Click here to get back home

Auto-enrollment setting at different OU levels

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Auto-enrollment setting at different OU levels StuartH 06-19-2007
Posted by StuartH on June 19, 2007, 4:59 pm
Please log in for more thread options
We have stumbled across something a little bizarre when trying to set
auto-enrollment for computers at levels below the domain object.
What I mean, is that if we set a GPO (say in the default domain policy) at
the root of the domain to autoenroll, then computer objects happily accept
the cert that is automatically given to them. However, further down, if we
set a GPO (say at a server OU) to not autoenroll...this is ignored. The GPO
*is* applying and it is just the AE settings that are not being applied.
This seems to be behaviour similar to how EFS cannot be turned on/off
throughout a domain/OU level.....if you set EFS to enabled in the root of a
domain, you cannot turn it "off" lower down without having a deny ACE set un
the subOU (so they can read the GPO setting EFS in the domain GPO).
We basically want to be able to have servers and workstations auto-enroll
but not DCs. We could set a deny ACE for Enterprise DC's so they cannot read
the cert-authentication CA template...but I would rather have autoenrollment
work properly, by GPOs.

Anyone seen this behaviour or can explain it ?

Thanks

Stuart





Similar ThreadsPosted
Setting COM Security at the parent levels November 7, 2006, 10:01 am
Help with AutoEnrollment Error 15 March 22, 2007, 10:21 am
Autoenrollment Fails September 16, 2007, 3:48 pm
Autoenrollment error number 6 October 4, 2005, 10:39 am
Multiple CAs: Selection mechanism for autoenrollment? June 16, 2005, 1:14 pm
Autoenrollment of encryption certs and Outlook configuration June 8, 2005, 10:25 am
Ceritifcate Services Autoenrollment Subject Name Format April 23, 2006, 4:33 pm
Microsoft PKI: problem with autoenrollment for domain controllers August 14, 2007, 8:51 am
Autoenrollment problems - Enrollment access is not allowed to this template computer September 1, 2006, 4:02 pm
Setting up IIS 6.0 tutorial February 21, 2006, 4:38 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap