starscream Posted June 27, 2007 Posted June 27, 2007 I am wanting to change the local policy on all computers to not need ctrl-alt-del, not remember last logon and to display an AUP warning on every client computer. I have set this in Ranger for all computers but it didn't seem to make any difference to the client computers so I think that I need to change each computer's own local policy. Does anyone know what a need to change on each computer to enable the above changes and is there a way to do this on all machines at ones, remotely or with the least amount of work possible? I don't want to have to go to every single machine and log on locally and change the policy. Any help would be mucho appreciated guys!
Geoff Posted June 27, 2007 Posted June 27, 2007 Login to one machine, run 'gpedit.msc' and change the local policy as required. Copy %Systemroot%\System32\GroupPolicy to the other machines.
mrforgetful Posted June 27, 2007 Posted June 27, 2007 I'd advise never to change policies at a local machine level, do it via Group Policies. You can find the settings you mention here: Computer Configuration Windows Settings Security Settings Local Policies Security Options The policies you require are Interactive Logon: Do Not Display Last Username Interactive Logon: Do Not Require Ctrl + Alt + Del Interactive Logon: Message Test For Users Attempting To Logon Interactive Logon: Message Title For Users Attempting To Logon I use these to display messages when common problems arise and can change it whenever I like.
starscream Posted June 27, 2007 Author Posted June 27, 2007 I did this this ranger for the computers but it didn't work. Should I just use active directory and create a policy for the OU of the computers and change it there?
starscream Posted June 27, 2007 Author Posted June 27, 2007 OK I did this the way you said and it works great! Many thanks! Will this overwrite the local policy on the machine? For example if it was disconnected from the network would the policy still be applied?
Nij.UK Posted June 27, 2007 Posted June 27, 2007 @starscream: what you have suggested there would be the best way to apply the changes that you are wanting. If what you want to achieve can be done via group policy then i would opt for that method first before trying another route.. Also remember to do gpupdate /force after changes
altecsole Posted June 27, 2007 Posted June 27, 2007 I suggest you create a Test OU and put a test machine in it. Then, create the policy for the Test OU (use MS Group Policy Management Console) using the setting that mrforgetful suggests. If you've got a couple of domain controllers give the policy time to propagate (about 5 minutes should do). Logon to you test machine and open a Run command. Type in gpupdate /force /boot and hit Enter. This will force the machine to update the group policy settings and reboot. Once it's rebooted see if the changes have been applied. If not, we'll see if we can figure out why not.
mrforgetful Posted June 27, 2007 Posted June 27, 2007 Computer Configuration changes can take two reboots, one to load the policy then another to apply it.
starscream Posted June 27, 2007 Author Posted June 27, 2007 thanks for the help guys. I feel like an AD padawan at the moment! Thanks for your help AD masters!
starscream Posted June 27, 2007 Author Posted June 27, 2007 thanks for the help guys. I feel like an AD padawan at the moment! Thanks for your help AD masters!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now