Solved

Active Directory - Group Policy Question

Posted on 2011-02-11
3
392 Views
Last Modified: 2012-05-11
1.  Are local group policies applied differently than domain group policies in terms of which one takes precedence?  It is my understanding that the most specific GPO is takes precedence is that true for both local and domain?  

2.  Reading the 70-622 book it states that if I had a domain structure like the one below

Forest:  hq.contoso.com
OU: Accounting, Finance Human Resouces, IT etc
IT OU split into Desktops, Laptops, and Server OUs each with their own GPO

The order of precedence would be the in the following order

Local GPO
Default Domain Policy
IT GPO
IT Desktop GPO

Wouldn't the Local GPO be first then followed by the IT-Desktop GPOs, IT and finally Default Domain Policy...I thought it went most specific to most general.  

A bit confused because on page 107 it says Settings in lower-level GPOs override settings in higher GPOs but then they say domain GPOs override lower GPOs in the very next sentence.  

I am hoping someone out there has a simple way to think of this.  THanks

Aaron
0
Comment
Question by:AJJ36
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 5

Expert Comment

by:zippybungle2003
ID: 34870325
Domain GPOS will always overide local policy settings aslong as the machine is a member of the domain.

Also remeber enforce is also authorative.
0
 
LVL 85

Accepted Solution

by:
oBdA earned 500 total points
ID: 34870401
Part of your confusion might be the difference between application time and priority: note that GPOs that are processed later have a higher priority, since the settings from the GPOs that are applied later will overwrite the same settings that might come from "earlier" GPOs.
So in your list above, you're not listing the precedence/priority, you're listing the application order--the priority will be the reverse of that list.
GPOs are applied in the order "LSDOU":
Local Policies
Site GPOs
Domain GPOs
OU GPOs
For the OU GPOs in general: the "closer" the GPO is to the object in the AD path, the higher the priority.
0
 

Author Closing Comment

by:AJJ36
ID: 34877356
Thank you for the help
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question