Solved

Populating an OU

Posted on 2006-07-16
8
526 Views
Last Modified: 2008-05-30
Hi,

I am new to the whole OU set-up and need to get some clarification on how I can achieve my aim.

What I want to do is as follows:

I have users that will use a roaming profile, I have added them to a group called "Roaming" I have created an OU called Roaming. What I want to do is apply a Group Policy to the Roaming OU which in turn will contain the Roaming group. I can create a new Group Policy Object Editor on the domain which I will want to use to set the control on the Roaming OU. How do I get the Group Policy Object Editor to be applied to the Roaming OU? - Is this the correct way to go about this to achieve my aim?

Thanks,

jonathanr
0
Comment
Question by:jonathanr
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 9

Accepted Solution

by:
NYtechGuy earned 45 total points
ID: 17119012
jonathan-

You pretty much have the right idea.  However, I've haven't done it the way you are proposing.

What I have always done is this:

- Create OU (Example:  Roaming Users)
- Create Group Policy Object (GPO)
- Link GPO to OU I created in step 1
- Add/move users *into* OU called "Roaming Users".

I am not sure if your way of applying the GPO to an OU containing a group which contains the users will work.  I have only populated OUs for GPO purposes with Users or Computers.  I have only used security groups for other purposes (file/folder permissions, etc)

THanks,

Justin
0
 

Author Comment

by:jonathanr
ID: 17119054
Thanks Justin,

Can you detail how I would "- Link GPO to OU I created in step 1"

thanks,

jonathanr
0
 
LVL 14

Assisted Solution

by:Juan Ocasio
Juan Ocasio earned 45 total points
ID: 17119402
When you create the OU, Right-Click on the OU and select properties.  Then select the Group Policy Tab and create your GPO there.  You can then drag and drop (new in Win 2003) the objects - users- you want to apply the GPO to.

HTH

jocasio
0
Office 365 Advanced Training for Admins

Special Offer:  Buy 1 course, get 2nd free!  Buy the 'Managing Office 365 Identities & Requirements' course w/ Accelerated TestPrep, and automatically receive the 'Enabling Office 365 Services' course FREE!

 
LVL 14

Expert Comment

by:Juan Ocasio
ID: 17119416
Oh  I am assming you have Win 2003.  If you have 2000, you would select the object you want to move and select 'Move...'

jocasio
0
 

Author Comment

by:jonathanr
ID: 17119937
Hi jocasio123,

OK, it is 2003. I have done what you said but I cannot get any of the modifications that I am testing with to show up on the test user when they log in. I have got "No Override" set on the policy in the OU and I have played with the "Block inheritance" option too - do you have an idea where I am going wrong?

Thanks,

jonathanr
0
 
LVL 1

Assisted Solution

by:rickardc
rickardc earned 35 total points
ID: 17121737
Group policys are applied to user and computer objects, NOT groups.  To make it work, you will have to move the user account (and the computer account if you want to make computer settings) to the OU where your group policy is linked.

Are you creating your group policy through active directory user and computers?

A much better (and free) tool is the group policy management console (GPMC) from microsoft.  You can downlaod it from here.  http://www.microsoft.com/downloads/details.aspx?FamilyID=0a6d4c24-8cbd-4b35-9272-dd3cbfc81887&DisplayLang=en

In the GPMC, there's a section down the bottom called group policy results, and it'll show you all the settings that will be applied to a user / computer object.
0
 
LVL 14

Expert Comment

by:Juan Ocasio
ID: 17125806
jonathanr:

rickardc is correct.  I had to reread your initial post when I read his post.  Add the users to the OU.  Once you do this, you should be good to go.  You also have to wait until the GPO propagates

HTH

jocasio
0
 
LVL 9

Expert Comment

by:NYtechGuy
ID: 17125849


helpful command line (on XP clients):

gpupdate /force

this will force rereading of GPO and apply them to the machine - without a reboot

thanks,

justin
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article runs through the process of deploying a single EXE application selectively to a group of user.
Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question