Solved

Can I push a GPO to multiple domains?

Posted on 2011-03-10
7
1,883 Views
Last Modified: 2012-06-22
I'm in a new environment which is a result of one company acquiring a few other companies.  It's a multi-forest, multi-domain environment.  I wasn't a part of the domain migration projects, but my job is to administer the systems.  I'm doing my best to familiarize myself with how everything works so from time to time I have questions which need to be answered.  Obviously the people that set this up initially are no longer here ... enter the EE experts!

Each domain has a Default Domain Policy, and a couple of the domains have additional GPO's for various settings (i.e. Outlook settings, IE settings to direct users to proxy, etc).  Two-way trust is setup between the domains (although I don't think it's functioning very well and may not be applicable to this specific issue).  

We'd like to add a GPO that would push a specific desktop wallpaper to all the desktop machines in all the domains.  I guess my question is how do I acheive that properly?  I know where to go to set up the GPO settings that I require - though I welcome suggestions on this as well.  My thought would be that I would have to edit each Default Policy to include the proposed change??  Can anyone confirm or advise steps to acheive the end result of one GPO pushed to multiple domains?  I'm attaching a snapshot of GPMC to aid in visualizing the request.   :o)   GPM MMC
0
Comment
Question by:mrah
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 21

Expert Comment

by:snusgubben
ID: 35097461
You cannot have a single GPO for multiple domains.
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 75 total points
ID: 35097579
You can link to multiple domains but generally not recommended.  I've seen it done is some smaller environments that happened to have multiple domains

See the section Cross-Domain GPO Links

http://windows-active-directory.net/Que-Windows.Server.2003.Active/0789729504_ch06lev1sec5.html

Thanks

Mike
0
 
LVL 21

Expert Comment

by:snusgubben
ID: 35097738
I wasn't aware that you could cross-link GPOs to different forests. You always learn. Thanks for bringing it up Mike :)
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 21

Accepted Solution

by:
snusgubben earned 175 total points
ID: 35097870
Looking at http://technet.microsoft.com/en-us/library/cc738810(WS.10).aspx#BKMK_forest 

it says: It is not possible to link a GPO to a domain in another forest (even with a forest trust)

0
 
LVL 1

Author Closing Comment

by:mrah
ID: 35098144
Thanks for the confirmation...I was pretty sure it wasn't "recommended" and I understand the performance issues associated.  I've skimmed these documents in my quest for an answer, but thanks for pointing out the specifics!
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 35098243
ahh different forests....I just read the title and then had a meeting....regular work called so I had to go :)
0
 
LVL 1

Author Comment

by:mrah
ID: 35098414
:o) ... it's all good, that's why I included the image ... I know how that goes, I hate when regular work interrupts my EE time...LoL.  Thanks again for contributing!
0

Featured Post

Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question