Re: RE: loopback group policy



Hi,

First of all, just so you know. GPO's don't apply to Groups or members of
Groups. Groups can be used for Security Filtering only however, I don't even
use them for that. It doesn't matter where in AD you put the Groups, it only
matters where you put the computers and the users.

Basically GPO's are Cumulative with the one "Closest" to the User winning in
the case of a conflict. The exception is the Loopback because if set to
"replace" then it replaces all the Users GPO Settings. If set to "Merge" it
merges the settings on the Computer GPO (in Users section) with the Users GPO
settings BUT if in case of a conflict the Computer GPO wins out. (This is
all explicit in the Help Section of the Loopback GPO)

For your case, I would create a GPO for Department 1 OU and link it to
Department 2 OU as well (same GPO). I would call this GPO "Loopback" and the
only setting would be the Loopback = Enabled = Merge.

I would then create a Workstation1 GPO and a separate Workstation2 GPO. In
these GPO's I would instruct the Admins of the departments to make any
Computer Conf settings in the Computer Config and any Users Settings (to
apply specifically to their department computers) in the Users Config.
Because the "Loopback" GPO is above the Workstation1 and the Workstation2
GPO's then it will still affect any workstations below it.

In this case when users logon to workstations in the Workstation1 GPO then
they will get their Users Settings (set on User OU) merged with any settings
in the User Config of the Workstation1 GPO that your department heads set.

Cheers,

Lara

"twospoons" wrote:

> yes, i know where to turn on loopback processing in terms of a single
> gpo... what i'm asking is concerning the processing
> order/inheiritance of gpo's when configured in loopback mode from
> multiple OU's... and what if the OU's are not nested?
>
> say a user from a top level OU logs into a workstation in a seperate
> OU's (department) nested OU (workstation)
>
> domain
> - Users_OU
> - Department1_OU
> ---- Workstations1_OU
> ---- Groups1_OU
> - Department2_OU
> ---- Workstations2_OU
> ---- Groups2_OU
>
> how would loopback work if there is a gpo applied to the Users_OU,
> Department1_OU and the Workstations1_OU... and a different gpo
> applied to the workstations in department two? which of these gpo's
> would you turn loopback on? what order would the gpo's be applied?
>
> what i'm wanting to accomplish is to have a global gpo configured for
> all users... then i want each department manager to have access to
> apply gpo's to their own groups and workstations. is loopback policy
> even the best way to do this? what steps do i need to take to ensure
> that the departmental gpo's comply with the global gpo's from the
> User's OU?
>
> thanks
>
>
.



Relevant Pages

  • Re: GPO problems
    ... OK I understand Loopback, I don't think it will help. ... I have a Terminal Server user within his own seperate OU ... with his own GPO assigned to it. ... therefore no conflicting GPO settings. ...
    (microsoft.public.windows.group_policy)
  • Re: Getting desperate: GPO applying incorrectly, PLEASE HELP ME!!
    ... all the settings for lockdown in it. ... I think you are on to something with the linking of the GPO. ... > OU to which the loopback GPO is linked, ... > OU you placed the TS server, and you set loopback on in replace ...
    (microsoft.public.windows.group_policy)
  • Re: Group Policy - Terminal Server
    ... There is a GPO linked to this OU called ... This contains some not-so-restrictive settings. ... I also have a 'TerminalServer' OU. ... It's like the loopback processing is not happening. ...
    (microsoft.public.windows.group_policy)
  • Mulitiple Loopback GPOs and one OU
    ... of the two loopback policies applied to its corresponding OU, ... other GPO will disable this setting. ... policy settings within that GPO. ... Computer settings from the higher priority policy, ...
    (microsoft.public.windows.group_policy)
  • RE: Propagating the Pop-Up Blocker List
    ... Under XP SP2, you can add to the allow list for the built- ... I have found this option within the GPO ... How do you get these settings into the GPO Policy on the ... server so that they are pushed to the workstations. ...
    (microsoft.public.win2000.group_policy)