Re: Effects of not using any GPO in AD?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Mark Renoden [MSFT] (markreno_at_online.microsoft.com)
Date: 07/29/04


Date: Fri, 30 Jul 2004 08:51:18 +1000

Hi

Do not remove the Default Domain Policy or the Default Domain Controllers
Policy. These provide a base line set of policies that if left alone,
shouldn't cause you problems.

Kind regards

-- 
Mark Renoden [MSFT]
Windows Platform Support Team
Email: markreno@online.microsoft.com
Please note you'll need to strip ".online" from my email address to email 
me; I'll post a response back to the group.
This posting is provided "AS IS" with no warranties, and confers no rights.
"Parhez Sattar" <pxs01@grh.org> wrote in message 
news:6ac301c47583$dae5b7f0$a501280a@phx.gbl...
> We have a mixed network with 200+ W2K/XP clients, with
> Novell eDirectory (it was there first) and a newly
> upgraded Windows Server 2003-based single domain (upgraded
> from NT 4).  All clients use resources that are in
> both "networks".  Since we have been traditionally
> managing our resources using eDirectory (originally Bind--
>>NDS), there is a push to disable the Default Domain Group
> Policy Object and configure all workstations's local GPO
> using Zenworks for Desktop from Novell from a central
> location.  This disregards group policy management on the
> Windows servers.  The thought at this point is to leave
> the Default Domain Controllers GPO alone, however.
> Essentially, we want to use AD just to authenticate users
> to Windows-based resources.  We do use DNS/DHCP based on
> W2K3 servers, both integrated with AD.  My questions are:
>
> -Without using group policies handed down by the domain
> (via the "Default Domain GPO") and by setting group
> policies only at the local workstation, are we weakening
> any inherent security (or any other benefits) built-into
> AD-based group policy implementations.
>
> -Parallely, since the same AD GPO would have set the
> policies on the Windows servers also (and we are not using
> that, nor are we manually setting the local GPO on each
> Windows server), what ramifications might we have at the
> server level security and performance?
> 


Relevant Pages

  • Re: Local GPO refreshes outside of refresh interval
    ... I looked through my GPO's Windows Settings section ... > Some policies, including IE policies, have a checkbox that defines if this ... > it should apply EVEN if the value defined in GPO did not change since the ... we are talking about one particular policy: ...
    (microsoft.public.windows.group_policy)
  • Re: "There are 0 filters" using IPSec via GPO
    ... 1)Deleting all IPSec policies in the GPO ... 4)Assigning "request security" policy in Local Security Settings, ...
    (microsoft.public.win2000.security)
  • Re: Windows 2003 Server - Group Policy
    ... Group Policies refresh time is 90-minute intervals by default. ... For Windows 2000 Computers see the follow KB: ... Policy Inheritance can be set to this OU it means no policies from higher ... You can also set No Override to a particular GPO. ...
    (microsoft.public.win2000.active_directory)
  • RE: Group Policy: multiple password policies in the same domain?
    ... > it under access to the GPO. ... The conflict only happens when both policies ... results in having the policy denied. ... > user accounts it affects be able to read it and have "apply ...
    (Focus-Microsoft)
  • Local GPO refreshes outside of refresh interval
    ... We are experiencing an unique situation where local group ... we are talking about one particular policy: ... a homepage on users and therefore, we never set this policy on the AD GPO. ... Even though we knew that group policies are refreshed every 90 minutes on ...
    (microsoft.public.windows.group_policy)