Re: GPO only applied if user account within OU container

From: Jago (Jago_at_discussions.microsoft.com)
Date: 12/13/04


Date: Mon, 13 Dec 2004 06:09:03 -0800

Arjan,

Thanks for getting involved in this discussion.

I have been advised that I should not need to setup a local machine policy
on the TS server as the GPO should be applied to group of users without
moving the user accounts into the OU.

This is what is really throwing me. Can someone confirm whether they can
successfully apply a GPO to a group without:

1. a local machine policy
2. moving the user account/group into the OU containing the GPO

Thanks,

Jago

"AdL" wrote:

> Jago,
>
> It looks like you have set User Configuration settings in the GPO. As there
> are no users in the OU for the Terminal Server, these settings are not
> applied. This also explains why they ARE applied if you move the test user
> account into this OU.
>
> Next to the loopback option, you could also create a local policy on the
> Terminal Server, which has all the settings you need. This way, every user
> that logs on to this server will get the local policy applied. Please note
> that this will also include the domain and local administrator(s)!
>
> To prevent this policy from applying to administrators, you can set a Deny
> for the Administrators group on the %windir%\system32\GroupPolicy folder.
> This is not the best way, but it works well if you configure it with care.
>
> Regards, Arjan.
>
> "Jago" <Jago@discussions.microsoft.com> wrote in message
> news:A31E19D3-46BE-4DEF-9942-6A7F793DAC31@microsoft.com...
> > Hi,
> >
> > I have a W2K AD infrastructure and I have a problem with the application
> > of
> > a GPO which is filtered by security group.
> >
> > I have setup as follows:
> >
> > 1. created a OU called 'terminal server'
> > 2. moved my TS server to this OU
> > 3. created security group called 'TS Standard' (with member user
> > =tsstandard)
> > 4. created a GPO named 'standard' in the terminal server OU
> > 5. restricted/filtered security on the GPO by removing authenticated users
> > and adding the security group TS Standard - set read permissions and apply
> >
> >
> > When I logon the my TS machine using the tsstandard user, the standard GPO
> > is not applied
> >
> > If I move the user account into the TS Standard OU, the GPO is applied
> >
> > My understanding is that the GPO should be appied without having to move
> > the
> > user account into the OU. Correct?
> >
> > If this is not the case, please explain?
> >
> > If my understanding is correct, can someone help me as I have run out of
> > ideas?
> >
> > I have used gpresult, GPMC and diagnostic logging. The GPO is just not
> > applied.
> >
> > Thanks,
> >
> > Jago
> >
>
>
>



Relevant Pages

  • Automatic Updates options are greyed out, SBS 2003 and WSUS
    ... The SBS server is the DC ... GPO: Default Domain Policy ... Computer Setting: 50 ... GPO: Default Domain Controllers Policy ...
    (microsoft.public.windows.server.sbs)
  • Re: SCW question.
    ... Created a new Server and installed IIS. ... and saw that the default rights for IUSR and IWAM users are there. ... Server to the domain without and GPO's applied...Local Security policy ... rights (which coincides with my Member server GPO settings). ...
    (microsoft.public.windows.server.security)
  • RE: IE Security Group Policy
    ... username and password to access the Companyweb and the GPO did not apply on ... In the Security filtering of the GPO, please select the user account or ... Step 2: Check the IIS settings on the SBS Server: ...
    (microsoft.public.windows.server.sbs)
  • Re: User Profiles
    ... You can use Folder redirection for the Start Menu, ... Exactly what icons are you getting from the Default Domain Policy, ... and in which GPO setting are they defined? ... MCSE, CCEA, Microsoft MVP - Terminal Server ...
    (microsoft.public.windows.terminal_services)
  • Re: Getting desperate: GPO applying incorrectly, PLEASE HELP ME!!
    ... > the exception of placing the TS machine account into the security settings ... > I think you are on to something with the linking of the GPO. ... >> OU to which the loopback GPO is linked, ... >> OU you placed the TS server, and you set loopback on in replace ...
    (microsoft.public.windows.group_policy)

Loading