|
Posted by Mary M on April 19, 2006, 3:34 pm
Please log in for more thread options
Is there a way to apply settings found in gpedit.msc to an AD group? ie.
Hide desktop, remove run, ect..
Many thanks in advance.
|
|
Posted by Paul Adare on April 19, 2006, 4:12 pm
Please log in for more thread options
microsoft.public.windows.server.security news group, Mary M
> Is there a way to apply settings found in gpedit.msc to an AD group? ie.
> Hide desktop, remove run, ect..
>
> Many thanks in advance.
>
You should probably start here:
http://www.microsoft.com/windowsserver2003/technologies/management/group
policy/default.mspx
or
http://tinyurl.com/4gv3z
--
Paul Adare - MVP Virtual Machines
It all began with Adam. He was the first man to tell a joke--or a lie.
How lucky Adam was. He knew when he said a good thing, nobody had said
it before. Adam was not alone in the Garden of Eden, however, and does
not deserve all the credit; much is due to Eve, the first woman, and
Satan, the first consultant." - Mark Twain
|
|
Posted by Miha Pihler [MVP] on April 19, 2006, 4:14 pm
Please log in for more thread options Hi Mary,
Yes, this can be done. Here are few articles on the subject:
How To Use the Group Policy Editor to Manage Local Computer Policy in
Windows
http://support.microsoft.com/default.aspx?scid=kb;en-us;307882&sd=tech
How To Prevent Domain Group Policies from Applying to Administrator Accounts
and Selected Users in Windows Server 2003
http://support.microsoft.com/default.aspx?scid=kb;en-us;816100
I hope this helps...
--
Mike
Microsoft MVP - Windows Security
> Is there a way to apply settings found in gpedit.msc to an AD group? ie.
> Hide desktop, remove run, ect..
>
> Many thanks in advance.
>
>
>
|
|
Posted by Roger Abell [MVP] on April 19, 2006, 5:15 pm
Please log in for more thread options Yes, if you can do this using an AD based GPO.
No, if you mean doing this with gpedit in local policy.
www.microsoft.com/gp
has a ton and a half of docs on use of Group Policy
in AD environment.
--
Roger Abell
Microsoft MVP (Windows Server : Security)
> Is there a way to apply settings found in gpedit.msc to an AD group? ie.
> Hide desktop, remove run, ect..
>
> Many thanks in advance.
>
>
>
|
|
Posted by Steven L Umbach on April 19, 2006, 6:17 pm
Please log in for more thread options Yes it can be done with domain/OU level group policies. However Group
Policies to not apply to groups. They apply to computers and users. You can
"filter" group policy apply permissions to apply Group Policy to only users
in the Group that the Group Policy affects but basically think of AD Group
Policy this way. You create an Organizational Unit and add the user to the
OU that you want to have the "user" restrictions. Then create and link the
Group Policy with the restrictions to the OU. If you want the restrictions
to apply to all users in the domain then link the GPO to the domain
container. A user/computer can inherit any Group Policy setting that is
applied "above" them in the domain hierarchy but the Group Policy closest to
the user [such as OU compared to domain] will take precedence if the same GP
setting is defined in more than one Group Policy. The main exception is that
for "domain" users account/password policy can be defined only at the domain
level. --- Steve
> Is there a way to apply settings found in gpedit.msc to an AD group? ie.
> Hide desktop, remove run, ect..
>
> Many thanks in advance.
>
>
>
|
| Similar Threads | Posted | | 2003 Group Policies | April 24, 2006, 11:55 am |
| Windows Vista Group Policies in a Server 2003 SP1 Domain environment | May 11, 2007, 9:21 am |
| Group Policies | September 13, 2006, 8:31 am |
| Account Policies - Windows 2003 Server | July 23, 2007, 8:43 pm |
| Applying Windows 2003 policies to Windows XP | June 24, 2008, 2:34 pm |
| Windows 2003 Problem with Group Policy for Services Startup and Permissions | April 27, 2006, 7:27 am |
| local group / global group permissions problem | August 18, 2005, 12:42 pm |
| policies | September 12, 2005, 9:16 am |
| RAS and VPN policies - help | March 15, 2007, 10:10 am |
| Account Policies - NT | January 19, 2006, 3:14 pm |
|