Re: Security Filtering does not work correctly in GPO



Hi Paul,

you mean, that i should add the admin to the GPO and set a deny on the
administrator object for this GPO.

I have learnd that you sould be careful with deny permissions. Normally you
sould not add a specific object to something, what the object should not do,
or would be applied on the object.

here is a quick schema, how the AD structure looks like...
/[mydomain.com]
|
|>>User Group Policy [Linked GPO with security filter on the Group "User
Group"]
|
+-domain conrollers [inheritance allowed]
|
|
+-OU-Server [inheritance allowed]
| |
| |
| +-Memberserver [computer object]
|
|
+-Users [Contaier Object]
|
|
+-Administrator [User Object]


But today i tried another thing. I deleted the domain admin profile on the
Memberserver, where the domain admin was logged on. After a new logon, with
a new crated profile, the settings in the "User Group Policy" were gone.

I will now keep track on it, if the administrator receices the settings again.

regards
Roland


"Paul Bergson" wrote:

I am not sure how you set this up but set the doman admin to deny on apply
policy, this should prevent it from being applied.

--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no rights.

"Roli79" <Roli79@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5A066C08-E098-4BD7-A889-B42C6C08ADB1@xxxxxxxxxxxxxxxx
Hello there,

i have depoyed the following scenario in my environment.

- I created a Group Policy Object with GPMC SP1 on my W2k3 Server (DC)
- Also i supplied this GPO with a Security Filter so that the settings
just
have
affect to a specific Group. (Group Type: Security Group - Global)

- In this Policy, there are just user settings configured.

- I linked this GOP on the top level in my Active Directory domain,
because
i have
multiple users in different OU's wich belong to the Group, wich is
definded in the
"Scope-Setting" in the Group Policy object. The domain administrator does
not
belong to this group.

As i run the Group Policy result Wizard, a few days later, on a certain
machine, where the domain admin was logged on, i found in the result set,
that GPO with the
Security Scope on the specific group, has applied on the administrator!

How coult this happened. I am a little bit helpless now, because of my
logical understandig. The domain admin shouln't receive this settings.
Normally it sould
only take affect on the adjusted group in the Secuirty Filtering box.

thanks for your help
Roland



.



Relevant Pages

  • Re: Need limited domain admin rights user account.
    ... Are you saying there to create a custom group that would be ... > or how to give most of the permissions that a Domain Admin would have. ... > folders, can't change Administrator passwords, here is what you would ...
    (microsoft.public.windows.server.security)
  • Re: Security Filtering does not work correctly in GPO
    ... Did you removed the Authenticated Users from apply GPO ... Systems Administrator ... "Scope-Setting" in the Group Policy object. ... The domain admin shouln't receive this settings. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ACL on GPO link
    ... prevent them from unlinking your GPO. ... The gpLink attribute is monolithic in that each link ... A person who can manage links everywhere is aswell an admin ... ... I conclude that you cannot prevent an AD administrator from ...
    (microsoft.public.windows.group_policy)
  • Re: Applications/programs that require admin rights
    ... True I was always a fan of adding them to local admin group and removing once ... from the server using active directory to make her an administrator and ... you need to be Domain Admin to install software on a laptop?? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Need to filter domain admin from GPO
    ... It's best practice to use a 2nd administrator account as your regular user ... domain admin. ... Block inheritance (I would have to move the domain admin from Users ...
    (microsoft.public.windows.group_policy)