Help with Removable Storage Access limits
hi crowd,
i'm having problem group policy that's been driving me nuts month now.
i need limit write access removable media.
due layout of our network, have multiple sites. site has computers connected internet, site b has computers not connected internet. each site has dc. i'm focusing on site now.
i created 2 group policies:
"removable read only" has "deny write access" group policy objects enabled.
"removable read , write" has "deny write access" group policy objects disabled.
i have created ou (lets call "a computers"), , added site a's computers it. linked 2 group policies created "a computers" ou. set scope on "removable read" "authenticated users". set scope on "removable read , write" "transfer agents" group.
now when login workstation, , run gpresult /v 1 of transfer agent users, reporting policies applied, not letting me write media. (im testing usb flash drives)
upon further investigation, gpresult reports "removable read , write" policy has deny_write enabled!.
what missing? have sworn working 1 day, , not next. tested many different combinations of group policies, , 1 seemed work, stop.
someone please me before loose rest of hair!
thanks!!
hi,
based on description, did mean link "removable read" gpo authenticated users added in security filtering ou, , link “removable read , write” gpo transfer agents group added in security filtering same ou ? if so, should current scenario. "removable read" gpo applied authenticated users cover "removable read , write" gpo applied group. "removable read" gpo deny permission takes precedence on "removable read , write" gpo.
you can create 2 groups in same ou, , apply 2 gpos corresponding group. way may solve problem. please refer following operation.
- in activity directory users , computers, create 2 groups , add every user different groups.
- create 2 gpos description in question , link same ou.
- in gpmc, click gpo, find security filtering in gpo scope in right show box.
- click add , add 2 different groups security filtering in different gpos.
please refer following article , more details.
filter using security groups
http://technet.microsoft.com/en-us/library/cc778238(v=ws.10).aspx
if have misunderstood, please don’t hesitate tell me.
hope helps.
best regards,
justin gu
Windows Server > Group Policy
Comments
Post a Comment