Avatar of Gibo
Gibo asked on

Windows Default Domain Policy in Active Directory

Can we block the Default Domain Policy in Active Directory?

If yes, how?
Windows OSActive DirectoryWindows 10AzureWindows Server 2016

Avatar of undefined
Last Comment

8/22/2022 - Mon

If you want to block it for a set of users and/or computers, you can create a new OU, place those objects in it, and enable Block Inheritance on the OU.

There are other ways to block GPOs, but note that this sort of thing can cause confusion, especially (speaking from experience here) when you're troubleshooting a Group Policy issue and aren't aware that inheritance has been blocked somewhere.


The obvious question in an environment that facilitates single point management, why?

Do you have an error and want to reset it?

You can deny Access to the policy..

The MS Edge group policy was configured in the default domain policy & I linked another different MS Edge group policy to test in an OU & blocked the inheritance, but still the MS Edge group policy from the the default domain policy persists?
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck

Mark the ms edge policy in the O?u enforced.
This will make the OU ms edge settings supplant the default domain policy settings.

Additionally, use GPmC on the server to confirm which is the winning GPO.

Tried enforced & didn't work, ran gpupdate /force & gpresult /r says my MS Edge Group policy was applied & filtered out the default domain policy

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question

One option is to create a fo sin side ms edge policy and apply it to the top of the domain excluding the users, groups to which you do not want it applied, could be using wmi filter.
Remove the entries from the default domain policy
Gpupdate ...and retry. It might take two attempts..
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.

Remove the settings from the default Dom policy. Done.

Thank you for all your prompt response, appreciate much for all your help!