Moving users into new container, policy problems?


i have small ad implementation 8 users.  we using new ad sync tool sync users within container, not general user ou.

 

there 8 users separate container never created.

 

i created new container users, put in test user, , sync software works fine.  i went , linked default domain policy new container policy.

 

however when try login test user not allow remote login, although part of remote desktop group, remote access rd group set via policy. 

 

since need move users new container, , remote desktop users(on server), going run pitfalls?  there 2 traditional desktop users , folder redirection turned on.

 

my original plan create new container, move users, , link gp default domain gp setup way want.

 

i've since read best practice, putting users in own container, regardless size of install plan on going , correcting others, assuming can follow same procedure on all.

hello,

"users" in ad uc mentioned called container , no gpos can linked it, password/account settings domain applied on containers. nothing else.

"domain controllers" example organizational unit(ou) , here gpos can linked to. gpo settings made in default domain controllers gpo apply domain controllers, not user account or computer of domain. should not modify them, better create new gpo link ou changes need, way can easy go default required settings dcs when problems occur new gpo, delete new 1 , after refresh or reboot dc has starting settings.

see difference between "container" , "organizational unit" icons.

there no need link default domain policy ou inheritance enabled default , if didn't block gpo applied.

you should move users own created ou, way can configure gpos (user configuration part) , link them ou. after running gpupdate /force on client, reboot , logon or waiting default gpo refresh time 90-120 minutes should applied. keep in mind settings require reboot.

the same applies computers, create own ou them , configure gpos, if needed (computer configuration part).

on pictures posted "s users" written spaces before, avoid them prevent problems if ever start scripting , need set path them.


best regards meinolf weber disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights.


Windows Server  >  Directory Services



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL

Como saber quien entro a mi PC por la Red