![]() |
Group Policy help W2K3 Server
I run a small network of about 30 pc's. I'm currently working on setting up a group policy to affect a specific group of users. Users are setup in active directory (AD) into seperate organizational units (OU).
When i create a new group policy object (GPO) and apply it to an OU, it will not take effect. Only GPO's at the domain level are applied to users, and only if it is applied to authenticated users only. if i remove authenticated users and try to apply it to any specific users or any specific security group, it will not take effect. Any help on this? why can i only set up a GPO that will affect all users on the domain at the domain level? Why cant i set up a GPO that affects either a security group or an OU?. thanks in advance. |
A few things to look at...
GPO settings are defined as Computer or User centric. GPOs with mixed policies (Computer and User) will only apply to the like objects in the OU. Thus, Computer policies won't apply to John Smith in the Marketing OU. You must apply a mixed GPO against the OU(s) which are home to the User and Computer object(s). You may also want to look at the ACL on your new GPO. Some times Windows may lose an ACL you need for the policies to apply. Not sure why but I've seen it happen. Windows Server 2003 has some good tools to do all of this: AD Users & Computers is a start then the Group Policy Admin tool (via MMC) gives you the skinny on settings, ACLs, etc. Don't forget to use the GPRESULT app on the client computer to view which policies are being applied and which are not. |
thanks rubicon. took some playing and tweaking but i got it to finally work properly. now the little bastards cant play games all day. hehe
|
All times are GMT -8. The time now is 07:43 PM. |
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project