GPO Management Delegation



Hello,
I have what I consider an interesting and frustrating problem. I have
attempted to grant some non domain admin users that are OU admins the ability
to create and link GPOs in the OU they administer. I have followed the
procedure outlined by Microsoft. I.E. I have added the Security Group they
belong to to the "Group Policy Creator/Owners group" I have also added them
to the delegation tab for Group Policy object creation in our domain and I
have granted them the right to link GPOs in GPMC. When you right click on
the OU they administer and attempt to Create & Link a new GPO, it is not
grayed out and it will ask for the name of the new GPO. But, once you name it
and click "OK", it will then give an "Access Denied" error. If this is
attempted on any other OU, the GPO actions are grayed out. I have
reasearched and double checked everything but it does not work and I cannot
find anything that sticks out as being wrong. It is almost as if the
permissions are "halfway" in place. Any thoughts, ideas or suggestions would
be greatly appreciated.

Thank you!
.



Relevant Pages

  • Re: GPO Management Delegation
    ... to create and link GPOs in the OU they administer. ... to the delegation tab for Group Policy object creation in our domain and I ... grayed out and it will ask for the name of the new GPO. ...
    (microsoft.public.windows.server.active_directory)
  • Re: GPO Management Delegation
    ... to create and link GPOs in the OU they administer. ... belong to to the "Group Policy Creator/Owners group" I have also added ... grayed out and it will ask for the name of the new GPO. ...
    (microsoft.public.windows.server.active_directory)
  • Re: GPO Management Delegation
    ... Have you verified that the group you designated has Write permissions on the ... to create and link GPOs in the OU they administer. ... to the delegation tab for Group Policy object creation in our domain and I ... grayed out and it will ask for the name of the new GPO. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Using Group Policy to give install permission
    ... Group Policy is simply (well, ... Active Directory there is only one Organizational Unit: ... Your user account objects or computer account objects must directly reside ... in the Organizational Unit to which you linked the GPO. ...
    (microsoft.public.win2000.group_policy)
  • Re: Terminal Server GPO Issue
    ... The name of the OU where the GPOs should not be applied is: Citrix XP ... They both sit at the same level under an OU called Servers. ... Microsoft Windows Operating System Group Policy Result tool v2.0 ... Sharepoint Auth GPO ...
    (microsoft.public.windows.server.active_directory)

Loading