Re: Clarification Needed



Howdie DJ!

DJ wrote:
My objective is to lockdown desktops for users and expempt domain admins from the policy. My plan was to create 2 GPO's one User Level and one Domain Admin GPO. Configure each one as needed and then link to domain. I did notice that when you create a GPO, it automatically adds authenticated users. Is there any problem removing and in line with the above thinking, add domain users to the User GPO and domain admins to the Domain Admins GPO.

You can alter the NFTS permissions of the Group Policies by accessing the tab "Security" at the properties of the Policy. If a group of users shall not apply/overtake a Group Policy, simple add a "Deny Group Policy" permission to the group...

But be sure to document your steps very well since "messing around" with security permissions - also called "security filtering" is a common trap to fall into, as other administrators might not clearly "see" that you altered the default permissions of this Group Policy.

cheers,

Florian
--
Nachwuschsadmin aus dem Süddeutschen/Germany.
eMail: Vorname [bei] frickelsoft [Punkt] net.
blog: http://www.frickelsoft.net/blog.
.



Relevant Pages

  • Re: Group Policy???
    ... > properties in Group Policy via user configuration/administrative ... See the link below for details on Group Policy ... logging into the TS server or their own workstations, ... You would normally want to exclude the domain admins from ...
    (microsoft.public.win2000.security)
  • Re: Active directory Group Policy (Win2k)
    ... When I enforce the policy onto the computers in the new OU, ... Domain Admins so the Domain Admins cannot view ... workstations, to access Microsoft Office. ...
    (microsoft.public.security)
  • Re: administrator locked out of SBS 2003
    ... The Domain Admins group was a member of ... included in the "Deny log on locally" local security policy settings. ... Select "All users except local administrators" ... That allowed the installation of VMware server to complete. ...
    (microsoft.public.windows.server.sbs)
  • GPO for one machine
    ... I have one machine setup with Terminal Server. ... domain admins security box is set not to apply group policy. ... Download a FREE whitepaper on Security Policy Automation for Web Applications. ...
    (Focus-Microsoft)
  • Re: Access to stop/start services.
    ... These permissions are only exposed in Group Policy. ... Open the Active Directory Users and Computers snap-in. ... Grant the System account and Domain Admins Full Control. ...
    (microsoft.public.windows.server.general)

Loading