Group Policy Security Filtering - Windows 2008 R2 64bit


i'm having issue group policies window server 2008 domain - we're linking gpo contains user , computer configurations ou contains computers (terminal servers).

we're trying apply security filtering on gpo specific group of users only, when test filtering usergroup gpo not applied. if use security group "authenticated users" user , computer policy gets applied users logged terminal server. same exact test works in our windows 2003 domain setup.

we created basic test policy break issue down. enabled loopback processing , disabled access taskbar under user config. verified user navigate specific test policy on sysvol folder , under delegations tab had proper permissions.
way can work place "authenticated users" group or computer/server account under security filtering scope. seems applying if computer account (which beneath ou) defined in security filtering.

- additional testing created second ou , linked simple gpo change background, did not work using user group security filtering.
-we tried using 2 types of servers, virtual/physical windows 2k8 r2 , 1 windows 2003 sp2 server
-we found http://www.grouppolicy.biz/resources/hotfixes/ have higher version of dll mentioned in these hotfixes

update:

we took loopback processing out of picture , applied computer policy disable windows updates , unless place computer or "authenticated users" in security filtering windows update policy never gets applied. clear server underneath
the ou hosting policy.

the ultimate goal apply user policy specific set of users ("test group") using security filtering , not placing users under ou hosting policy.

 

hi nobletrade,

 

thanks posting.

 

from description, understand hope apply user policy specific set of users using security filtering , not placing users under ou hosting policy.

 

first, suggest read articles below:

 

security filtering using gpmc

http://technet.microsoft.com/en-us/library/cc781988(v=ws.10).aspx

filter using security groups

http://technet.microsoft.com/en-us/library/cc779291(v=ws.10).aspx

 

as can see in article: settings in gpo apply users , computers contained in domain, organizational unit, or organizational units gpo linked, , specified in, or members of group specified in security filtering. 

 

this means gpo cannot apply user if user not in ou gpo linked with.

 

the gpo apply user objects in ou meet criteria of gpo (i.e. group filter used).

 

to achieve goal, suggest add servers , user group in security filtering. uses belongs group apply user settings in gpo linked servers’ou.

 

i hope information above can useful you.

 

regards


kevin



Windows Server  >  Group Policy



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file