Re: Need advice: GPO practice for member servers

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Here is an exemple.

We want to control the following rights

Allow logon locally
Allow logon via TS
Deny logon from network
Manage security Log
Backup/Restore files
Take ownership
Shutdown from network

moreover we want to control the local groups like

Administrators
Backup Operators
Power Users

Suppose that I make one basic GPO for all member servers that works as
following:

Allow logon locally = Administrators, Backup Operators

Now application and service accounts that wants to have this privilege
are not working.
Same thing if I assign a restricted group like this:

Administrators=Administrator, Domain Admins

All services that wanted to be here are not working any more.

The problem is that on 100 servers I may have 10 servers with services
that requires local admin rights, other 10 that require the "logon
locally" right, and 10 other that require both of them.

Now think of number of combination that I can have with 100 servers, 8
rights and 3 local groups that I want to control -> a pretty big
number

So, is creating one GPO per server the only possiblity to get job done?
How others manage this nightmare?

.



Relevant Pages

  • Re: Task scheduler generates logon type messages
    ... Logon type 4 is logon as batch job so normally it would be; ... For backup we want to use the ... | If I add this batchfile to the Task Scheduler and assign it the rights ...
    (microsoft.public.windows.server.general)
  • Re: Logon screen gone
    ... One of our windows 2003 servers is having a strange issue. ... screen to logon. ... stops working from this DC to other DC's in the same domain. ... use Tivoli backup software). ...
    (microsoft.public.windows.server.general)
  • Re: Ping Request Time Out sometimes
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... I have 2 vlan the 3 sql servers are on the same vlan, but the backup ... configuration, but if you tell me what configuration could cause this ...
    (microsoft.public.windows.server.networking)
  • Re: Assiging permissions for a group to logon to a domain controll
    ... Windows Settings>Security Settings>Locla Policies>User Rights ... Allow logon through Terminal Services. ... To grant a user these permissions, start either the Active Directory Users ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Issue after establishing a 2-way trust between 2 forests
    ... Best regards ... This posting is provided "AS IS" with no warranties, and confers no rights. ... Thought I'd let you know a new good news, they can logon without ...
    (microsoft.public.windows.server.general)