Solved

Locking Down users with Group Policy

Posted on 2006-06-14
2
569 Views
Last Modified: 2008-01-09
Hi I'm having some problems getting Group Policy to work like I want.

I have 9 users that are using the default User Template from SBS 2003 that I want to lock down.  I created an OU called "Locked Down Users".  I also created a Security Group called "Locked Down Users".  I added all the users that need the extra security into the "Locked Down Users" Group and I added the "LDU" Group to the "LDU" OU.

I also created a Group Policy Object that has the restrictions I want, ie no control panel, no run menu etc.  I set these all up in Administrative Templates of the User Configuration.  I then linked the the GPO to the "LDU" OU, and gave the "LDU" Group Read permissions on the GPO.  The GPO is link enabled and enforced.

Unfortunately I must have missed something as the GPO is not being applied to the users?

Any idea what I'm missing?  Still sort of a newb at Group Policy so be gentle.  ;)
0
Comment
Question by:jb1013
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 74

Accepted Solution

by:
Jeffrey Kane - TechSoEasy earned 500 total points
ID: 16908161
It's probably more of where you put the OU.  It MUST be under \MyBusiness\SBSUsers\Users in order to work... however, there is no need to put them in a separate OU, just use the security group instead.  Then, create a NEW template that is a member of the security group and then apply that new template to the users you want to have in it by using the Change Permissions Wizard.

Then, make sure that your GPO is linked and enabled to that security group.  Finally, run a GPUPDATE /FORCE command on the server.

To see if it's being enforced properly, log into a workstation with a member's account and run a GPRESULT /V command.

Jeff
TechSoEasy

0
 
LVL 1

Author Comment

by:jb1013
ID: 16909441
OK, that's probably it then I think the OU is in the wrong place.  Thanks for the pointers on how to do this correctly.  I'll give it a shot when I'm back over there in a day or so.  I really appreciate your help.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A lot of problems and solutions are available on the net for the error message "Source server does not meet minimum requirements for migration" while performing a migration from Small Business Server 2003 to SBS 2008. This error pops up just before …
I’m often asked about newer and larger USB drives connected to SBS2008 and 2011 failing Windows Server Backup vs the older USB drives not failing. As disk space continues to grow and drive technology change SBS2008 and some SBS2011 end up with the f…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

735 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question