Computing.Net > Forums > Windows 2000 > Policies for all users except admins

Policies for all users except admins

Reply to Message Icon

Original Message
Name: Mark Ebrey
Date: August 19, 2001 at 06:58:15 Pacific
Subject: Policies for all users except admins
Comment:

I have used mmc > user configuration > administrative templates to enable various desktop features (i.e. hide my docs icon) but this policy also applies to administrative logons as well. How do i apply this policy to the users group only?


Report Offensive Message For Removal

Response Number 1
Name: Mike W
Date: August 19, 2001 at 09:56:10 Pacific
Subject: Policies for all users except admins
Reply: (edit)

There are a couple methods:

One way is to create a security group. Add all user accounts for which you do not want the policy to apply. From the Properties page of the GPO select the Security tab and add the group you just created. Give this group "Deny" apply group policy permission.

The other method is to create a security group to which you add all users who you wish the GPO to apply. From the GPO Properties page from the Security tab Add this group and give it "Allow" Read and "Allow" Apply Group Policy permissions. Then remove the Authenticated Users Group.

Keep in mind that it is having the Read and Apply Group Policy permissions that control whether a policy is applied to a user or computer. And that the Deny permission takes precedence.

-MW


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Policies for all users except admins

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software