Computer still getting Default Domain Policy even though it's not linked/inherited.

I'm testing with different GPOs and for some reason I'm still having GPOs apply to me from the "Default domain policy", even though my computer is in an OU that does not have the Default Domain Policy linked or inherited. It's also not enforced, so I'm not sure why it's still applying to my computer.

I have Block Inheritance checked on the OU my computer is in as well.

Is that normal behavior, do I need to add an explicit Deny Apply GPO for my Computer Object in this specific GPO's security tab?
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Will SzymkowskiSenior Solution ArchitectCommented:
Couple of things here...

This is not normal. When you use blocked inheritance it blocks the Default Domain Policy unless you Enforce it. You should not use Deny if you are using blocked inheritance.

You stated your "computer" is in an OU where blocked inheritance is linked to the OU. Does your Default Domain Policy have any user based policies? If they do they will be applied to your user account if you have not added your USER account to an OU where you are also using blocked inheritance.

Have you rebooted or run gpupdate /force? When you use rsop.msc and check the properties of Computer or User Configuration do any policies show up?

In my lab i have blocked inheritance on a few OU's and if computers or users are in these OU's they do not get any policies from parent OU's.


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
garryshapeAuthor Commented:
Omg I totally didn't think about that, my user account. Hahaha
Seth SimmonsSr. Systems AdministratorCommented:
I've requested that this question be closed as follows:

Accepted answer: 500 points for Spec01's comment #a40841939

for the following reason:

This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.