Re: GPO only applied if user account within OU container

From: AdL (antispam_at_dela-d.nl)
Date: 12/13/04


Date: Mon, 13 Dec 2004 14:50:11 +0100

Jago,

It looks like you have set User Configuration settings in the GPO. As there
are no users in the OU for the Terminal Server, these settings are not
applied. This also explains why they ARE applied if you move the test user
account into this OU.

Next to the loopback option, you could also create a local policy on the
Terminal Server, which has all the settings you need. This way, every user
that logs on to this server will get the local policy applied. Please note
that this will also include the domain and local administrator(s)!

To prevent this policy from applying to administrators, you can set a Deny
for the Administrators group on the %windir%\system32\GroupPolicy folder.
This is not the best way, but it works well if you configure it with care.

Regards, Arjan.

"Jago" <Jago@discussions.microsoft.com> wrote in message
news:A31E19D3-46BE-4DEF-9942-6A7F793DAC31@microsoft.com...
> Hi,
>
> I have a W2K AD infrastructure and I have a problem with the application
> of
> a GPO which is filtered by security group.
>
> I have setup as follows:
>
> 1. created a OU called 'terminal server'
> 2. moved my TS server to this OU
> 3. created security group called 'TS Standard' (with member user
> =tsstandard)
> 4. created a GPO named 'standard' in the terminal server OU
> 5. restricted/filtered security on the GPO by removing authenticated users
> and adding the security group TS Standard - set read permissions and apply
>
>
> When I logon the my TS machine using the tsstandard user, the standard GPO
> is not applied
>
> If I move the user account into the TS Standard OU, the GPO is applied
>
> My understanding is that the GPO should be appied without having to move
> the
> user account into the OU. Correct?
>
> If this is not the case, please explain?
>
> If my understanding is correct, can someone help me as I have run out of
> ideas?
>
> I have used gpresult, GPMC and diagnostic logging. The GPO is just not
> applied.
>
> Thanks,
>
> Jago
>



Relevant Pages

  • Re: GPO problems
    ... OK I understand Loopback, I don't think it will help. ... I have a Terminal Server user within his own seperate OU ... with his own GPO assigned to it. ... therefore no conflicting GPO settings. ...
    (microsoft.public.windows.group_policy)
  • Re: Help with configuration
    ... But now, aside from that, it is not applying any of the settings ... created the GPO on the 2000 server originally. ... I have the Terminal Server computer object in the security ... the domain account profile is blank, ...
    (microsoft.public.windows.terminal_services)
  • Re: Help with configuration
    ... I will specify it on the folder redirect in the GPO. ... But now, aside from that, it is not applying any of the settings again! ... I have the Terminal Server computer object in the security list of the ... domain account profile is blank, ...
    (microsoft.public.windows.terminal_services)
  • Re: Getting desperate: GPO applying incorrectly, PLEASE HELP ME!!
    ... User and Computer settings a single GPO,. ... OU with the Terminal Server computer accounts, ... See in particular the section called "Group Policy Loopback ...
    (microsoft.public.windows.group_policy)
  • Re: Getting desperate: GPO applying incorrectly, PLEASE HELP ME!!
    ... Do you have any idea why the Computer Settings portion of the GPO gets ... > the following setting in a GPO applied to the TerminalServerOU - Computer ... > be able to shutdown the terminal server (e.g. ...
    (microsoft.public.windows.group_policy)