Re: Block inheritance ?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



You could try to block inheritance at the Department OU as you did, but then
set the Default Domain Policy to "Override" or "Enforce" (the name depends
on the version of Active Directory you are running). That will override any
place where inheritance has been broken. This might be one approach to
consider.

You could also consider using a group to control permissions to the group
policy.
Create a group in Active Directory. Add the computer objects in the
Computers OU to this new group. Do not add any of the computer objects from
your Department OUs.
Now go to the security tab of the GPO. Add your new group in the Access
Control List and set the "Apply Group Policy" permission for the group.
You'll want uncheck the "Apply Group Policy" for any objects outside of the
Computers OU.

I made a screenshot for you:
http://img295.imageshack.us/img295/3746/18369284mo3.jpg

I hope this helps.

--
Ken Aldrich
DSRAZOR for Windows
Visual Click Software, Inc.
www.visualclick.com

"Mark Bohlsen" <mbohlsen@xxxxxxxx> wrote in message
news:AAE4EB5A-61E7-4155-839D-0D852AFD3FEB@xxxxxxxxxxxxxxxx
Is there a way to block inheritance of a specific group policy at the OU
level? It appears to me that if one chooses to block inheritance of a GP
at an OU level it also blocks the default domain policy. My situation is
the following:

Computers OU---default OU policy and WSUS policy applied at this level
------>Dept OU --inherits both GP's. I want to block the WSUS policy at
this level because we are slowly migrating to another patch management
solution.

Any help would be much appreciated.


.



Relevant Pages

  • Re: Default user registry settings
    ... Well it depends whether you're part of an Active Directory network or not. ... If you are then computers can have policies set as a group, ... > create a policy... ...
    (microsoft.public.win2000.registry)
  • Re: 3rd Party -> Group Policy Editors and Import policies "on the fly"?
    ... For security policy ... only you can import templates that you create into other computers using ... Again, no active directory, and I will not ... I've tried to learn the policy template format but I simply dont get ...
    (microsoft.public.win2000.group_policy)
  • After upgrade win2000 server to 2003
    ... Active Directory users en computers, ... 2.if i go to local policy from start menu en then for exmple chose acount ...
    (microsoft.public.win2000.general)
  • Applying a policy to a group
    ... Create an Organisational Unit in Active Directory Users and Groups ... Computers and click the Group Policy Tab. ...
    (microsoft.public.win2000.active_directory)
  • Re: Reinstall everytime assigned applications through GPO on start
    ... Software installation extension has been called for background policy refresh ... Stations - R&D Software (EMEA computers). ... Stations - R&D Software (EMEA computers) is set for installation because it ... The assignment of application Remote Administrator v2.1 from policy Software ...
    (microsoft.public.windows.group_policy)