Solved

Security groups for GPOs

Posted on 2004-09-11
1
352 Views
Last Modified: 2012-05-05
When we create organizational units and I want to apply GPOs to objects contained in them (for example users or computers), I have realized that if we do not want to apply the policy to special users (Help desk users, admistrators, etc) when they log in that computers (to complete maintenance tasks) it is necessary to use GPO filtering to avoid it.  that force to create a group with same objects that are contained in that OU to  APPLY and READ checkboxes only for that group. We remove authenticated users of the list. In that way when an IT user log in he has not problem with the computer. I don´t understand very well this. We have to create the same groups with the users or computer which are incluided in the container? . Is that correct ?. Is it a good idea and practice to deny APPLY and READ GPOs for these special groups of administrators ?




0
Comment
Question by:intentalo69
1 Comment
 
LVL 83

Accepted Solution

by:
oBdA earned 250 total points
ID: 12035146
In my opinion, your approach is correct; I don't like the "Deny" approach, neither for NTFS nor for GPOs. What I usually do is to gather the GPOs in a top-level OU, then create a dedicated security group for each GPO, named something like GPol-<GPOName>; the Read and Apply permissions are removed from the Authenticated Users, and applied to the group instead. That way, you can easily find your GPOs, instead of having to search for them in several different OUs, and you have easy control about who gets which policies applied. If you combine that with the GPO priority, you can avoid duplicate settings in different GPOs, depending on your needs.
In addition, I separate the computer and user settings in different GPOs; you can then disable the User configuration part of the GPO in machine GPOs, and vice versa.
Whether that approach works for you depends of course on your organisation, and if you want to delegate control over OUs to other users, and the air humidity.
Another good idea is the use of the Group Policy Management Console; that makes the administration a bit easier.
Enterprise Management with the Group Policy Management Console
http://www.microsoft.com/windowsserver2003/gpmc/default.mspx
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now