"Deny Apply Policy" for Domain Admin not working
hi,
thanks post.
from description, understand set security setting prevent domain group policies regarding roaming profile applying administrator roaming profile still used when logging in domain administrator.
as terminal service roaming profile configuration [computer configuration\administrative templates\windows components\terminal server\profiles\set path ts roaming user profile] computer configuration, applied when computer starts up. @ time, no users have logged on server. result, cannot configure whether computer component group policy applied according whether user belongs group.
for domain group policy, can set apply permission. example, can set user groups , computer accounts have apply group policy permission. computer components group policy, can use computer account permission setting restrict computers apply policy; however, user account permission setting not effective system cannot determine user group membership when computer policy applied. user components group policy, can use user account permission setting restrict users apply policy.
hope helps.
Windows Server > Group Policy
Comments
Post a Comment