Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Setting group policies on distribution groups - Windows 2003 AD

Posted on 2006-11-20
7
Medium Priority
?
1,067 Views
Last Modified: 2009-12-16
I am running exchange server 2003 and I am using Group Policy Management Console to manage my group policies. All my users are set up under different distribution groups in AD and I am looking for a way to set up different group policies on each distribution group. Is there a way to set group policies on distribution groups?
Thanks
0
Comment
Question by:mrvan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 57

Expert Comment

by:Pete Long
ID: 17980818
No - you CANT you can apply to a security group by just giving that group the read and apply right but you cant assign a GPO to a distribution group
0
 
LVL 31

Accepted Solution

by:
Toni Uranjek earned 200 total points
ID: 17981394
Group policy has - in fact - almost nothing to do with groups. GPO can be linked to site, domain or OU and applies to user and computer accounts. You can use "Security filtering" to apply (or deny) GPO to members of security (NOT distribution) group but only if the settings from GPO would apply to users in first place (only if user accounts are in OU)
0
 
LVL 9

Assisted Solution

by:SamuraiCrow
SamuraiCrow earned 300 total points
ID: 17982077
Keep in mind that you can use a security group as a distribution group but not vice-versa.  If you need to simplify group management create all groups as security groups and then make them mail enabled.  That way you get the best of both worlds.
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Author Comment

by:mrvan
ID: 17996237
Thank you for the advice given.

What I need to do it to create a group or group 10 users and assign a group policy to them. This group will be very limited on what they can do on their workstation.

Then I would create a second group with 15 users and assign different policies to that group.

I need to break my domain users up into groups and assign different policies to them.
Could this be archived?
Thanks you
0
 
LVL 9

Assisted Solution

by:SamuraiCrow
SamuraiCrow earned 300 total points
ID: 17997869
This can absolutely be done as toniur mentioned above.  Here is a link that talks about the process of assigning group policy to an active directory group:
http://www.windowsnetworking.com/articles_tutorials/Group-Policy-Security-Filtering.html
0
 
LVL 9

Expert Comment

by:SamuraiCrow
ID: 17997875
0
 
LVL 31

Expert Comment

by:Toni Uranjek
ID: 17999042
It can be achieved but not exactly the way you put it. Create two OUs. Put first ten users in first OU, create and link appropriate GPO setings to this OU. Put another 15 user in second OU, create and link appropriate GPO to second OU. Let me remind you that your goal can be achieved without creating groups.

If you use only one OU, then you create two groups, assign members to groups and then you should create two GPOs, link them both to this OU, and then use "Security Filtering" to allow GPO to apply only to users in groups.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Have you created a query with information for a calendar? ... and then, abra-cadabra, the calendar is done?! I am going to show you how to make that happen. Visualize your data!  ... really see it To use the code to create a calendar from a q…
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question