Solved

Group Policy OU

Posted on 2010-08-24
5
308 Views
Last Modified: 2012-05-10
So I created a an OU for my Terminal Server then I created a lockdown GP applied it to my OU. I then Put my TS in the OU all by itself.

It has been working fine until I as admin got tired of being locked down too.

So I did this. I removed Authenticated Users and added my general users group. (MNoffUsers) Applied security of Read and Apply Group Policy to them.

Now the Terminal Server is not locking down at all for anyone. The kicker is that I put authenticated users back and removed the users group but that didn't work. It doesn't seem to be applying the group policy at all.

Any suggestions?
0
Comment
Question by:cchayden
  • 3
  • 2
5 Comments
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
Are you applying user settings in that GPO,   If you did they would not apply to the users (if they are in a different OU).
The caveat to that is if you are using loopback.
However when you added authenticated users back things should have gone back to how they were.  Any errors in the logs?
 
Thanks
Mike
0
 

Author Comment

by:cchayden
Comment Utility
Yes the GPO is a mixture of both computer and user policies.

Logs on the TS or the DC, or both?
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
Comment Utility
Start with the TS box;  check out this question I helped with dealing with loopback and security filtering
http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_26409306.html
Thanks
Mike
0
 

Author Comment

by:cchayden
Comment Utility
Ok.

So I now have 2 GPOs linked to my TerminalServerOU. One is a Replace Loopback that security filters Read, and Apply GP to the Terminal Server itself. The other is my original lockdown GPO that security filters Read and Apply GP to the MNOffUsers security group.

The Terminal Server is still inside the TerminalServerOU. Any overide settings for the GPOs?

Now for the final stupid question. Do I need to restart the Terminal Server after changes to the GPOs?
0
 

Author Comment

by:cchayden
Comment Utility
So rather than kick everyone off the TS I guess I can use the command :

gpupdate/force

and adding the loopback GPO seems to have fixed my original problem.

Thanks Much!
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

I know all systems administrator at some time or another has had to create a script to copy file from a server share to a desktop. Well now there is an easy way to do this in Group Policy. Using Group policy preferences is not hard. The first thing …
Installing a printer using group policy preferences is not that hard let’s take a look at it. First lets open up your group policy console and edit the policy you want to add it to. I recommend creating a new policy for each printer makes it a l…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now