Preventing Group Policy applied to domain administrator
hello,
we have 2 gpo's linked ou
1 gpo users, , 1 gpo computers
all policies working good, when log workstation domain administrator account computer policy still apllies , functions disabled due computer policy restrictions. happens when log in locally
the domain administrator account in seperate ou has no gpo's linked it
we have managed disable user policy processing giving deny " apply group policy" on user policy domain administrators. unfortunately computer policy doesn't affect setting
we want no policy processed when domain administrator logs client workstation. how can done?
we have 2 gpo's linked ou
1 gpo users, , 1 gpo computers
all policies working good, when log workstation domain administrator account computer policy still apllies , functions disabled due computer policy restrictions. happens when log in locally
the domain administrator account in seperate ou has no gpo's linked it
we have managed disable user policy processing giving deny " apply group policy" on user policy domain administrators. unfortunately computer policy doesn't affect setting
we want no policy processed when domain administrator logs client workstation. how can done?
hi,
thank update. think had not made clear in previous reply. speaking, not prevent computer group policy applying when administrator logs on. determined how group policies processed.
computer configuration includes computer-related policy settings specify operating system behavior, desktop behavior, security settings, computer startup , shutdown scripts, computer-assigned application options, , application settings. computer-related group policy (or computer configuration) applied when operating system initializes , during periodic refresh cycle. in general, computer policy takes precedence on conflicting user policy. thus, not possible configure computer configuration, such domain account lockout policy, apply specific users.
little policy has built-in mechanism configured bypass users or computers.
thanks.
this posting provided "as is" no warranties, , confers no rights.
thank update. think had not made clear in previous reply. speaking, not prevent computer group policy applying when administrator logs on. determined how group policies processed.
computer configuration includes computer-related policy settings specify operating system behavior, desktop behavior, security settings, computer startup , shutdown scripts, computer-assigned application options, , application settings. computer-related group policy (or computer configuration) applied when operating system initializes , during periodic refresh cycle. in general, computer policy takes precedence on conflicting user policy. thus, not possible configure computer configuration, such domain account lockout policy, apply specific users.
little policy has built-in mechanism configured bypass users or computers.
thanks.
this posting provided "as is" no warranties, , confers no rights.
Windows Server > Group Policy
Comments
Post a Comment