Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi
I am new to group policies with W2KS, i have used policies with NT4, but am having troubles with 2KS.
I have gone into the Group policies of the domain and removed the Default.
I have then created 3 OU's, 'Admins', 'Standard' and 'Restricted'.
I have then gone into the group policies of all three and set my policies up for the respective groups (ie: restricted have no desktop icons, cant access C drive etc, admin has no restrictions, but the My Documents folder is redirected to the users share, the "Logoff" option is enabled on start menu etc)
*I have then created users inside these OU's, and if i log onto the server as a user in the "admins" group, all is well, policies are set, everything is as it should be.
*If i add a restricted user to the 'domain admins' group to allow interactive login, and log on as one of these groups, they have no start menu options, no desktop, are restricted as they should beBUT
(here comes the BUT)If I log onto another computer..... you got it.... NO POLICIES!!!!
I have tried this on multiple computers, and no luck. the policies wont propegate.
What have I done wrong?
Have I missed somethingAny help appreciated
Thanks
Matt

so..are you saying that you have OU's and then place computers and users inside them. then you create the GPO and link the GPO to the OU's.
sounds to me that you need to go to the ACL of the GPO and add the appropriate groups. remember that any group set to DENY read and apply permissions will allways have a higher priority than any other permission they might get.
1.) set the EVERYONE group to READ AND APPLY
2.) set any other groups that dont need the GPO, like the administrators group to DENY READ AND APPLY permission.
the everyone group now has the GPO apply to them and the administrators do NOT get the GPO.
allso,
are you setting a USER or COMPUTER GPO. this might be the reasoon that you logging into a certain computer does NOT give the desired results.
good luck
AJ"ye of itchy azz hole, have stinky finger"

Hey
What I have done is,
*Created an OU
*Right-clicked the OU and gone properties
*Gone to "Group Policies"
*Clicked "NEW" and gave it a name
*Double clicked the GP to modify the policy
*Modified the policy, closed out and OKed off
*Added users inside this OU.I havnt added PC's to the OU, but i tried this and didnt do anything anyway.
I tried adjusting the permissions and to no avail.
Im not sure about the "ACL" you mentioned.
Is there a "step-by-step" guide to doing this that isnt written by microshaft?
I am just getting a little frustrated as i know that it is most probably something simple and i just cant seem to get it going. Why cant it be like NT4 where i just use poledit? EASIER! ehheheehehThanks for the help, and thanks in advance for any more to come.
Thanks
Matt

I too am having the same problem applying the group policies to the local pc's....I think I have clicked on and modified everything that could be it....but it looks like I am missing something somewhere! I have done almost the exact same thing as Matt has done!
Any help would be great!Thanks!

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |