talksr Posted December 7, 2018 Posted December 7, 2018 Hi there, I have followed the online guides for disabling run and command prompt on windows 10 computers by using Group Policy on our Windows Server 2016. These are my settings in Group Policy: I have gpupdated my testing station, added specific users to the policy in security filtering under scope and nothing is making a difference. Users are still able to open the run window and run command prompt. Where am I going wrong?
Reboot_IT Posted December 7, 2018 Posted December 7, 2018 Is the policy applied to a User OU? It looks as if it's just linked to your laptop OU? 1
talksr Posted December 7, 2018 Author Posted December 7, 2018 (edited) Is the policy applied to a User OU? It looks as if it's just linked to your laptop OU? Thank you. That now works perfectly. For the future...If you make any config changes under User Configuration on Group Policy, do you have to link it to the OU that the users reside in? As I have other GPOs with User Configuration items in, they are not linked to user groups, but they still apply and work ok. Edited December 7, 2018 by talksr
PD1279 Posted December 7, 2018 Posted December 7, 2018 (edited) I personally have sets of GPOs and the Computer Config is ALWAYS separate to the User Config with the other part disabled just in case. Makes it much easier to maintain. Yes you have more of them but then you know where to look if it is a computer or user issue In answer to your question yes the User GPO would have to be in or a 'Parent of' the OU the user is in. If one of yours is working I would assume it is in a parent OU hence why it propagates down to where the user is Edited December 7, 2018 by PD1279 2
Reboot_IT Posted December 7, 2018 Posted December 7, 2018 As above, I always separate User and Computer policies too! 1
talksr Posted December 13, 2018 Author Posted December 13, 2018 As above, I always separate User and Computer policies too! Ok thanks both. I understand. So even in this example, whereby I am using a GPO to both install a Google Chrome msi and set it as a default, I would need to split these and have: A computer policy for the actual install of the MSI A seperate user policy for the setting of Chrome as a default browser Would be grateful if you could just confirm that?
PD1279 Posted December 14, 2018 Posted December 14, 2018 Yes as they are two different actions 1 - Installing Software 2 - Configuring software Makes for much better managment and as long as other part disabled Plus you may need different configs for Pupils / Staff - I for example have two Proxies controlled by the LA and one if for staff and one Pupils, so when each logs in they get the correct Proxy but the installation of the software is the same on that one machine
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now