• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 173
  • Last Modified:

XP users of Windows 2000

I have a W2K server + a few XP rrofessional clients.
I have imported the adm templates into W2K for use in group policies.
I created a simple policy that changes screen colour and disables control panel for a certain user.
When the user logs in the policy does not work. Why??
  • 2
1 Solution
have you put that user account into an ou and applied your policy to the ou?
This is a quirk in 2k In the policies you have 3 option remove control panel, show only specified applets or hide applets.

One of them doesnt work and its not alway the same one. I dont know what country you are in but it may be law that you have to allow users to change screen size.

Allow the control panel and hide the applets if that doesnt work for you use the other one show only some. This way it will work. As the other user suggested create a OU and add the users to a group and to the ou and apply the policy to the ou. If it still doesnt work you may be inherting polices there is a check box to disable that on the policy.
samuria, your first suggestion may be true (i'm not certain about that one), but actually, you can't apply group policy to groups. i know it's that you should be able to, but "group" policy doesn't work in that way. it has to be applied to ous that have specific user or computer accounts, ad sites, or to the whole domain.

the only way to get around this is to play with the security settings.  for example, if the admin has an ou with a bunch of user accounts and he only wants it to be applied to one specific user without having to move that user account to another ou, the admin has to go to the security settings for the policy and choose "deny" for all of the users or groups that he doesn't want the policy for the intended user account to apply to. or he can remove the read or appy settings.

i could be wrong, but i'm pretty certain this is the case, because i had to research this subject for a problem i was having on my network very recently.

from serverwatch.com:

"Strangely enough, you cannot link Group Policies to Win2000 groups (a bit of misnomer). You might think of trying placing groups into OUs in order to bypass this limitation, but unfortunately this will not help either. Groups placed in OU are not affected by processing of group policies (only users and computers). However, you can apply GPOs to groups based on the DACLs (Discretionary Access Control List entries) assigned to groups (or other Win2000 security principals, such as computers or users) using Security tab of GPO's properties. This is done by checking Allow column for Read and Apply Group Policy permissions for groups you want to have GPO applied to."

this is essentially what i just explained, but i added it here so that you guys could see it from a different source.

This question is still open and getting old. If any of the comment(s) above helped you please accept it as an answer or split the points who ever helped you in this question. Your attention in finalising this question is very much appreciated. Thanks in advance,


- If you would like to close this question and have your points refunded, please post a question in community support area on http://www.experts-exchange.com/Community_Support/ giving the address of this question. Thank you      


Cleanup Volunteer


Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now