Jump to content

Recommended Posts

Posted

Our active directory structure I am sure is designed like many others in that we have an OU structure:

 

School Name -> Users -> Pupils -> Year Groups

 

Each student is in a Year Group OU named 7 to 13.

 

We apply group policies at various levels:

 

At the year group OU there are no policies applied.

 

At the Pupils OU level we apply a policy for:

desktop redirection

software restriction

 

At the Users OU level we apply a policy for:

Internet Explorer

Locking down the PC

Google Chrome

*and some others

 

The locking down the PC policy sets a common desktop background for all pupils

 

We have had a new year 12 join the school who is visually impaired.

 

I need to either give her the ability to change the background or force her to use something more suitable to her needs.

 

I can't move her out of the year 12 OU as many other things rely on her being there, like papercut, smoothwall filtering etc.

 

Is there a way to prevent the lockdown policy applying to her and create a new lockdown policy which ONLY gets applied for her?

Posted

1) Create a lockdown policy with the required settings;

2) Link it to the appropriate OU, but with a higher priority than the existing policy;

3) Change the security on the policy by removing "Authenticated Users" and adding just her user account.

  • Thanks 1
Posted

I would create a policy and link at the top level of pupils that allows background changing (or whatever settings you choose)

Make it enforced so it takes priority over other GPOs

In the scope tab remove Authenticated Users and add a group containing the pupil, something like VI_Support (I'd use a group so the settings can easily be reused should you have another with similar needs)

 

This way, even though the policy applies to all pupil OUs, it only gets applied to pupils in the VI_Support group.

  • Thanks 1
Posted
If you created a new OU under the year 12 on that changed the background that one would take priority I think.

 

^ This, I've had to do it in the past for SEN students.

Posted
^ This, I've had to do it in the past for SEN students.

 

I am just worried moving the student out of the year 12 OU to a lower nested one might break other things that expect her to be in the year 12 OU....

Posted
1) Create a lockdown policy with the required settings;

2) Link it to the appropriate OU, but with a higher priority than the existing policy;

3) Change the security on the policy by removing "Authenticated Users" and adding just her user account.

 

Think this might be the way to go....

Posted
You could leave her there, and create a new GPO with the settings you need at the pupils OU level. Create an AD Group - "Students - Visual Settings Override" or something, and add her to it. Then, as above, remove Authenticated users from the Security Filtering, and add the name of your new group. That will stop you having to move the user around - and if you need to use I again, or have other students in other year groups in future...its easier...
Posted
It shouldn't. GPO's apply in order or presidence from the lowest OU up. LDAP queries return contents of OU and sub-OUs. In short, the student should for effectively remain a member of the 12 OU with the new GPO on the sub OU overriding higher up settings.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...