Re: Controlling User Policy via Computer account
- From: "Warner@xxxxxxxxxxxxxxxx" <Warnernospampostalias@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 5 Apr 2005 09:37:03 -0700
That sounds good, except that the policy I want to utilize is the
screensaver. For HIPAA security we need to force a screensaver out to all
networked PCs, but there are a few exceptions. I was trying to avoid
creating multiple OUs to resolve this.
Unfortunately the screensaver is a user policy and not a computer policy and
therefore it looks like we can not control it based on the computer with just
a GPO and security groups.
Any other thoughts? Thanks for your help.
Warner.
"Roger Abell" wrote:
> oops - I had a major lapse there
> You do not need a subOU.
> Since loopback processing is a machine policy you could
> link the new loopback GPO on the original OU and use
> security group processing so that it will apply to the
> group of machines on which it should have an effect and
> on the users for which it should be effective, after removing
> the read/apply for Authenticated Users.
>
> --
> Roger Abell
> Microsoft MVP (Windows Security)
> MCSE (W2k3,W2k,Nt4) MCDBA
> "Roger Abell" <mvpNOSpam@xxxxxxx> wrote in message
> news:u2FtzEfOFHA.624@xxxxxxxxxxxxxxxxxxxxxxx
> > I see no way to do precisely that, at least not without
> > OU restructure. If you would define a new subOU and
> > move all machines except the exempt ones into the new
> > subOU, and then link a GPO set to use loopback processing
> > on the new subOU then you could effect the objective with
> > minimum restructure/redef of existing OUs and GPOs.
> >
> > --
> > Roger Abell
> > Microsoft MVP (Windows Security)
> > MCSE (W2k3,W2k,Nt4) MCDBA
> > "Warner@xxxxxxxxxxxxxxxx"
> <Warnernospampostalias@xxxxxxxxxxxxxxxxxxxxxxxxx>
> > wrote in message
> news:325DB1CD-5157-42B7-9EC4-46AAC125734D@xxxxxxxxxxxxxxxx
> > > Is is possible to Apply a User Policy only if the Computer account is a
> > > member of a security group?
> > > I have a user policy that I want applied to all computers except a few.
> I
> > > would like to control this based on a security group rather than an OU.
> > Is
> > > this possible?
> > >
> > > Thanks,
> > > Warner.
> >
> >
>
>
>
.
- Follow-Ups:
- Re: Controlling User Policy via Computer account
- From: Roger Abell
- Re: Controlling User Policy via Computer account
- References:
- Controlling User Policy via Computer account
- From: Warner@nospam.postalias
- Re: Controlling User Policy via Computer account
- From: Roger Abell
- Re: Controlling User Policy via Computer account
- From: Roger Abell
- Controlling User Policy via Computer account
- Prev by Date: Re: Changing default computer OU
- Next by Date: disabling effects with AD group policy ?
- Previous by thread: Re: Controlling User Policy via Computer account
- Next by thread: Re: Controlling User Policy via Computer account
- Index(es):
Relevant Pages
|