sloughman Posted September 18, 2013 Posted September 18, 2013 I wonder if anyone can help. I want to apply loopback processing. I have an OU for some computers which I have linked to a GPO with loopback processing merge enabled, in the User side of this loopback GPO I have made a few settings that oppose settings in the main staff GPO (eg I am enabling internet options menu as opposed to restricting them as this is what I want, I only want these opposed settings to apply for these computers in this GPO) When I log on to a computer in this loopback OU, the "opposed" settings do not apply ie internet options still disabled. My understanding is the computer in a loopback linked OU in merge mode will apply normal (in this case, staff policies and merge them with any applied in the user node, in my case allowing internet options menu, and that these take precedence over User's user settings, however this does not seem to be the case. Thoughts anyone, or am I missing something ?
jinnantonnixx Posted September 18, 2013 Posted September 18, 2013 (edited) We use loopback processing, the settings from the 'User' side of the 'Computer Settings' should override the 'User' side of the 'User Settings' (I hope I've stated that correctly). To check, run a simulation in AD (make sure you specify 'merge mode' within the wizard) and see your results. This will tell you the 'winning' policy. One thing Ive noticed, if you combine Internet settings from more than one GPO, things can get unreliable. Edited September 18, 2013 by jinnantonnixx
sloughman Posted September 18, 2013 Author Posted September 18, 2013 I think I've worked it out, but don't fully understand why. Whilst testing this, in the GPO security filtering box I added the test computer name (which resides in the test OU linked to the loopback GPO). I have changed the security filtering to Authenticated Users and it now works ! As an aside I noticed it also works if you put a user name AND the computer name in the security filtering box, and then log on to that computer as that user but not not if it is only the computer name in the security filtering, presumably to do with delegations ?
Davit2005 Posted September 18, 2013 Posted September 18, 2013 I have had many an occasion where I've had to add Domain Computers as well as a specific user account or group for various policies.
jinnantonnixx Posted September 18, 2013 Posted September 18, 2013 The best way of applying policies is using security groups. While editing the policy, remove the 'Apply group policy' tick from Authenticated Users (but leave the 'Read' flag - they have to be able to read) Create a security group (e.g. LibraryComputers) and set the 'Apply Group policy' tick to this group. When you place machines into this group they will get the policy.
plexer Posted September 18, 2013 Posted September 18, 2013 The best way of applying policies is using security groups. While editing the policy, remove the 'Apply group policy' tick from Authenticated Users (but leave the 'Read' flag - they have to be able to read) Can you clarify what you mean by that please? Ben
sted Posted September 18, 2013 Posted September 18, 2013 Can you clarify what you mean by that please? Ben i assume he means its better to apply settings limited with filtering than have to overide them with loopback which should always be a last resort (says someone who uses it lol)
jinnantonnixx Posted September 18, 2013 Posted September 18, 2013 (edited) I worded that paragraph poorly. I was trying to reconcile GPO targeting-by-filtering with loopback processing. Loopback last resort? Pfah! Edited September 18, 2013 by jinnantonnixx wrong link
Davit2005 Posted September 18, 2013 Posted September 18, 2013 Create a security group (e.g. LibraryComputers) and set the 'Apply Group policy' tick to this group. When you place machines into this group they will get the policy. I think the only problem with Computer Groups is that you have to remember to add the computer/s to the group, if however you need to apply the policy to all the computers in an OU it is better to use the built-in Domain Computers group.
jinnantonnixx Posted September 18, 2013 Posted September 18, 2013 (edited) I think the only problem with Computer Groups is that you have to remember to add the computer/s to the group, if however you need to apply the policy to all the computers in an OU it is better to use the built-in Domain Computers group. Yes indeed. You can nest groups, though. A group "All-workstations" can contain "Library-workstations" & "Science-workstation". Apply general stuff to the group "All-workstation", and perhaps library-specific settings to '"Library-workstations". Horses for courses, but we've found this approach very flexible. Edited September 18, 2013 by jinnantonnixx
sloughman Posted September 18, 2013 Author Posted September 18, 2013 The best way of applying policies is using security groups. While editing the policy, remove the 'Apply group policy' tick from Authenticated Users (but leave the 'Read' flag - they have to be able to read) Create a security group (e.g. LibraryComputers) and set the 'Apply Group policy' tick to this group. When you place machines into this group they will get the policy. What do you mean by the 'Apply group policy' tick, where is that ?
jinnantonnixx Posted September 18, 2013 Posted September 18, 2013 What do you mean by the 'Apply group policy' tick, where is that ? Here's a good article: How to Implement Group Policy Security Filtering :: Windows 2003 :: Articles & Tutorials :: WindowsNetworking.com I also found this about group policy best practices (includes a section on loopback) Group Policy Design | Group Policy content from Windows IT Pro
jinnantonnixx Posted September 18, 2013 Posted September 18, 2013 (edited) Another way of doing this would be Item Level Targeting. Edit your GPO, -User Configuration -> Preferences -> Control Panel -> Regional Options -Right-Click and Select New -Navigate to Common Tab -Check Item-Level Targeting and Press Targeting… Click New Item and feast your eyes upon the treasures herein. http://www.windowsnetworking.com/articles-tutorials/common/Group-Policy-Preferences-Understanding-Implementing-Item-Level-Targeting.html Edited September 18, 2013 by jinnantonnixx
sloughman Posted September 18, 2013 Author Posted September 18, 2013 This topic is drifting off what loop back processing is for , isn't it ?
jinnantonnixx Posted September 18, 2013 Posted September 18, 2013 (edited) This topic is drifting off what loop back processing is for , isn't it ? It is a bit. You can't beat a good tangent, though. Back to the topic, we use loopback, and for troubleshooting, group-policy simulation, rsop and gpresult have been useful. Edited September 18, 2013 by jinnantonnixx
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now