Computing.Net > Forums > Windows Server 2003 > Stop Logon Script From Affecting DC

Stop Logon Script From Affecting DC

Reply to Message Icon

Original Message
Name: DJX
Date: November 14, 2007 at 16:56:42 Pacific
Subject: Stop Logon Script From Affecting DC
OS: Windows Server 2003 R2 En
CPU/Ram: Core 2 Duo 3ghz with 2048
Model/Manufacturer: Custom
Comment:

I'm trying to get a logon script for USERS applied through group policy to NOT apply to domain controllers.

I set the domain controllers OU group policy to NOT overwrite but the main group policy with the script still applies to the DC.
I also tried blocking inheritance for the OU and it still doesn't work.

I can’t see any other way. There has to be something wrong.



Report Offensive Message For Removal


Response Number 1
Name: briantvit
Date: November 15, 2007 at 06:39:24 Pacific
Reply: (edit)

Place all your users in a seperate OU in Active Directory. Then apply the group policy only to that OU instead of your whole domain.


Report Offensive Follow Up For Removal

Response Number 2
Name: DJX
Date: November 15, 2007 at 08:00:04 Pacific
Reply: (edit)

I'll try that..but...

Am I doing something wrong?
Is this the normal behavior?

My previous attempts should have worked, according to regular understanding unless there is some sort of extra clause not written about it.


Report Offensive Follow Up For Removal

Response Number 3
Name: tvitbrian
Date: November 15, 2007 at 11:55:51 Pacific
Reply: (edit)

I'm assuming that you're placing the group policy on your entire domain rather then on just one OU. Or perhaps you're making the policy change on the default domain policy. Which wouldn't be a good idea.


Report Offensive Follow Up For Removal

Response Number 4
Name: DJX
Date: November 15, 2007 at 17:39:45 Pacific
Reply: (edit)

I got it...did what you said.

I have one GPO for the entire domain (global) with the master set of rules compatible with all machines.

I have one GPO on the OU Domain controllers

I have one GPO on an OU I made called "Member Machines" which I can use the "Computer" aspect of the GPO if I need to in the future.
I moved the applicable machines from "Computers" to this OU.

I have one GPO on an OU I made called "Member Users" which I use the "User" aspect of the GPO. I put the logon script in this one and moved the applicable users to this OU.

I just didn't want to move the machines from the default location because any time a new user or computer comes along; I have to manually add them to these custom OU's.

Baring all that, your suggestion worked and the policy is now working as I want it to.

Thanks.


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Stop Logon Script From Affecting DC

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




Have you ever used OpenOffice?

Yes, as my main suite.
Yes, occationally.
Yes, but only once.
No, never.


View Results

Poll Finishes In 6 Days.
Discuss in The Lounge