"Deny Apply Policy" for Domain Admin not working


i have gp on ou contains terminal servers.  the gp specifies path roaming profile used when accessing terminal server.  i have "apply policy" security setting domain admins set deny per kb816100 how prevent domain group policies applying administrator (windows server 2003).  
however, when log in domain administrator roaming profile used.  i used rsop @ setting romaing profile path , says being set gp on terminal servers ou.

can explain why deny isn't working?

thanks

hi,

 

thanks post.

 

from description, understand set security setting prevent domain group policies regarding roaming profile applying administrator roaming profile still used when logging in domain administrator.

 

as terminal service roaming profile configuration [computer configuration\administrative templates\windows components\terminal server\profiles\set path ts roaming user profile] computer configuration, applied when computer starts up. @ time, no users have logged on server. result, cannot configure whether computer component group policy applied according whether user belongs group.

 

for domain group policy, can set apply permission. example, can set user groups , computer accounts have apply group policy permission. computer components group policy, can use computer account permission setting restrict computers apply policy; however, user account permission setting not effective system cannot determine user group membership when computer policy applied. user components group policy, can use user account permission setting restrict users apply policy.

 

hope helps.



Windows Server  >  Group Policy



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file