Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Override the Local Group Policy?

Status
Not open for further replies.

deejflash

IS-IT--Management
Dec 12, 2003
13
US
I am in the process of implementing a new security policy. In order to test the effects of the changes I created a test OU with test users and machines.

I changed the password policy, however, the policy did not occur on the test machines. When I did a "gpresult" I notice that the Local Group Policy was taking effect over the Domain Group Policy. How do I make it so that the Domain G.P. overrides the local G.P.?

Here's the gpresult output...

Microsoft (R) Windows (R) 2000 Operating System Group Policy Result tool
Copyright (C) Microsoft Corp. 1981-1999


Created on Wednesday, July 27, 2005 at 3:08:23 PM


Operating System Information:

Operating System Type: Professional
Operating System Version: 5.0.2195.Service Pack 4
Terminal Server Mode: Not supported

###############################################################

User Group Policy results for:

CN=security2,OU=Test OU,DC=MintelChicago,DC=usdmm,DC=com

Domain Name: MINTELCHICAGO
Domain Type: Windows 2000
Site Name: Chicago

Roaming profile: (None)
Local profile: C:\Documents and Settings\security2

The user is a member of the following security groups:

MINTELCHICAGO\Domain Users
\Everyone
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
\LOCAL


###############################################################

Last time Group Policy was applied: Wednesday, July 27, 2005 at 3:07:42 PM
Group Policy was applied from: cougar.MintelChicago.usdmm.com


===============================================================


The user received "Registry" settings from these GPOs:

Default Domain Policy



###############################################################

Computer Group Policy results for:

CN=MINTEL-ZWNRDNC7,OU=Test OU,DC=MintelChicago,DC=usdmm,DC=com

Domain Name: MINTELCHICAGO
Domain Type: Windows 2000
Site Name: Chicago


The computer is a member of the following security groups:

BUILTIN\Administrators
\Everyone
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
MINTELCHICAGO\MINTEL-ZWNRDNC7$
MINTELCHICAGO\Domain Computers

###############################################################

Last time Group Policy was applied: Wednesday, July 27, 2005 at 2:58:31 PM
Group Policy was applied from: cougar.MintelChicago.usdmm.com


===============================================================


The computer received "Registry" settings from these GPOs:

Local Group Policy
Default Domain Policy
Windows Updates


===============================================================
The computer received "Security" settings from these GPOs:

Local Group Policy
Default Domain Policy
Password policy


===============================================================
The computer received "EFS recovery" settings from these GPOs:

Local Group Policy
Default Domain Policy
 
if you have any settings set in the local policy that aren't defined in the domain policy, then the local settings will be applied.

Windows will apply a combination of all the policy settings if they don't overlap. If they do overlap (different policies define same settings), then the order will be from furthest to closest:
local machine policy, site policy, domain policy, OU policy. Which means anything in local that is also specified in the others will be overridden by those othersettings.

Aftertaf
We shall prevail, and they shall not
 
The password policy is defined in the Domain Policy, but the Local Policy still seems to be the one that the machine uses. Under Local Security Settings, the Local Settings are define by default and the Effective Settings are those which I defined in the Domain Policy.

Does this mean that somewhere along the way different policies are overlapping? Could it be the default domain policy even though I had select No Override under the test OU Domain Policy?
 
password policy is defined in the Domain Policy" and they can't be defined anywhere else.

some gpo settings, namely account security ones, are only on a domain level, and not possible to set different policies within a domain.

Aftertaf
We shall prevail, and they shall not
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top