Re: Group policy to apply only to some workstations
- From: "Dave Nickason [SBS MVP]" <gwdibble@xxxxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 22 Apr 2008 14:24:52 -0400
Another alternative is to leave the computers where they are, link the relevant GPO to that OU, and use security filtering to apply it only to the relevant client PCs. By default, GPOs are applied to "Authenticated Users," a security group that includes domain computers. What you'd do is to create your own security group containing the factory PCs, add it to the security for the GPO, and remove Authenticated Users. Offhand, I can't think of a reason why one or the other option would be preferable - security filtering is just another option.
"Lanwench [MVP - Exchange]" <lanwench@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:OIRScTKpIHA.1164@xxxxxxxxxxxxxxxxxxxxxxx
Gregg Hill <bogus@xxxxxxxxxxx> wrote:Hello!
I want to create a group policy to lock down a client's computers in
the factory, but not the ones in the office. I have a lock-down GPO
for terminal servers that works perfectly, but it is in an OU outside
of the normal SBS OU structure, i.e., it is directly under the
office.lan domain in ADUC.
I want all normal SBS GPO settings for "SBSComputers" to apply to
these workstations, and add the restricted GPO settings. I am
thinking that I can create a sub-container(?)
An OU (not a sub-anything)
such as "MyBusiness >
Computers > SBSComputers > Restricted Computers" and move the desired
computers to that sub-container.
Put it under MyBusiness\Computers, not under SBSComputers.
Note that any computer (not user) specific GPO settings applied at a higher level (e.g., the domain or MyBusiness or Computers will be applied.
Remember to always create your own GPOs - don't edit the defaults - and be very careful with what you do. You may want to implement loopback processing in the Restricted Computers GPO. Test first!
Am I even close to being on the right track? If not, would someone be
so kind as to throw the switch for me?
Thank you!
Gregg Hill
.
- References:
- Group policy to apply only to some workstations
- From: Gregg Hill
- Re: Group policy to apply only to some workstations
- From: Lanwench [MVP - Exchange]
- Group policy to apply only to some workstations
- Prev by Date: Re: Group policy to apply only to some workstations
- Next by Date: Re: SBS 2003 Premium License Transfer
- Previous by thread: Re: Group policy to apply only to some workstations
- Next by thread: Re: Group policy to apply only to some workstations
- Index(es):
Relevant Pages
|
Loading