Re: Apply User Settings only when using specific Computers




"Dragos CAMARA" <dragos_c@xxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:BC3D8FA4-CDA2-4CEE-AE5E-45D27C4393F2@xxxxxxxxxxxxxxxx

--
Dragos CAMARA
MCSA Windows 2003 server


"Yuppie" wrote:

On Aug 9, 11:40 pm, "Roger Abell [MVP]" <mvpNoS...@xxxxxxx> wrote:
"Yuppie" <xje...@xxxxxxxxx> wrote in message

news:1186680278.340642.95860@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx





So, I am thinking the issue is all in what you mean by "specified
the scope".

Probably.

In a more normal case, one links the loopback GPO to the OU
containing the machines where this should happen.

I believe I have done this. In the GPO Settings on the Scope tab
under Security Filter "The settings in this GPO can only be applied
to
the following groups, users, and computers" I have specified one
machine for testing.

Then when editing the the policy, I have changed Computer
Configuration | Administrative Templates | System/Group Policy | User
Group Policy loopback processing mode (enabled - merge) and specified
a logon script under User Configuration.

Is the the proper way to set up the GPO to accomplish what I set out
to do?

No. The computers that are to process the GPO and so see that it
is a loopback policy, and then also the user accounts that are to
have the GPO processed in loopback for them need to be in the
security group filtering.

Something seems wrong. With only the computer specified in the
Scope,
the script does not run. When "Domain Users" and the computer are
specified, the script runs, but it also runs on computers other than
my test machine.

That part I do not understand. I mean, I do see how that lets the
loopback processing happen for users, but I do not see why that
cause it to apply with other computers (unless someone has
modified the membership of Domain Users). Computer accounts
are in Domain Computers and user accounts in Domain Users, so
adding Domain Users causing other computers to use the GPO
otherwise (than DU membership having been altered) does not
make sense to me.

Roger- Hide quoted text -

- Show quoted text -

I think the problem now is link order and precedence. I recently
discovered creating OU's and putting GPO's in OU's. So my setup is
like this:

Domain:
-Default Domain Policy GPO
-Greenview OU
--Greenview GPO (where script, loopback is set up, etc.)

When logging on to the test machine and running rsop.msc, the
Greenview GPO settings are not applied. The GPO is Enforced, Enabled
and Link Enabled. The Group Policy Inheritance is 1 Default Domain
Policy, 2 Greenview GPO.


it' ok, move the test machine on Greenview OU and run a gpupdate /force.
The
users dosent have to be on Greenview OU

I think poster's issue is not getting it to work on the intended machine,
as it is said all works if Domain Users has grant to read/apply.
Rather, poster's problem is that when there is a Domain Users grant
the GPO gets applied by other machines (or else I read posts wrong).


.



Relevant Pages

  • Re: Applying user object policy (filtering based on computer location)
    ... should have the GPO applied via loopback when logging into ... the computers in NY Desktops OU, ... I have a OU called "NY DESKTOPS" - I created a new policy and enabled Loopback processing mode. ...
    (microsoft.public.win2000.group_policy)
  • RE: Im falling my hairs with this domain gpo problem
    ... Where is the GPO linked? ... Do Authenticated users and Domain Computers have permissions to "Apply ... I'm having problem with a domain policy. ... only local security policy was showed in the gpresult log (for ...
    (Focus-Microsoft)
  • Re: SBS2K Offline File Question
    ... When I rename one group policy, ... > caching for client computers using GPO. ... > all the policy in this folder is related to the offline files. ...
    (microsoft.public.windows.server.sbs)
  • Re: cant override screen saver policy
    ... > Settings in the User Configuration part of a GPO always apply to User ... > users log on to specific computers, then enable Loopback processing in a GPO ... >> don't get this policy setting. ...
    (microsoft.public.win2000.group_policy)
  • FW: Im falling my hairs with this domain gpo problem
    ... Where is the GPO linked? ... Do Authenticated users and Domain Computers have permissions to "Apply ... I'm having problem with a domain policy. ... only local security policy was showed in the gpresult log (for ...
    (Focus-Microsoft)