Re: Loopback GPO filtered to specific workstations.

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Using security group filtering with a group defining the machines that
should use this loopback policy does cause those machines to see in
the computer policies that they should use this policy for loopback
processing. What you have done to this point is fine.
But, then no user account ever pass the security group filtering and
so the loopback processing is never invoked.
You need to filter on both the machines that should do the loopback
processing with this GPO and the user accounts that should be subject
to the settings via the loopback processing.

"David Gould" <DavidGould@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:AB83B0A9-A085-497F-9468-20F958ED8B7D@xxxxxxxxxxxxxxxx
Hi

I've been trying to get a loopback policy to work, but been struggling...

I've an OU that contains all workstations. I've created a GPO (linked to
the
OU) that contains a user configuration setting to disable the screen saver
with the loopback merge setting.

I've removed the 'Authenticated Users' groups and created a GPO filter
group
and added a couple of test machines to it. The idea being that if a user
logs
on to one of the test machines the screen saver is disabled - regardless
of
any screen saver settings applied to the user.

Problem is that it only appears to work (i.e. the machine screensaver
settings are applied) if I don't use the filter group, and leave it with
'Authenticated Users'.

Can someone tell me if a loopback GPO can be filtered, or provide any
suggestions as to what I might be doing wrong?

Appreciate any ideas.

Best Wishes
David.


.



Relevant Pages

  • Re: Im having an issue with the "user group loopback processing m
    ... The problem was that i had a GPO with loopback set and security ... filter had authenticate users. ... computers i want to stop the screen saver on and created another GPO. ... Y also had loopback applied and was link to that OU. ...
    (microsoft.public.windows.group_policy)
  • Re: panics on 24 hour boundaries
    ... and he said they make heavy use of INET6 so they could not take it out. ... >It could be any large device on the same electric circuits you are ... >connected to the computer is not also on the same filter those ... >maintained many machines with serial terminal] terminals and also ...
    (freebsd-stable)
  • Re: ZoneAlarm log shows probes *from* 127.0.0.1 ?
    ... Generally with this type of thing you will get more hits from more localized ... same time that one of these infected machines is. ... Without the loopback address as trusted this is what one would expect. ... were forced to put the loopback address in the trusted zone for something ...
    (comp.security.firewalls)
  • Re: Loopback policies - Domain admins ??
    ... loopback, is because the whole idea of loopback is so the ... >> You have to filter the scope of Group Policy according ... security group through ... >> which you want to filter this Group Policy object. ...
    (microsoft.public.win2000.group_policy)
  • Re: Access 2007 filtering issue
    ... The earlier Access 2007 machines *do* still have the ... All I've done is distribute the converted frontend (converted from '97 to ... changes to the "Filter On Load" property setting in Access 2007? ...
    (microsoft.public.access.modulesdaovba)