Jump to content

Recommended Posts

Posted (edited)

I've probably set up 100 servers and dozens of domains and never had this problem before. It's something I've either forgotten how to do, or I've missed a step as I've been setting the DC up. Google isn't helping so I thought I'd ask here.

 

To cut a long story short I've had to setup a new domain.

 

I've got the usual security groups:

 

Leadership

Office

Teachers

Pupils

(and so on)

 

Each of the above exist as a security group and also have their own OUs, with users being placed in the correct OU and the corresponding security group being placed in each correct OU and each user being placed into a member of the security group.

 

We also have mapped drives (again, the usual type of shares that seem to exist in most schools):

 

an O: drive mapped to \\server\office

P: mapped to \\server\pupils

L: mapped to \\server\leadership

T: mapped to \\server\teachers

and so on.

 

 

Each of the mapped drives is done with a GPO, and that is applied to the corresponding OU (so for example, there's a GPO in the Office OU that applies the Office Share drive to users in that GPO).

 

Here's the thing that's puzzling me (and that I've obviously missed something!): sometimes a user will require access to a mapped drive in another group. I.E. we might have a teacher that covers the office sometimes, so they need the \\office share, or an office manager who also needs access to the Leadership mapped drive.

 

Every time I've set this up before all I needed to do was add them to the corresponding security group and they'd automatically get the share. i.e. I'd add a teacher to the office security group (but they would remain in the teacher OU!) and the next time they logged in they'd get the mapped office drive (because I'd added them to the office security group).

 

That isn't' working. I'm having to create them their own OU and create a new GPO which manually maps both the office and teacher drives using a brand new GPO.

 

Thankfully at the the minute I'm still only a couple of days into building the domain, so this hasn't been a major issue (only a couple of users have come to me and said they require access to resources outside of their OU), but obviously this can't continue otherwise we end up with 50+ security groups and OUs for each combination of user that requires access to drives outside of their current OU.

 

I feel like a dunce because I've obviously missed something really obvious! Any suggestions?

Edited by Cazale
Posted
Well in this case I would have one Group Policy Object an OU level up from where you have with Item-level targeting restricted by specific OU and an or section by Security Group.
  • Thanks 1
Posted

I'm not sure that can work without Item-level targeting, but I'm often wrong!

 

To achieve this, I use Item-level targeting (in GPP Drive Maps, on the Common tab). This allows me to apply a drive mapping GPO at a root level (so applicable to all staff, say) then only apply it if the staff member is a member of a security group. It's effectively what yours is doing - and may be what you currently have on your old domain and you've missed it.

  • Thanks 1
Posted
I'm not sure that can work without Item-level targeting, but I'm often wrong!

 

To achieve this, I use Item-level targeting (in GPP Drive Maps, on the Common tab). This allows me to apply a drive mapping GPO at a root level (so applicable to all staff, say) then only apply it if the staff member is a member of a security group. It's effectively what yours is doing - and may be what you currently have on your old domain and you've missed it.

 

That makes complete sense and yes, that's almost certainly how I've done it on every other occasion. Many thanks!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...