Re: loopback processing mode

From: Chriss3 (noSpamHere_at_chrisse.se)
Date: 06/19/04


Date: Sat, 19 Jun 2004 12:30:40 +0200

Hello Robert.

This sounds weird to me because it works as expected for me in many cases.

Deny Apply Policy for Domain Admins for the particular GPO Object.

Ensure the restrictions not are applied from another policy?

You can use the built in tool gpresult to see applied policies and settings.

-- 
Regards
Christoffer Andersson
No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips
"R. Schaaf" <scf@hesasd.nl> skrev i meddelandet
news:1d70e01c45452$5927ab80$a301280a@phx.gbl...
> I needed loopback processing mode to apply GPO's to
> terminalserverusers, so if they log on to a hard disk
> machine they don't get the GPO. However if domain
> administrator logs on to a terminalserver, he gets the GPO
> as well and I don't want that. We tried to deny apply
> group policy on domain admins but that didnt work. Has
> anyone a clue???
>
> gr. Robert Schaaf


Relevant Pages

  • Re: cannot logon locally
    ... For a machine in a domain use a GPO that will apply ... >>equivalent) and then set a deny of full control for the ... >>local policy to remove the obstructing setting. ... >>> not let me logon locally. ...
    (microsoft.public.windows.group_policy)
  • Re: Exclude from GPO ..
    ... Policy but to create a new GPO linked to the Domain level? ... and deny them the right to read or apply the gpo. ... but for the life of me cannot figure out how to exclude the user accounts ...
    (microsoft.public.windows.server.active_directory)
  • RE: Filtering GPO
    ... When filtering the security group for the Domain Admins, ... Apply Group Policy is all that is required to ensure this GPO does not apply ...
    (microsoft.public.windows.group_policy)
  • Re: Hide TS drives from users, but not Administrators.
    ... I took Jeff's suggestion to create a loopback gpo with nothing else in it. ... then created another gpo to deny all users from the servers local drives. ... I want to deny the Domain Admins from applying this policy so I continued ...
    (microsoft.public.windows.terminal_services)
  • RE: Restricted Group Problem My Scenario and problem..what am i doing
    ... if you wish to security filter the policy you must filter it based on ... The computers you wish to apply this policy must have ... Open up a GPO ... this group, I add Domain admins, another domain group, and then i choose ...
    (microsoft.public.windows.server.active_directory)

Loading