Re: Locking down a TS

Tech-Archive recommends: Fix windows errors by optimizing your registry



Not a problem - yes it is really as easy as that - add the group of uses who you don't want the policy to apply to to the ACL of the group policy object and deny them apply. When members of that group login they will not apply the policy.

This URL (although based on Windows 2003) is still relevant to what you want to achieve - it's Microsoft's step-by-step:

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/directory/activedirectory/stepbystep/gpfeat.mspx

Open the page and do a search for the section "To deny GPO application to members of the Management group"

Hope this helps you

Best Regards

Jon Wallace
AppSense - http://www.appsense.com

-----


MLL wrote:
Jon:

I have read several articles on loop back processing, and it looks like this is exactly what I need in this situation.

Could you expound on denying the application of the policy to the relavant groups? Is this as simple as adding the group in the security tab of the GPO and checking the "deny" box next to the "apply group policy" permission? If you known of any documantation on this procedure, that would br great to have as well.

Thanks again,
.



Relevant Pages

  • Re: hiding contacts from directory search (LDAP)
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... policy and denying that right on the policy. ... the majority that I want to deny makes up about 80-90%. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Loopback Processing and Deny Apply in ACL
    ... The actual group policy is being applied to the user logon, ... If you Apply the policy to a user then Deny ... >> for the terminal server (which is in it's own OU, ... >> setting the deny apply gpo setting in the acl to the user account of this ...
    (microsoft.public.win2000.group_policy)
  • Re: Linux IPChains Question
    ... At the moment I haven't set NAT up, ... ipchains -P forward DENY ... >>I suggest adding an explicit DENY and log rule at the end. ... With iptables, if you set the forwarding policy to drop, you ...
    (comp.security.firewalls)
  • Re: cannot logon locally
    ... For a machine in a domain use a GPO that will apply ... >>equivalent) and then set a deny of full control for the ... >>local policy to remove the obstructing setting. ... >>> not let me logon locally. ...
    (microsoft.public.windows.group_policy)
  • Re: Applying GPO only to certain computers within an OU...........
    ... Don't forget that deny permissions take precedence over allows. ... I think if you remove the authenticated users grou0p from the acl, ... add in the security group "Yes Software" or whatever (the computers that are ... supposed to get the policy) and give them Read & Apply GPO permissions. ...
    (microsoft.public.win2000.group_policy)