Solved

Administrator GPO Loopback Problem

Posted on 2004-08-21
5
588 Views
Last Modified: 2010-04-19
I have an OU that contains "Kiosk" type computers where many users (students) will be logging in, as well as to their own
personal PC's on my domain.
So I have created very restrictive GPO's on the Kiosk OU that takes away just about everything you can take away on a Desktop.
I use the "Loopback" feature on the Kiosk OU, so that when they log onto their personal laptops elsewhere in the school they are not locked down.

My problem is now that when I go to any PC contained in the Kiosk OU and attempt to login with the "Adminsitrator" account,
I get the same restrickted desktop as the students.

How do I prevent a GPO Loopback from Applying to Administrator account?
Perhaps this isn't the exact right approach to solving the problem... but you understand the ultimate goal.

I want the Administrator to be unrestricted when I log in.

I have tried to remove the Domain Admin group from the "Delegation" tab in the Group Policy Management Console for
the obove mentioned GPO with no success.

Any assistance is greatly appreciated!
0
Comment
Question by:manogue
  • 3
  • 2
5 Comments
 
LVL 16

Accepted Solution

by:
mdiglio earned 500 total points
ID: 11862683
Hello,
The Domain Admin group is still being affected
because they are receiving the policy through the Authenticated Users group.
 
From the delegation tab within the group policy management console
click the advanced tab. From the Security Settings box you will need
to deny the Domain Admin group 'apply group policy' and 'read'

It is perfectly acceptable to use deny when using group policy
In case you are worried about the deny part of the soultion here is a link for some comfort:
http://www.microsoft.com/windows2000/en/advanced/help/default.asp?url=/windows2000/en/advanced/help/filter.htm

Hope this helps!
0
 

Author Comment

by:manogue
ID: 11875671
Okay... I did what you said... now I cannont administer that policy at all.

0
 
LVL 16

Expert Comment

by:mdiglio
ID: 11876097
Hi manogue,

I followed the same steps and received the same results as you did.
My fault...I thought I have done this procedure several times before
and did not test it before posting

The way I just got around my mistake right now was to create a new user in the Enterprise Admin group.
Run the Group Policy Management Console as that new user >> then removed the deny 'Read' part of the settings
and left the deny 'apply group policy'. Then,  of course , deleted the new user.

Again...I apologize for my mistake and being so sloppy. I should not have told you to deny 'Read'

We'll get it fixed!

0
 

Author Comment

by:manogue
ID: 11876137
Ah Ha!!!

Works like a charm now!!

Thank you so much for your time and help!!!
0
 
LVL 16

Expert Comment

by:mdiglio
ID: 11877382
Great!
Thanks for the points and for being understanding of my mistake.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
Learn about cloud computing and its benefits for small business owners.
In a recent question (https://www.experts-exchange.com/questions/28997919/Pagination-in-Adobe-Acrobat.html) here at Experts Exchange, a member asked how to add page numbers to a PDF file using Adobe Acrobat XI Pro. This short video Micro Tutorial sh…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question