123ArticleOnline Logo
Welcome to 123ArticleOnline.com!
ALL >> System-Network-Administration >> View Article

Filtering Gpo Scope With Security Groups

Profile Picture
By Author: Jasmine
Total Articles: 286
Comment this article
Facebook ShareTwitter ShareGoogle+ ShareTwitter Share

As discussed in Lesson 1, the policies in a GPO apply only to CompTIA A+ Essentials users who have the Read and Apply Group Policy permissions for the GPO set to Allow. However, by default, all users in the Authenticated Users group have Read and Apply Group Policy permissions set to Allow for all new GPOs. This means that by default, all users are affected by the GPOs set for their domain, site, or OU regardless of the other groups in which they might be members. Therefore, there are two ways of filtering GPO scope:
Clear the Apply Group Policy permission (currently set to Allow) for the Authenticated Users group, but do not set this permission to Deny. Then determine the groups to which the GPO should be applied and set the Read and Apply Group Policy permissions for these groups to Allow.
Determine the groups to which the GPO should not be applied and set the Apply Group Policy permission for these groups to Deny.
Recall from Chapter 9, "Administering Active Directory Objects," that if you deny permission to a user to gain access to an object, the user will not ...
... have that permission, even if you allow the permission for a group of which the user is a member.
To filter the scope of a GPO, complete the following steps:
1.Access the Group Policy Object Editor for the GPO.
Right-click the root node, and then click Properties.In the Properties dialog box for the GPO, click the Security tab, shown previously in Figure 10-14, and then click the security group through which to filter this GPO.
If you need to change the list of security groups through which to filter this GPO,you can add or remove security groups using Add and Remove.
4.Set the permissions as shown in A+ Exams, and then click OK.
To specify the No Override option, complete the following steps:
1.Open the Active Directory Users And Computers console to specify the No Override option for a domain or OU, or open the Active Directory Sites And Services
console to specify the No Override option for a site.
2.In the console, right-click the site, domain, or OU to which the GPO is linked,click Properties, and then click the Group Policy tab.
3.In the Properties dialog box for the object, in the Group Policy tab, select the GPO, and then click Options.
In the Options dialog box for the GPO, shown in Figure 10-18, select the No Override check box to specify that other GPOs should be prevented from overriding
settings in this GPO, and then click OK.
The east.humongous.com administrator, Sharon Salavaria, has configured a GPO, named Required_Set, that she says is mandatory for her entire domain. She also has several GPOs that she's configured at the domain, but she doesn't consider those policies mandatory. The Administration and Regional Sales OU administra?tors have blocked policy inheritance to their OUs. Sharon wants to be sure that they receive at least the Required_Set GPO. What should she clo?
Sharon should configure the Required_Set GPO for No Override. The Required Set MCSE exams will be inherited by all the OUs, but the administrators of those OUs will not have to accept the other GPOs she has configured.

Total Views: 284Word Count: 524See All articles From Author

Add Comment

System/Network Administration Articles

1. Fiber Fused Biconical Taper Systems And Fiber Cable Cutting Machine Potential
Author: Ryan

2. Understanding Polarization Maintaining Fiber Rotation Systems And Their Applications
Author: Ryan

3. Cat6a Patch Cable: The Best Preference For Comprehensive Cabling
Author: Ryan

4. A Brief Idea About The Mtp/mpo Cables And Their Use
Author: Ryan

5. 5 Reasons Why A Smart Bus Ticketing System Is The Future Of Public Transport
Author: Limon

6. How To Implement Technology In Your Inbound Call Center?
Author: DialDesk

7. How To Choose An Enterprise Help Desk It Support Company
Author: Entrust Network Services

8. Cost-effective Network Solutions For Offices In Singapore
Author: Entrust Network Services

9. Choosing Between Uv Light And Heat Ovens For Superior Performance
Author: James

10. The Right Tools And The Right Radius Are Vital In A Fiber Optic Polishing Process
Author: James

11. Lc And Sc Connectors Explained: Which Fiber Connection Is Right For You?
Author: James

12. A Closer Look At Armored Fiber Patch Cables
Author: James

13. The Essential Guide To Fiber Connectors: Sc, Fc, Lc, And St Explained
Author: Ryan

14. Wireless Network Setup Solutions For Offices By Entrust Network
Author: Entrust Network Services

15. Pcb Manufacturing: Understanding The Burn-in Test Process
Author: Ryan

Login To Account
Login Email:
Password:
Forgot Password?
New User?
Sign Up Newsletter
Email Address: