Solved

Active Directory - Group Policy Question

Posted on 2011-02-11
3
391 Views
Last Modified: 2012-05-11
1.  Are local group policies applied differently than domain group policies in terms of which one takes precedence?  It is my understanding that the most specific GPO is takes precedence is that true for both local and domain?  

2.  Reading the 70-622 book it states that if I had a domain structure like the one below

Forest:  hq.contoso.com
OU: Accounting, Finance Human Resouces, IT etc
IT OU split into Desktops, Laptops, and Server OUs each with their own GPO

The order of precedence would be the in the following order

Local GPO
Default Domain Policy
IT GPO
IT Desktop GPO

Wouldn't the Local GPO be first then followed by the IT-Desktop GPOs, IT and finally Default Domain Policy...I thought it went most specific to most general.  

A bit confused because on page 107 it says Settings in lower-level GPOs override settings in higher GPOs but then they say domain GPOs override lower GPOs in the very next sentence.  

I am hoping someone out there has a simple way to think of this.  THanks

Aaron
0
Comment
Question by:AJJ36
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 5

Expert Comment

by:zippybungle2003
ID: 34870325
Domain GPOS will always overide local policy settings aslong as the machine is a member of the domain.

Also remeber enforce is also authorative.
0
 
LVL 84

Accepted Solution

by:
oBdA earned 500 total points
ID: 34870401
Part of your confusion might be the difference between application time and priority: note that GPOs that are processed later have a higher priority, since the settings from the GPOs that are applied later will overwrite the same settings that might come from "earlier" GPOs.
So in your list above, you're not listing the precedence/priority, you're listing the application order--the priority will be the reverse of that list.
GPOs are applied in the order "LSDOU":
Local Policies
Site GPOs
Domain GPOs
OU GPOs
For the OU GPOs in general: the "closer" the GPO is to the object in the AD path, the higher the priority.
0
 

Author Closing Comment

by:AJJ36
ID: 34877356
Thank you for the help
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question