Re: local gp v's domain based gp
- From: "Roger Abell [MVP]" <mvpNoSpam@xxxxxxx>
- Date: Mon, 28 Aug 2006 12:20:09 -0700
<joshua.morgan@xxxxxxxxx> wrote in message
news:1156755102.716765.322500@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Would this then mean that if for whatever reason a
OU/domain/site-linked GPO isn't applied that the local computer policy
would be enforced?
When I stated
that means local policy cannot be "enforced".. . . and then finally, at lowest priority (and not able to block
anything from above) the Local policy.
I.e. I am just pointing out that "enforced" is a term loaded with
special meaning for AD GP processing, whereas I think your
comment could have used "effective" and still carry your intent.
"Enforced", which may be set for a domain or OU linked GPO
means that no lower priority AD based GPO can change what
is set in the enforced policy.
To your question, local policy would be effective only if the AD
based policies had never been seen/downloaded to the machine.
Else, current, and lacking ability to obtain that, most recently seen
would be effective.
For example, if a user logged in and pulled the network cable out
during the Group Policy-applying stage (meaning that an
OU/domain/site-linked GPO doesn't apply) would the local policy then be
enforced, and if an OU/domain/site-linked GPO *does* apply then the
local policy isn't enforced?
Thanks,
Joshua Morgan
Roger Abell [MVP] wrote:
Setting is the local policy have the lowest priority and would only take
effect if there were no conflicts with GPO based settings.
The order of priority, not considering use of "no override"/"enforced" or
of "blocked inheritance", is GPOs linked to the Site, Domain, OU, nearer
nested OUs and then finally, at lowest priority (and not able to block
anything from above) the Local policy.
"Gunna" <gunna@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:%23tFnd3NyGHA.2300@xxxxxxxxxxxxxxxxxxxxxxx
I have a XP machine that has its default local policy set after being
built.
I have added this to a domain which I use group policies to sewt
various
options etc. How do these 2 react when the settings on the local
policy
and
the matching setting on the domain gp conflict? Which get priority or
is
there a way I can set this?
.
- Follow-Ups:
- Re: local gp v's domain based gp
- From: joshua . morgan
- Re: local gp v's domain based gp
- References:
- local gp v's domain based gp
- From: Gunna
- Re: local gp v's domain based gp
- From: Roger Abell [MVP]
- Re: local gp v's domain based gp
- From: joshua . morgan
- local gp v's domain based gp
- Prev by Date: Re: Logon Script Not Running
- Next by Date: Re: Workgroup
- Previous by thread: Re: local gp v's domain based gp
- Next by thread: Re: local gp v's domain based gp
- Index(es):
Relevant Pages
|