Blocking Domain Policies

Posted on 2008-11-03
Last Modified: 2013-12-04
Is there a way to block a domain policy to a local machine via a registry key or local policy setting?  I do not want to block this policy via A/D inheritance.  The policy must be blocked at a local level if possible.  Any Ideas?
Question by:stetlers
    LVL 70

    Accepted Solution

    Domian policies will always take precidence - unless you put the machine in an OU and block policy inheritance on the OU or to use security filtering

    In any event it has to be done at the domain not at the client

    Assisted Solution

    Unfortunately there is no way to do this at the PC level. Group policy wants to be in control. If you do not want to create a group to block inheratance and put this PC in it you can create a GPO and set it to 'undo' whatever other policies you do not want to be applied to this computer. Then assign the policy to this computer only and set it for no override.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive Gives IT Their Time Back

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    Common practice undertaken by most system administrators is to document the configurations and final solutions of anything performed by them for their future use and reference. So here I am going to explain how to export ISA Server 2004 Firewall pol…
    First let me explain that I am extremely paranoid about computer security issues and computer backup issues.  This means that I only feel safe if I am running unknown programs and visiting unknown sites in a virtual machine.  In that way, if anythin…
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
    This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

    794 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now