Posted on 2012-03-15
I know this is basic Group Policy 101, but for some reason I can't figure it out after all the searching I've done.
We have several servers, then we have a lot of computers.
I want automatic updates for our computers, but I don't want auto updates on the servers. My problem is this. It seems that no matter what I do, whatever I have set in the Default Domain policy applies to everything in the domain.
I have a separate OU for my servers, and a separate OU for my computers.
I've blocked inheritance on the servers and have a GPO created in those containers to disable auto updates. But as soon as I allow auto updates on the default domain policy, it overrides the GPO I created for the servers.
What am I doing wrong here?
Domain is a server 2003 domain, with 2 x Server 2003 domain controllers.
Computers are a mix of XP and windows 7.
Can anyone tell me what I'm messing up? I thought that by blocking inheritance on my server OU, I would keep the default domain policy from getting applied.