Solved

Group Policy

Posted on 2010-08-26
5
860 Views
Last Modified: 2012-05-10
I have a group policy that disables "Enable native XMLHTTP support" for all the servers in one OU, I am adding a 2008 R2 Ent x64 server to that OU, but this server needs it enabled.

This server needs to be in this OU, any solution?
0
Comment
Question by:nourben
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 2

Assisted Solution

by:Juliancito
Juliancito earned 150 total points
ID: 33536382
Create Anather OU inside that OU, put the Server there, create a GPU for that OU with Enable native XMLHTTP support"
0
 
LVL 38

Assisted Solution

by:Justin Smith
Justin Smith earned 150 total points
ID: 33536547
you could modify the permissions on the GPO and put an explicit DENY for that server.
0
 
LVL 38

Expert Comment

by:Justin Smith
ID: 33536551
only if that the XML is the the only setting on the GPO ;)
0
 
LVL 12

Expert Comment

by:Rant32
ID: 33536602
Agreed, creating a sub-OU enables you to override the setting.

If you reallyreallyreally can't move the computer object to another OU, I would wonder what created that dependency. The only thing I can think of is that some automation/scripts is dependent on the LDAP path of the server. Nasty.

If you really must use this OU, you can also create a higher ranking GPO for that OU, and configure GPO security such that only the x64 server has the "Apply policy" permission. The higher ranking setting will win, but only for that server.
0
 
LVL 12

Accepted Solution

by:
Rant32 earned 200 total points
ID: 33536826
To recap:

1) Create and configure the policy that will override the setting. Don't link it yet.
2) Create a Global security group "Enable native XMLHTTP" or something. Add the server to that group.
3) Open the policy's properties
4) Disable the User portion of the policy with the checkbox (I assume it's a computer setting). Then hit tab Security.
5) Remove the Authenticated Users group from the list.
6) Add the security group you just created and grant the Apply Policy permission
7) Link the GPO to the OU
8) Make sure the overriding policy is listed first (Link Order 1)
0

Featured Post

Webinar: Aligning, Automating, Winning

Join Dan Russo, Senior Manager of Operations Intelligence, for an in-depth discussion on how Dealertrack, leading provider of integrated digital solutions for the automotive industry, transformed their DevOps processes to increase collaboration and move with greater velocity.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Modifying AD Group Policy Powershell to list unused GPO 5 78
Certificate Authority Issues 6 56
Exchange, OWA, PROXY 7 70
is a device online 4 46
This article runs through the process of deploying a single EXE application selectively to a group of user.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question