Jump to content

Recommended Posts

Posted

Hi Guys,

 

Our AD structure and GPO's were setup by a third party company, I'm new in the role and I'm trying to get my head round how everything is connected just so I've got a better understanding myself. I've got some experience of GPO's but I'm no expert.

We have a setup where staff can access C drives and Control Panel but students cannot. That's fine, and I'm happy how that all works in the GP structure we have two different GPO's that dictate which domain users can access what.

 

However, I am wanting to allow access to the C drive and Control Panel for students in one particular IT suite. The PC's in the IT suite already exist in their own folder in our AD, so it's a simple case of dropping the correct GPO into their folder in group policy management.

Here's what I was going to do. Copy the Student GPO which resides in root users folder, modify the GPO to allow access to the control panel and C drive. Add this modified GPO to the relevant IT suite folder in GPM and bingo...

However, I tested this and it didn't work. Students in that IT suite still have no C drive access. Do the GPO's in the root user folder override any other GPO's in daughter folders? Thereby overriding my modified GPO?

 

What is the best way to add a GPO so that students can access their C drive only in a specific list of PC's?

 

I hope I've explained myself sufficiently. If any of you are wondering...yes I could ring up our 3rd party company who set this up but that's not the point :) I want to learn myself! I've got so far but am now stuck.

 

Many thanks.

Guest obsidianpillar
Posted
Thanks both of you - Loopback processing is exactly what I need to apply in this situation. Looks like I've got a bit of reading to do but it looks like just the ticket.

 

Basically, if your not wanting to do reading set user processing to merge, and then apply user policy settings. That way, your existing policies stand as set to the users, but you set the policies now that apply on a computer level. Don't overwrite user policy settings as then they will only receive the settings that you explicitly apply in that policy.

 

Tom

Posted
Basically, if your not wanting to do reading set user processing to merge, and then apply user policy settings. That way, your existing policies stand as set to the users, but you set the policies now that apply on a computer level. Don't overwrite user policy settings as then they will only receive the settings that you explicitly apply in that policy.Tom

But if you merge isn't it going to cause conflicts and possible errors with the original user (hide the C drive and Cont Panel) policy?

I'm not saying it will, I'm just asking the question.

Guest obsidianpillar
Posted
But if you merge isn't it going to cause conflicts and possible errors with the original user (hide the C drive and Cont Panel) policy?

I'm not saying it will, I'm just asking the question.

 

If you merge, it applies the policy in addition to the existing user policies configured to users logging onto the workstation. If you "Enforce" the loopback policy, it takes presidency over any other policies, user or otherwise.

Posted
If you merge, it applies the policy in addition to the existing user policies configured to users logging onto the workstation. If you "Enforce" the loopback policy, it takes presidency over any other policies, user or otherwise.

 

So Tom, are you saying I'm better off creating a new clean GPO with just the changes to allow C drive and control panel and set this to merge with the Student GPO?

I was afraid that if I did this, any other "not configured" items in the new loopback GPO would override the other settings in the Student GPO. I want to retain the other settings in Student GPO but just override C drive and Control Panel.

 

I've tried this out and set to replace at the moment but it doesn't seem to be taking effect. When the little darlings go home I'll try it out with merge.

Thanks again.

Guest obsidianpillar
Posted (edited)
So Tom, are you saying I'm better off creating a new clean GPO with just the changes to allow C drive and control panel and set this to merge with the Student GPO?

I was afraid that if I did this, any other "not configured" items in the new loopback GPO would override the other settings in the Student GPO. I want to retain the other settings in Student GPO but just override C drive and Control Panel.

 

I've tried this out and set to replace at the moment but it doesn't seem to be taking effect. When the little darlings go home I'll try it out with merge.

Thanks again.

Hi, I'd create a new GPO, linking it to whichever OU your computer objects reside in. Then, set the processing mode to "merge". You can now edit the user settings and they will propagate to any computers within the OU.

 

Additionally, out of course of habit I set this policy to "Enforced" on the GPO itself (right click, Enforced), i.e it takes precedence over any other policy. The "Replace" setting within the policy itself only explicitly uses the settings you apply within that specific GPO, meaning that any user settings specified elsewhere will not be processed.

 

In our case, we have to do some personalisation settings on our RDS Servers. I can attach a screenshot of my configured policy should you run into any more trouble.

 

Hope this helps,

 

Tom.

Edited by obsidianpillar
Additional detail + clarification added.
Posted

Hi friendlytechnician, are you sure you want to enable this level of access to all students? I only ask because it's most likely that they need to use the control panel and access the c:\ drive for only a small portion of one term and very likely to be just one year group at that.

 

The suggestions so far are really good but I would look more at using security groups, one for the PCs and one for the students you want to have access. Create a new gpo with only the settings you require and set the security filter to your two new groups only after removing authenticated users first. Apply it at the user ou level ( you possibly have the students split into year ou's ) the only thing you need to do then is move the order of precedence of the new gpo so that it gets applied last, this will then overwrite the default settings when the users in your new user security group logon at the PCs in the new PCs security group.

 

When these users logon at any other PCs around the school they will not get the new gpo settings applied as the other PCs have no read access to the new gpo and therefore cannot apply it. This is only true if you have removed the authenticated users from the new gpo though so make sure you that step first.

  • Thanks 1
Posted
I still can't get this to work, I've tried various combinations of merge, replace and enforce, but all I succeeded doing was removing my own admin permissions to access the C drive! Our OU has several other GPO's in it. I'm beginning to think that there is more than one GPO that is restricting the access to C drive and Control Panel. I'm going to contact the 3rd party who set this up and see what they suggest, but thanks for all your help. I learned a load about settings I'd never before considered and am better equipped now to explain what I want.
Guest obsidianpillar
Posted
I still can't get this to work, I've tried various combinations of merge, replace and enforce, but all I succeeded doing was removing my own admin permissions to access the C drive! Our OU has several other GPO's in it. I'm beginning to think that there is more than one GPO that is restricting the access to C drive and Control Panel. I'm going to contact the 3rd party who set this up and see what they suggest, but thanks for all your help. I learned a load about settings I'd never before considered and am better equipped now to explain what I want.

 

If you can't get anywhere with them, do a resultant set of policy inside of an MMC window and see what policies are applying where. Hopefully that can give you some pointers.

 

Hope you get it sorted, glad we could have helped.

 

Tom

Posted
run rsop.msc as a user you want to get control panel and look what settings are applied it will even tell you which policies settings it is applying for every setting and show precedence. It may must be the order of the gpos is such yours is getting over ridden (you could also try enforcing the policy)
Posted (edited)

Your best bet would be to use the command line utility called gpresult so that you can see what gpo's are being applied and then drill down in the generated report to see which gpo is setting access to the C:\ drive and control panel.

 

you can generate a report and find what settings are taking effect on a classroom machine if you know the machine name and also the account name of a user who has logged on at the computer.

 

so assuming you computer is called pc1 and your user account is called pupil1 you would the start a command prompt and run as administrator and the command would be

 

gpresult /s pc1 /user pupil1 /h c:\mygporeport.html

 

this command is to be run from a command prompt on your technician computer.

 

once you have this information you should have a better understanding of what is being applied at the workstation and you should see some differences if you alter your GPO.

 

Did you create a new GPO or alter an exisiting one.

 

If you are keen to learn more on group policy i would recommend "Group Policy: Fundamentals, Security, and the Managed Desktop" by Jeremy Moskowitz as it is a very good reference book i found.

Edited by jcubbin

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...