Re: GPO



When a computer is booting, it goes through a stage of applying policy.
When this finishes you are left with the logon screen. Logging on does this
again, but this time using the context of the user who is logging on, not
the computer.

At both points the GPO CSE (Client Side Extensions) make a call to a DC to
find their location and then see if there are any GPOs within scope. If
there are, the permissions are checked and if they have the necessary
permissions application starts.

If the computer is not part of a domain, it is unable to locate a DC (as it
has no need to) and therefore doesn't apply any policy other than the local
one.

The "handing out" of IP information is done by DHCP, which is much lower in
the ISO model and has no idea of what Windows is. DHCP has nothing to do
with GPO. Although a domain machine that doesn't pick up a valid DHCP
address will use an APIPA address and then not be able to locate a DC and
thus not apply GPO (among other things).

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


.



Relevant Pages

  • Re: GPO no longer being applied to user
    ... and/or Default Domain Controller group policies, you can enable GPO debug ... logging on your server. ... RunDiagnosticLoggingGroupPolicy. ... REG_DWORD with value 1 will turn on verbose logging specifically for GPO ...
    (microsoft.public.win2000.active_directory)
  • Re: GPO no longer being applied to user
    ... > and/or Default Domain Controller group policies, you can enable GPO debug ... > logging on your server. ... Enable Verbose logging by editing the registry. ... >> Thank you, Jack ...
    (microsoft.public.win2000.active_directory)
  • Re: Windoze GPO Question
    ... Some GPO settings remain persistent even ... And logging in with a local account is a bad idea; ... This may be slightly off topic, but I have a question about GPO scope. ... I have a client that has a bunch of sales people who have laptops. ...
    (Security-Basics)
  • Re: DHCP option "135 Domain Suffix Search Order" is missing
    ... I'll implement the GPO ... "Mike" wrote: ... and got no solution on how to do this on DHCP. ... I have a large organizations with about 50 DHPC server in many ...
    (microsoft.public.windows.server.general)
  • Re: Login Script
    ... With LGPO is much more complex ... ... logging in all the time. ... And the network will be scrapped as we are building ... Forget about all possibilities of centralized Management wit AD and GPO. ...
    (microsoft.public.windows.group_policy)