Jump to content

Recommended Posts

Posted

Hi,

 

Im looking at replacing Directaccess with AOVPN,

 

ive been looking through the following microsoft article on this https://learn.microsoft.com/en-us/windows-server/remote/remote-access/da-always-on-vpn-migration/da-always-on-migration-deploy

 

I would like to do a phased deployment to check it all works first, however DA is configured for the domain computers group with the GPO at the top level of out computers OU, so I dont think its going to be easy to either remove machines from the group or move their OU to be one not affected by the GPO.

 

has anyone else encountered this before ? im wondering if I can create a group which is denied permission on the DA config GPO and put the machines i wish to use the new VPN in there until everyone is complete ?

  • 5 months later...
Posted

Hi,

In your GPO, you can add an advanced permission that prevents a user or computer from applying the GPO.

In ur GPO go to delegation, and click on advanced (at the bottom of the windows) add or select User / Computer and select Block in the 'applied policy'

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...