Deny "Apply" right not denying computer config settings
i setting group policy apply pair of windows 2003 terminal servers on server 2008 domain. the 2 servers in own ou, "terminal servers", , in own security group, called "terminal servers". i have few policies on domain: default domain, default domain controller, , policy "ts policy". the policy applied terminal servers security group domain users, authenticated users, plus system , enterprise domain controllers have rights on this.
the policy works ok, has user group policy loopback mode set replace, , setting roaming profile on file server redirecting folders separate root folder on same file server. that seems work although haven't gone through enough testing take live yet.
i keep these applying administrator account. i have set "apply group policy" right "deny" administrator. however, in practice policy still applying partially. i confirmed using group policy modeling: user config portion of policy (redirected folders) coming through denied. the computer config portion (profile redirection) listed applied.
this isn't show stopper, i'm not understanding , have learned hard way wary of that. i thought whole gp not apply administrator. why half of being denied?
because set "deny" on user object , prevent user settings being applied.
the computer settings independend user , still apply.
to microsoft words: "this design"
therefore in ts loopback policy i'd try set policies in "user configuration" whenever possible.
thus can avoid issue facing.
in case not sure mean "profile redirection" in "computer config portion" because folder redirection settings
part of "user configuration". anyway, policies are available in both sections and if so, follow recommendation above.
if available in "computer configuration" settings apply machine , every user (including admins) logs on
is affected indirectly machine policy.
hope makes clear how works...
a article on ts , admins issue one:
http://www.frickelsoft.net/blog/?p=63
patrick
the computer settings independend user , still apply.
to microsoft words: "this design"
therefore in ts loopback policy i'd try set policies in "user configuration" whenever possible.
thus can avoid issue facing.
in case not sure mean "profile redirection" in "computer config portion" because folder redirection settings
part of "user configuration". anyway, policies are available in both sections and if so, follow recommendation above.
if available in "computer configuration" settings apply machine , every user (including admins) logs on
is affected indirectly machine policy.
hope makes clear how works...
a article on ts , admins issue one:
http://www.frickelsoft.net/blog/?p=63
patrick
Windows Server > Group Policy
Comments
Post a Comment