Re: GPO for servers only

From: Phillip Windell (_at_.)
Date: 02/09/05


Date: Wed, 9 Feb 2005 11:19:25 -0600

The best way is to have the servers in an OU and apply the GPO to the OU.
You control what it effects by where you apply it in the "tree".

Here is an example AD Tree looks like I would use (each "--" is an OU).
Even though NT4.0 doesn't partake in AD I still have the OUs with the
machines in them for organizational purposes. Notice there is a "disabled
users" OU for former employees where the disabled accounts would be kept
instead of deleting the accounts.

[Domain]
    --Domain Computers
            --NT4.0 WorkStations
            --Windows 2000 Pro
            --XP Pro with SP1
            --XP Pro with SP1
    --Domain Controllers
    --Domain Servers
            --Server 2003
            --Server 2000
            --NT4.0 Server
    --Domain Users
            --ISA Users
                    --Accounting
                    --Engineering
                    --Production
                    --Sales
                    --Special ISA User Accounts
            --Special User Accounts
    --Disabled Users

-- 
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com
"TechMasters" <kiosk@comcast.net> wrote in message
news:jggi01dea0q4h7nr58p6p66eu58cbceri3@4ax.com...
>
>
> Thanks, I want to use GPO filtering but is there any performance issue
> assciated with GPO processing from having to do it this way?? (i.e
> does a large group memebership enumerationf of the GPO filter slow
> down its processin?)
>
> On Tue, 8 Feb 2005 15:34:12 -0600, "Steven L Umbach"
> <n9rou@nospam-comcast.net> wrote:
>
> >You could either put the servers in an OU or use "filtering" so that the
> >apply permissions for that GPO only applies to a global group you create
and
> >then put those servers computer accounts into that group. See the link
below
> >for the section on filtering Group Policy.  --- Steve
> >
> >http://support.microsoft.com/default.aspx?scid=kb;en-us;322176
> >
> >"TechMasters" <kiosk@comcast.net> wrote in message
> >news:me3i019ps0avertlubaskjchmfoimc3mm2@4ax.com...
> >>
> >> Hi,
> >> I need to implement a GPO thru my entire domain (one only) which only
> >> applies to servers thou, and not the workstations. Is this possible?
> >> I would like the GPO to be set at the Domain level and apply to
> >> servers only, not anything else....thanks!
> >
>


Relevant Pages

  • Re: Disable everything except for a web site authentication.
    ... Our main issue, once we create domain accounts for partners, how can we stop ... a GPO that automatically takes care of the issue without having to create ... > Sharepoint grants are well administered. ... > all, to internal servers that are necessary: ...
    (microsoft.public.win2000.security)
  • Re: Windows 2008 Network Level Authentication
    ... temporarily block inheritance on all domain-wide GPOs on the OU ... Terminals Servers, properly licensed and set up in a round-robin ... Using either the local GPO and Disabling the Network Level ... Authentication turned completely off, and remain so. ...
    (microsoft.public.windows.terminal_services)
  • Re: Terminal Server GPO Issue
    ... servers that is not in the OU where the GPO is supposed to be applied and I ... Microsoft Windows Operating System Group Policy Result tool v2.0 ... Sharepoint Auth GPO ... Event Log Settings ...
    (microsoft.public.windows.server.active_directory)
  • Re: GP/OU Problem/Question
    ... Create OU & GPO for the TS: ... Right click 'Terminal Servers' OU, ... Ensure that TestUser1 is a member of Domain Users & Remote Desktop ... Make the Security group member of RDU. ...
    (microsoft.public.windows.terminal_services)
  • Re: Loopback Policy Not Taking Effect
    ... Have you rebooted your servers yet? ... Terminal Servers in the OU ... loopback GPO to the "Terminal Servers" OU but to the OU that holds my TS ... ad TS Lockdown Policy and assigned them mostly Computer ...
    (microsoft.public.windows.terminal_services)