RE: Local group policies vs. domain group policies



Hi Jeff,

Then I disconnect from the domain and reboot the computer. On my
computer,
my local group policy has a setting to allow me to view the Control Panel
("Prohibit access to the Control Panel" is Disabled). Will I be able to
see
the Control Panel when I log in locally?

If you log on locally then you will be able to see the control panel, even
if you are connected to the domain. This is because the User Settings GPOs
in the domain will not apply to local accounts. If you are logging in with
a domain account while disconnected from the domain then yes the GPO will
still apply as it is cached locally on the workstation.

Also, what if the domain policy is configured to Enabled but my local
policy
is set to Not Configured?

The setting is enabled for domain accounts. Local accounts on the machine
will not be affected if this is part of the User Settings in Group Policy
as this will not apply to local users.

In other words, do domain GPOs remain on the computer when the computer is
not connected to the domain or do the local GPOs get reapplied upon every
boot?

Domain GPOs are cached locally on the machine and will continue to apply
when disconnected from the network. Naturally any GPOs that rely on a
resouce on the network such as Software installation will fail when off the
network.

Hope this helps,

Brian Delaney
Microsoft Canada
--

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
Thread-Topic: Local group policies vs. domain group policies
thread-index: AcbG+KN0BXiExQb1ThipzxQtpdt0aQ==
X-WBNR-Posting-Host: 209.105.253.133
From: =?Utf-8?B?amhhcmRlZQ==?= <jhardee@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: Local group policies vs. domain group policies
Date: Wed, 23 Aug 2006 14:11:02 -0700

Let's say I have a computer on the domain and there is a domain policy set
to
not allow me to view the Control Panel ("Prohibit access to the Control
Panel" is Enabled). I log into the domain, the policy gets applied, and I
can't view the Control Panel as designed.

Then I disconnect from the domain and reboot the computer. On my
computer,
my local group policy has a setting to allow me to view the Control Panel
("Prohibit access to the Control Panel" is Disabled). Will I be able to
see
the Control Panel when I log in locally?

Also, what if the domain policy is configured to Enabled but my local
policy
is set to Not Configured?

In other words, do domain GPOs remain on the computer when the computer is
not connected to the domain or do the local GPOs get reapplied upon every
boot? I understand the precedence of GPOs, but not what "sticks around".

Thanks,
Jeff


.



Relevant Pages

  • Re: Restrictions error when logged on as an administrator
    ... > not access any Control Panel nor Properites under My Computer. ... > computer and it shows my userid as part of the Adminstrators ... There may be a domain policy that is being ...
    (microsoft.public.win2000.security)
  • GPO
    ... In a default domain policy, ... users cannot view control panel, but when users log on, it doesn't work, ... For other and, only administrators can add local printers, for normal users, ...
    (microsoft.public.windows.server.sbs)
  • Re: Missing Screen Saver Tab
    ... You'll need admin access to the domain and check the default domain policy. ... Edit the policy and look for User Configuration -> Administrative ... Templates -> Control Panel -> Display ...
    (microsoft.public.windowsxp.general)
  • Re: user accounts not displayed in local groups and user accounts utility in admin tools
    ... in the control panel. ... Are they local accounts? ... Shenan Stanley ...
    (microsoft.public.windowsxp.general)