Re: DC & Local policy

Tech-Archive recommends: Speed Up your PC by fixing your registry



Default Domain Policy, which is linked to the domain object and affects all
users and computers in the domain where Default Domain Controllers Policy,
which is linked to the Domain Controllers OU. his policy generally affects
only domain controllers, because by default, computer accounts for domain
controllers are kept in the Domain Controllers OU.

I am confused, I actually apply some of the user rights on Domain controller
policy as per audit requirement. eg access this computer from network :
authenticated user.
for this case , should i apply it in DC policy or domain policy ?


"Meinolf Weber [MVP-DS]" wrote:

Hello DD,

Servers do not login to a domain, users will do. If you have domain member
servers, the local policy will be overwritten from the Site, Domain or OU
policies.

See also here:
http://technet.microsoft.com/en-us/library/cc778890.aspx

http://articles.techrepublic.com.com/5100-10878_11-1055139.html

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


I have member server login to DC, how to verify the member server are
using the local or DC policy when i login the member server to DC ?




.



Relevant Pages

  • Re: Default Domain password policy issue
    ... The domain controllers are members of authenticated users. ... as for applied Group Policy objects for computer settings. ... Policy replication/version problems. ... The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.windows.group_policy)
  • Re: revert to default domain policy
    ... There are many changes in the default domain policy, ... may be causing problems with my servers. ... I want to revert to the default policy, ... controller policy policys to the domain controllers, ...
    (microsoft.public.windows.group_policy)
  • Re: Blocking port scans on local network
    ... You can implement enumeration of SAM accounts and shares with probably no ... on domain controllers via Domain Controller Security Policy depending of ... domain computer that has a "require" ipsec policy assigned to it. ... between domain computers and domain controllers as the domain controllers ...
    (microsoft.public.win2000.security)
  • RE: Account Lockout Policy
    ... he didn't say that the policy would be *linked* at ... the Domain Controllers OU, just that the domain password policy would apply ... the Domain Controllers OU will still use the password policy that is defined ... they still utilize the domain-level account settings, because, again, the ...
    (Focus-Microsoft)
  • Re: Blocking port scans on local network
    ... > additional restrictions for anonymous connections in this security guide. ... > do not recommend applying ipsec policy wide scale without some testing of ... > between domain computers and domain controllers as the domain controllers ...
    (microsoft.public.win2000.security)