Re: Security Filtering does not work correctly in GPO



Hi

Did you removed the Authenticated Users from apply GPO

--
I hope that the information above helps you

Good Luck
Jorge Silva
MCSA
Systems Administrator

"Roli79" <Roli79@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5A066C08-E098-4BD7-A889-B42C6C08ADB1@xxxxxxxxxxxxxxxx
Hello there,

i have depoyed the following scenario in my environment.

- I created a Group Policy Object with GPMC SP1 on my W2k3 Server (DC)
- Also i supplied this GPO with a Security Filter so that the settings
just
have
affect to a specific Group. (Group Type: Security Group - Global)

- In this Policy, there are just user settings configured.

- I linked this GOP on the top level in my Active Directory domain,
because
i have
multiple users in different OU's wich belong to the Group, wich is
definded in the
"Scope-Setting" in the Group Policy object. The domain administrator does
not
belong to this group.

As i run the Group Policy result Wizard, a few days later, on a certain
machine, where the domain admin was logged on, i found in the result set,
that GPO with the
Security Scope on the specific group, has applied on the administrator!

How coult this happened. I am a little bit helpless now, because of my
logical understandig. The domain admin shouln't receive this settings.
Normally it sould
only take affect on the adjusted group in the Secuirty Filtering box.

thanks for your help
Roland


.



Relevant Pages

  • Re: I need Ideas on securing a remote Win2k machine
    ... Create the group policy objects and link them to that OU (it will ... click on "Browse" and locate your GPO to edit. ... Just remember that a Group Policy Object gets linked to an Organizational ... > suggests that I need to get the domain admin to do a lot of this. ...
    (microsoft.public.win2000.security)
  • Re: Security Treats
    ... imagine that a malicious user wants to gain domain admin access. ... the administrator unwittingly gives away ... If you have group policy, ... Make sure your workstation accounts reside in an OU (rather than the default ...
    (microsoft.public.win2000.security)
  • Re: Security Filtering does not work correctly in GPO
    ... administrator object for this GPO. ... I deleted the domain admin profile on the ... where the domain admin was logged on. ... I will now keep track on it, if the administrator receices the settings again. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Security Treats
    ... imagine that a malicious user wants to gain domain admin access. ... > somebody logs in and then persuade an administrator to come over and fix ... If you have group policy, ... > workstation admin accounts and place them in the group. ...
    (microsoft.public.win2000.security)
  • Re: Security Treats
    ... When I said "Make sure your workstation accounts reside in an OU", ... imagine that a malicious user wants to gain domain admin access. ... > somebody logs in and then persuade an administrator to come over and fix ... If you have group policy, ...
    (microsoft.public.win2000.security)