Is it possible to link a group policy to an AD secuirity group rather than an OU? I am sure that they used to do this in my old job, but cant see how you can do it. Anyone know?
Thanks, Im still not clear how to implement this on a DC.
Can anyone provide more information? Ive already searched the internet but couldnt find anything to help.
I have created a policy, linked it to an OU and created a secuirity group called GPO policy. Where do i configure secuirity rights for the group and which rights do I need to grant?
If you go to the properties of a GPO, you have the tab "Delegation". Here you can provide information which users / computers can modify, read the policy.
If users or computers are not listed here, they have no rights on the policy and threfore the policy will not "run" for those users.
Just 2 cents: anyway GPO applied to OU, not to group. But when applied, - filtered by group. -> if group member object not into OU to which policy applied, - policy would not apply to it!
WBR, Vadim V. Petukhov,
MCSE2003, CCEA4.0
vadimp@yandex.ru
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.