Jump to content

Recommended Posts

Posted

Hi folks,

 

I have some domain joined laptops that I need students to be able to take home.

 

We have a GPO that's at the level of the user OU that applies a fixed start menu based on a scope of authenticated users - that start menu is located on a domain share, so it's no use to the students that take the laptops home.

 

The laptops being taken home are in their own OU, and have some settings applied for Smoothwall cloud filtering. As part of the GPO applying in that folder there's a setting to change where the start menu is located, but the issue is I think that the above GPO applies *after* the home laptop OU because it's based on authenticated user.

 

Is it possible to get the second GPO to apply after the first, even though they're in separate unconnected OUs?

 

Thanks

Posted
Actually, both GPOs apply to Authenticated Users. The second GPO is also set to apply to a group of on-site PCs. I'm going to try putting the home laptops in their own security group, then add that to the scope of the first GPO. Not sure what else to try other than that.
Posted
There won't be a vast number, but as I'm adding them to a group anyway presumably I can deny the group? Although I still need the other GPO to apply. Weird request!
Posted
If you have a GPO linked just to these laptops and you set that as Enforced, it will override any conflicting settings that are in the inherited GPO. I think that's what you're after? (Based off a very tired read through the question at a silly time in the morning!)
  • Thanks 1
Posted

Definitely sounds like it, I'll try that. Thanks!

 

I'm doubting myself now. If a GPO is linked to an OU then it applies to any device/user in that OU, right? Otherwise would seem a bit pointless linking them to OUs!

Posted
Yes, assuming you haven't changed the permissions on it or used a WMI filter, it will apply to everything in that OU, and in any child OUs (unless you block inheritance)
  • Thanks 1
Posted
Thanks both, it seems to be working. It's a bit janky, in that my alternative redirected start menu and desktop aren't taking effect, but the usual redirected start menu and desktop aren't taking effect either and that's the key thing as it relies on being on the LAN. The Smoothwall cloud filtering has been tested, and that's still working, which is a key part of it. Will test anyway with the students that are taking the laptops...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...