round2it Posted March 2, 2012 Posted March 2, 2012 I have a default domain policy that supplies the proxy settings to machines (user configuration) I want to block this policy and then apply a new proxy I have blocked inheritance of the default policy but the user settings are still being passed through How do I block the user settings being passed through any help would be appretiated
Guest TheLibrarian Posted March 2, 2012 Posted March 2, 2012 You can disable user settings directly on the policy. Looking at the GPMC on Windows 7, you highlight the policy in the left hand pane and choose the details tab on the right hand pane then set the selection box called GPO Status. HTH
Willott Posted March 2, 2012 Posted March 2, 2012 You could place "enforce" on the downlevel policy 1
round2it Posted March 2, 2012 Author Posted March 2, 2012 Yes i have enforced the other policy but for some reason the default domain policy (user settings) is the winning policy (strange I know) Can I block The user settings only via a filter somehow?
Mr.Ben Posted March 2, 2012 Posted March 2, 2012 If your Users are in an OU you can 'Block Inheritance' of GPO's by right clicking on the Container 1
Willott Posted March 2, 2012 Posted March 2, 2012 Gpresult definitely shows it's coming from default domain policy and not a loopback on a machine targetted ou/gpo? 1
Guest TheLibrarian Posted March 2, 2012 Posted March 2, 2012 If the Default Domain Policy is still being processed after a block inheritance has been set it must mean the policy has been set as Enforced (right click the policy in the left hand panel of the GPO).
round2it Posted March 2, 2012 Author Posted March 2, 2012 The Default policy is not enforced When I block the policy it Blocks computer settings perfectly, But the user settings are still applied. This is simple stuff but its not doing as I ask with the user settings
ChrisMiles Posted March 2, 2012 Posted March 2, 2012 Err cant you just remove the old proxy settings? You should not use the default domain policy for applying non-default policies, create new policy objects for your custom policy settings and link them only where they should be applied. Applying policies at the domain level and then trying to override them complicates things for you and is generally going to slow down application at the client level. 1
Guest TheLibrarian Posted March 2, 2012 Posted March 2, 2012 Hold on, is this the Computer configuration to apply a machine proxy setting to all users? Make proxy settings per-machine (rather than per user) If so then all the filtering / block inheritance etc. isn't going to do anything.
round2it Posted March 2, 2012 Author Posted March 2, 2012 that is my next step I did not set this server up I just dont want to break the system while everyone is in.
round2it Posted March 2, 2012 Author Posted March 2, 2012 For some reason the proxy settings are set in the default domain policy ( i would have had it as a separate policy on the ous's required) this is the way to go i think am I correct thinking that any other settings that change the proxy will not apply due to the setting being in the default domain policy.
round2it Posted March 2, 2012 Author Posted March 2, 2012 Think this is the problem All Default Domain Policies Will win over sub policies and the proxy settings should be applied with a sub policy on the ou required.
chazzy2501 Posted March 2, 2012 Posted March 2, 2012 you should run the gpresult html option on a client and see what is happening. RSOP doesn't get everything! 1
round2it Posted March 2, 2012 Author Posted March 2, 2012 ah well email sent to everyone to say im going to break the system at 3pm today
6Foot2 Posted March 2, 2012 Posted March 2, 2012 (edited) Have you tried setting the User Group Policy Loopback Processing Mode to 'Replace'? http://img836.imageshack.us/img836/2227/usergrouppolicyloopback.jpg Edited March 2, 2012 by 6Foot2 Add punctuation. 1
6Foot2 Posted March 2, 2012 Posted March 2, 2012 never done that before could you elaborate Edit the new policy where the new setting you want to set is and go to: Computer Configuration/Policies/Administrative Templates/System/Group Policy Find the entry that says: User Group Policy Loopback Processing Mode Set this to 'Enabled' Also make sure that Computer Configuration for this GPO is enabled. The picture above summarizes this. HTH. 1
6Foot2 Posted March 2, 2012 Posted March 2, 2012 ah well email sent to everyone to say im going to break the system at 3pm today Just curious here: Did you save your network from breakage?
round2it Posted March 2, 2012 Author Posted March 2, 2012 Yes I did thanks Problem was the proxy settings in the default domain policy user configuration won every time in the gpo processing so no matter what i did with the gpos the default policy settings kicked in I removed all proxy settings from the default policy created 2 new gpos with proxy settings and applied to the pupils and staff accordingly one of the gpos i created had got corrupt some how so this was kind of some of my problem quickly recreated and all seems fine (tested the usual people office manager, head, heads pa and bursar all working correctly kids get the filtered connection staff get unfiltered (although it is a disaster waiting to happen, i will save that for another day) thanks for you help guys
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now