimented a group policy and it priventing me from getting to the MMC
    ... If you configured this on the "Default Domain Policy" you could rename the ... the next time the users log on. ... the Adminpak and right-click AD Users and Computers and specify domain Admin ... > remove the GPO from the domain controler so that I can fix ...
    (microsoft.public.windows.group_policy)
  • RE: Local security getting overwritten
    ... the Domain Policy conflicts with your server application ... account requirement. ... domain admin to change the domain policy, ...
    (microsoft.public.platformsdk.security)
  • Problem with applying Group Policy
    ... I have tried to apply Group Policies to the ... >users when they login, however the policies don't seem to ... >change the Default Domain Policy just to hide the icons ... >client workstation and it appears that the workstation is ...
    (microsoft.public.win2000.security)