apply ou policies to all users except domain administrators

Discussion in 'Active Directory' started by SANZMJ, Jun 20, 2005.

  1. SANZMJ

    SANZMJ Guest

    The policy applied to a OU to users is properly working, but when i do logon
    in a user´s pc the policy is applied as well.
    Then i denied apply group security permission from security tab from gpo,
    but it does not work.
    any help?

    Thanks.
     
    SANZMJ, Jun 20, 2005
    #1
    1. Advertisements

  2. Can you please try and reword that? I simply cannot understand what you
    mean?
     
    Paul Williams [MVP], Jun 20, 2005
    #2
    1. Advertisements

  3. SANZMJ

    SANZMJ Guest

    any help please?
     
    SANZMJ, Jun 21, 2005
    #3
  4. Hmmm, I'd not seen that KB before. I've written a similar one:
    -- http://www.msresource.net/content/view/15/47/

    Where are the administrative accounts located? Are they in the same OU? If
    they are in the same OU make sure you deny the apply permissions for a group
    that you define and add the administrators to that group.

    If they are elsewhere, then a different policy could be applying. Use RSoP
    to see what is being applied from where. let us know...
     
    Paul Williams [MVP], Jun 21, 2005
    #4
  5. SANZMJ

    SANZMJ Guest

    The domain admins group is in different OU. In this OU there are not any
    policies except the default domain policy.
     
    SANZMJ, Jun 22, 2005
    #5
  6. So run RSoP and see where the policy is being applied from. It could be
    linked to the Site. Or it might be coming from the DDP.
     
    Paul Williams [MVP], Jun 22, 2005
    #6
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.