Solved

Group policy - domain policies appearing last then first in precedence

Posted on 2009-05-14
2
231 Views
Last Modified: 2012-05-07
We run 2003 terminal servers with 2003 AD and use computer GPOs but recently we needed to split users into two OUs - one OU will use a proxy via a user GPO and the other group won't use the proxy via a different GPO.  The relevant user GPO will be merged with the computer GPOs via loopback.

The particular user GPO to apply the proxy is not working.  When I run rsop.msc and check the precedence for the proxy settings, a couple of domain policies are at the top with the proxy "<disabled>".  But those domain policies don't even have any proxy settings configured (enabled or disabled).  Plus, they appear at the bottom of the precedence AND at the top.  I thought GPOs were applied in this order: local, site, domain, OU.  

So how can the proxy be disabled when the GPO settings aren't even configured in the domain GPOs and why are the domain GPOs at the very top of the precedence level?  It must be something I've missed!
0
Comment
Question by:lrkwalkers
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 8

Expert Comment

by:schriste
ID: 24473124
I'd review this site: http://technet.microsoft.com/en-us/library/cc778890(WS.10).aspx

The exceptions to the precedence might be what is tripping you up.
0
 

Accepted Solution

by:
lrkwalkers earned 0 total points
ID: 24479054
This has been resolved by the IT company we outsource work to.

I will get more info.

0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question