Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 292
  • Last Modified:

How do I prevent domain admins from acquiring enforced group policy settings on a entire domain?

I have an active directory domain that has a Standard Domain Policy which is set to "enforced".
Recently, changes were made to the USER configuration of the policy (Do not permit changing proxy settings) and this seemed to work well, however, domain admins have advised that the policy has also applied to them.
Two things I should point out;
-It's not really necessary for domain admins to have the "Standard Domain Options" apply to them at all.
-The domain policy needs to remain "enforced".
I have toyed with security filtering and cannot seem to get around this.
Any thoughts?
Thanks!
Lab_Tech
0
Lab_Tech
Asked:
Lab_Tech
1 Solution
 
marcustechCommented:
Apply domain policy to domain users, not everyone
0
 
Glen KnightCommented:
You could create an OU in Active Directory and block inheritance on this OU but link the Domain Policy to the new OU so that it remains enforced.
0
 
Mike KlineCommented:
Since the policy is set to enforced it will win over block inheritance.  What happened when you tried the security filtering route
http://adisfun.blogspot.com/2009/04/security-filtering-and-group-policy.html
I'm guessing your users are spread across multiple OUs and that is why the policy is linked at the domain level.
Thanks
Mike
0
 
Lab_TechAuthor Commented:
Many thanks; This is exactly what I needed. The reason it did not work for me when I first played areound with the security filtering is that I had set read as deny without setting Apply group policy. Duh so simple!!!! Many thanks!!
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now