Re: Apply Group policy to all domain users but not users in group "a"
- From: "Kerry Brown" <kerry@xxxxxxxxxxxxxxxxxxx*a*m>
- Date: Sat, 17 Sep 2005 06:55:43 -0700
"Mark Heitbrink [MVP]" <spam-only@xxxxxxxxxxxxxxxxxxxxx> wrote in message
news:OJda7T2uFHA.1256@xxxxxxxxxxxxxxxxxxxxxxx
> Hi,
>
> Kerry Brown schrieb:
>> What happens if a member of the tech group is also a member of a group
>> that
>> has read and apply permission? The only way I have been able to do this
>> is
>> with deny which always trumps everything else. Am I doing something
>> wrong?
>
> You are right. But your example works viceversa ...
> What happens if you want to apply the settings and the user
> is a member of a group where you deny it ... ;-)
>
> It´s just a case of how you like to work. I try to work as less
> as possible with deny, because IMHO it is the better way.
> If a User/Group doesn´t even has the permissoin on a Share, NTFs
> or DSACLs, than I don´t have to deny it. I think that makes the
> situation a little bit simpler.
>
> It´s a question of your OU structure in AD and how the default
> inheritance and the scope of your GPO is.
> A lot of OUs prevent you from using "deny", but it makes the
> structure even more complex.
> You have to find your golden mean by yourself ;-)
>
I agree that deny should be use sparingly. I have never had to use it for
file permissions for sharing. Group policy is the only place I've ever had
to use it. Even then it was only in one case where loopback processing was
involved.
Kerry
.
- Follow-Ups:
- Re: Apply Group policy to all domain users but not users in group "a"
- From: Mark Heitbrink [MVP]
- Re: Apply Group policy to all domain users but not users in group "a"
- References:
- Re: Apply Group policy to all domain users but not users in group "a"
- From: Mark Heitbrink [MVP]
- Re: Apply Group policy to all domain users but not users in group "a"
- From: Kerry Brown
- Re: Apply Group policy to all domain users but not users in group "a"
- From: Mark Heitbrink [MVP]
- Re: Apply Group policy to all domain users but not users in group "a"
- Prev by Date: Re: Local Administrators group
- Next by Date: Re: Only "part of a policy" being applied!
- Previous by thread: Re: Apply Group policy to all domain users but not users in group "a"
- Next by thread: Re: Apply Group policy to all domain users but not users in group "a"
- Index(es):
Relevant Pages
|