Jump to content

Recommended Posts

Posted

I wonder if anyone can help.

 

I want to apply loopback processing.

 

I have an OU for some computers which I have linked to a GPO with loopback processing merge enabled, in the User side of this loopback GPO I have made a few settings that oppose settings in the main staff GPO (eg I am enabling internet options menu as opposed to restricting them as this is what I want, I only want these opposed settings to apply for these computers in this GPO)

When I log on to a computer in this loopback OU, the "opposed" settings do not apply ie internet options still disabled.

 

My understanding is the computer in a loopback linked OU in merge mode will apply normal (in this case, staff policies and merge them with any applied in the user node, in my case allowing internet options menu, and that these take precedence over User's user settings, however this does not seem to be the case. Thoughts anyone, or am I missing something ?

Posted (edited)

We use loopback processing, the settings from the 'User' side of the 'Computer Settings' should override the 'User' side of the 'User Settings' (I hope I've stated that correctly).

 

To check, run a simulation in AD (make sure you specify 'merge mode' within the wizard) and see your results. This will tell you the 'winning' policy.

 

One thing Ive noticed, if you combine Internet settings from more than one GPO, things can get unreliable.

Edited by jinnantonnixx
Posted

I think I've worked it out, but don't fully understand why. Whilst testing this, in the GPO security filtering box I added the test computer name (which resides in the test OU linked to the loopback GPO). I have changed the security filtering to Authenticated Users and it now works !

 

As an aside I noticed it also works if you put a user name AND the computer name in the security filtering box, and then log on to that computer as that user but not not if it is only the computer name in the security filtering, presumably to do with delegations ?

Posted

The best way of applying policies is using security groups.

 

While editing the policy, remove the 'Apply group policy' tick from Authenticated Users (but leave the 'Read' flag - they have to be able to read)

 

Create a security group (e.g. LibraryComputers) and set the 'Apply Group policy' tick to this group. When you place machines into this group they will get the policy.

Posted
The best way of applying policies is using security groups.

 

While editing the policy, remove the 'Apply group policy' tick from Authenticated Users (but leave the 'Read' flag - they have to be able to read)

 

 

Can you clarify what you mean by that please?

 

Ben

Posted
Can you clarify what you mean by that please?

 

Ben

 

i assume he means its better to apply settings limited with filtering than have to overide them with loopback which should always be a last resort (says someone who uses it lol)

Posted (edited)

I worded that paragraph poorly.

 

I was trying to reconcile GPO targeting-by-filtering with loopback processing.

 

Loopback last resort? Pfah!

Edited by jinnantonnixx
wrong link
Posted

 

Create a security group (e.g. LibraryComputers) and set the 'Apply Group policy' tick to this group. When you place machines into this group they will get the policy.

 

I think the only problem with Computer Groups is that you have to remember to add the computer/s to the group, if however you need to apply the policy to all the computers in an OU it is better to use the built-in Domain Computers group.

Posted (edited)
I think the only problem with Computer Groups is that you have to remember to add the computer/s to the group, if however you need to apply the policy to all the computers in an OU it is better to use the built-in Domain Computers group.

 

Yes indeed. You can nest groups, though. A group "All-workstations" can contain "Library-workstations" & "Science-workstation". Apply general stuff to the group "All-workstation", and perhaps library-specific settings to '"Library-workstations". Horses for courses, but we've found this approach very flexible.

Edited by jinnantonnixx
Posted
The best way of applying policies is using security groups.

 

While editing the policy, remove the 'Apply group policy' tick from Authenticated Users (but leave the 'Read' flag - they have to be able to read)

 

Create a security group (e.g. LibraryComputers) and set the 'Apply Group policy' tick to this group. When you place machines into this group they will get the policy.

 

What do you mean by the 'Apply group policy' tick, where is that ?

Posted (edited)

Another way of doing this would be Item Level Targeting.

 

Edit your GPO,

-User Configuration -> Preferences -> Control Panel -> Regional Options

-Right-Click and Select New

-Navigate to Common Tab

-Check Item-Level Targeting and Press Targeting…

Click New Item and feast your eyes upon the treasures herein.

 

http://www.windowsnetworking.com/articles-tutorials/common/Group-Policy-Preferences-Understanding-Implementing-Item-Level-Targeting.html

Edited by jinnantonnixx
Posted (edited)
This topic is drifting off what loop back processing is for , isn't it ?

 

It is a bit. You can't beat a good tangent, though. ;)

 

Back to the topic, we use loopback, and for troubleshooting, group-policy simulation, rsop and gpresult have been useful.

Edited by jinnantonnixx

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...