We help IT Professionals succeed at work.

Windows Default Domain Policy in Active Directory

61 Views
Last Modified: 2020-07-23
Can we block the Default Domain Policy in Active Directory?

If yes, how?
Comment
Watch Question

DrDave242Principal Support Engineer
CERTIFIED EXPERT

Commented:
If you want to block it for a set of users and/or computers, you can create a new OU, place those objects in it, and enable Block Inheritance on the OU.

There are other ways to block GPOs, but note that this sort of thing can cause confusion, especially (speaking from experience here) when you're troubleshooting a Group Policy issue and aren't aware that inheritance has been blocked somewhere.

CERTIFIED EXPERT
Distinguished Expert 2019

Commented:
The obvious question in an environment that facilitates single point management, why?

Do you have an error and want to reset it?

You can deny Access to the policy..
GiboSystems Engineer

Author

Commented:
The MS Edge group policy was configured in the default domain policy & I linked another different MS Edge group policy to test in an OU & blocked the inheritance, but still the MS Edge group policy from the the default domain policy persists?
CERTIFIED EXPERT
Distinguished Expert 2019

Commented:
Mark the ms edge policy in the O?u enforced.
This will make the OU ms edge settings supplant the default domain policy settings.

Additionally, use GPmC on the server to confirm which is the winning GPO.
GiboSystems Engineer

Author

Commented:
Tried enforced & didn't work, ran gpupdate /force & gpresult /r says my MS Edge Group policy was applied & filtered out the default domain policy
CERTIFIED EXPERT
Distinguished Expert 2019
Commented:
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION
CERTIFIED EXPERT
Distinguished Expert 2019

Commented:
One option is to create a fo sin side ms edge policy and apply it to the top of the domain excluding the users, groups to which you do not want it applied, could be using wmi filter.
Remove the entries from the default domain policy
.....
Gpupdate ...and retry. It might take two attempts..
CERTIFIED EXPERT
Distinguished Expert 2019

Commented:
Remove the settings from the default Dom policy. Done.
GiboSystems Engineer

Author

Commented:
Thank you for all your prompt response, appreciate much for all your help!

Gain unlimited access to on-demand training courses with an Experts Exchange subscription.

Get Access
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Empower Your Career
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.