Solved

GPO status

Posted on 2010-11-10
10
973 Views
Last Modified: 2012-05-10
in W2008, in the details tab of a GPO, there is a drop down box next to GPO status:
it shows:
Enable
User settings disabled
computer settings disabled
....
....

in which case we use this drop down box?

thanks

0
Comment
Question by:jskfan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
  • 2
10 Comments
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 167 total points
ID: 34106303
This basically blocks off the select portion of the GPO from running. Some postings on the net say that you can gain a bit of a boost by disabling a section of a GPO if it has no settings in it. I have heard that this is not true but some people swear by it.
0
 
LVL 35

Assisted Solution

by:Joseph Daly
Joseph Daly earned 167 total points
ID: 34106348
0
 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 333 total points
ID: 34106775
I'm not quite sure what ou are asking but if its under what condidtions you would use the disable user settings/disable computer settings tab then

If the GPO contains no computer settings, then you can disable the computer settings and that part of the GPO will not be applied and this may speed up their application

If the GPO contains no user settings then again you can disable the user part of the GPO and get some performance benefit

It has to be said though that the performance benefits are at best marginal and some would argue non-existant.

You can also disable the different parts of the GPO for troubleshooting process.
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Author Comment

by:jskfan
ID: 34106956
If a GPO is applied to users, it means automatically is disabled for computers and vice-versa
unless if there are 2 similar settings on 2 GPOs applied to computer and users and in this case the computer policy wins
there is a loopback policy, that uses merge , which can be applied to both.
even in this case it doesn't make sense at all.

I am not sure why it s there(GPO status)
0
 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 333 total points
ID: 34107551
A GPO is applied to the domain or to an OU

If a GPO is applied to an OU then the user setting affects any users whose user accounts are in that OU
If a GPO is allpied to an OU then the computer settings affect any computers with comuter accounts in that OU
There are some user settings that are the same as computer settings (in which case the user settings normally prevail), however there are also a lot of settings that are in the user settings but not in the computer settings and vice versa.

If a user account is in one OU and the computer account is in another OU then its possible that the computer settings from one GPO will be combined with the user settingd from another GPO
0
 

Author Comment

by:jskfan
ID: 34107709
computer settings wins
0
 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 333 total points
ID: 34107741
I dont understand your comment
0
 

Author Comment

by:jskfan
ID: 34108436
I believe you in your comment you meant when 2 GPOs settings  conflict (user and computer GPOs) always the computer gpo wins, instead of what it is been said in the previous comment.


Regarding GPO status drop down box, to me I don't see any benefits of it there.
0
 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 333 total points
ID: 34108460
As I said, if the GPO does not contain any computer settings, then you can disable that part of the GPO - this essentially saves time as its not reading the policy to not apply anything. You may have a GPO for example that sets up folder redirection for users. Even though that policy contains no computer policies, the computer policies will be read from the policy when the GPO is applies - unless its been disabled.
0
 

Author Closing Comment

by:jskfan
ID: 34114644
thanks
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question