Solved

How to perform Admin Support on a desktop that has GPO applied to user account

Posted on 2011-09-19
2
234 Views
Last Modified: 2012-05-12
Hello,

I have setup a OU structure and applied a GPO that prevents users from changing any settings on desktop, IE, control panel, etc.... Now as an Admin, how am I able to remote into any users system that has these GPOs and perform any troubleshooting within the areas I blocked through a GPO. I don't want to have to disable the policy everytime I need to work on a specific system and I don't want to have to log that user out and use a admin account if I'm working on that users desktop settings.

Server: Windows Server 2008 Enterprise
Users Desktops: XP and Windows 7

Thanks,

nimdatx
0
Comment
Question by:nimdatx
2 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 36561325
You can use security flitering on that GPO

http://adisfun.blogspot.com/2009/04/security-filtering-and-group-policy.html

Deny the "apply" permissions for the admin group and they won't receive the GPO settings.

...but you won't be able to make those changes as that user account directly if those policies are applied.  That is not possible.

Thanks

Mike
0
 
LVL 1

Author Comment

by:nimdatx
ID: 36561364
Admin account is good, but how does an admin perform work on a users system when logged into that system as that user and GPO is applied to users account. What if I need to map a network drive and put it on that users desktop? If this is not possible, how do you perform helpdesk support on a users account with a GPO applied to users?
0

Featured Post

3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question