PyROm Posted September 9, 2016 Posted September 9, 2016 I am experimenting with direct access for teachers laptops. At the moment staff have full administrator rights to their laptops and the laptops arnt on the domain. To use the direct access I have to join them to the domain. I have created a new OU called direct access and blocked inheritance to that folder, putting all direct access laptops in that folder. I have linked the direct access clients gpo to that folder. The problem I have is that I wish to block all gpo`s other then the ones directly in the folder, to make the laptops as close to what they already have as possible (I intend on making them local admins). Our AD is divided up into 2 main branches, users and computers with all the user gpos in the users branch and all the computer gpos in the computer branch. Blocking inheritance on the direct access folder works to block the computer gpos but not user gpos. I have created a group, added the direct access laptop to that group and denied applying group policy to group on all the user gpos, however this has not worked. User gpos are still applying. Any ideas?
sted Posted September 9, 2016 Posted September 9, 2016 so you want the pc gpos to apply but not user ones? if so you want group policy loopback the link says old versions of windows but it still works https://support.microsoft.com/en-gb/kb/231287
PyROm Posted September 9, 2016 Author Posted September 9, 2016 Thanks for the reply, I actually want to stop all user policys from applying to the laptops in the specific group. I have tried loopback processing and it doesnt seem to have made a difference. Im not trying to replace existing policys with computer ones, I just want no policys applied (apart from the directaccess settings, but can work that out after blocking all policys).
sted Posted September 9, 2016 Posted September 9, 2016 Thanks for the reply, I actually want to stop all user policys from applying to the laptops in the specific group. I have tried loopback processing and it doesnt seem to have made a difference. Im not trying to replace existing policys with computer ones, I just want no policys applied (apart from the directaccess settings, but can work that out after blocking all policys). you van set loopback to either overwrite some or all settings set it to all and it should basically have no user policies applied 1
PyROm Posted September 9, 2016 Author Posted September 9, 2016 Thanks for that, changed the policy to replace and it works. I misunderstood the technet article and assumed that replace would only work if there were competing entries in the computer gpo.
Norphy Posted September 9, 2016 Posted September 9, 2016 I am experimenting with direct access for teachers laptops. At the moment staff have full administrator rights to their laptops and the laptops arnt on the domain. To use the direct access I have to join them to the domain. I have created a new OU called direct access and blocked inheritance to that folder, putting all direct access laptops in that folder. I have linked the direct access clients gpo to that folder. The problem I have is that I wish to block all gpo`s other then the ones directly in the folder, to make the laptops as close to what they already have as possible (I intend on making them local admins). Our AD is divided up into 2 main branches, users and computers with all the user gpos in the users branch and all the computer gpos in the computer branch. Blocking inheritance on the direct access folder works to block the computer gpos but not user gpos. I have created a group, added the direct access laptop to that group and denied applying group policy to group on all the user gpos, however this has not worked. User gpos are still applying. Any ideas? I don't like using loopback processing, it makes troubleshooting GPOs a real pain in the backside. You can instead set permissions on the GPOs and deny certain users, groups or computers access to them. Find the GPO in your GPMC, edit it. In the GP editor, right click on the policy name at the top of the tree and go to properties. Go to the security tab, add the computer where you don't want it to be applied and set the Deny entry there.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now