Solved

Group Policy

Posted on 2010-08-26
5
849 Views
Last Modified: 2012-05-10
I have a group policy that disables "Enable native XMLHTTP support" for all the servers in one OU, I am adding a 2008 R2 Ent x64 server to that OU, but this server needs it enabled.

This server needs to be in this OU, any solution?
0
Comment
Question by:nourben
  • 2
  • 2
5 Comments
 
LVL 2

Assisted Solution

by:Juliancito
Juliancito earned 150 total points
Comment Utility
Create Anather OU inside that OU, put the Server there, create a GPU for that OU with Enable native XMLHTTP support"
0
 
LVL 38

Assisted Solution

by:Justin Smith
Justin Smith earned 150 total points
Comment Utility
you could modify the permissions on the GPO and put an explicit DENY for that server.
0
 
LVL 38

Expert Comment

by:Justin Smith
Comment Utility
only if that the XML is the the only setting on the GPO ;)
0
 
LVL 12

Expert Comment

by:Rant32
Comment Utility
Agreed, creating a sub-OU enables you to override the setting.

If you reallyreallyreally can't move the computer object to another OU, I would wonder what created that dependency. The only thing I can think of is that some automation/scripts is dependent on the LDAP path of the server. Nasty.

If you really must use this OU, you can also create a higher ranking GPO for that OU, and configure GPO security such that only the x64 server has the "Apply policy" permission. The higher ranking setting will win, but only for that server.
0
 
LVL 12

Accepted Solution

by:
Rant32 earned 200 total points
Comment Utility
To recap:

1) Create and configure the policy that will override the setting. Don't link it yet.
2) Create a Global security group "Enable native XMLHTTP" or something. Add the server to that group.
3) Open the policy's properties
4) Disable the User portion of the policy with the checkbox (I assume it's a computer setting). Then hit tab Security.
5) Remove the Authenticated Users group from the list.
6) Add the security group you just created and grant the Apply Policy permission
7) Link the GPO to the OU
8) Make sure the overriding policy is listed first (Link Order 1)
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
Learn about cloud computing and its benefits for small business owners.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now