Jump to content

Scrai

Members
  • Posts

    2
  • Joined

  • Last visited

Everything posted by Scrai

  1. Authenticated Users includes all users AND computers. The computers part is the important part now. MS changed it so computers now read all GPOs and decide if they apply or not. Not User accounts. So if you security scope computers out of the equation then the PC can literally not read any GPOs. Hence where the delegation comes in. You delegate all Domain Computers "Read" permission to all GPOs so they can decide whether the GPOs apply or not to the logging on User or Computer.
  2. Here is an article that explains it all very, very well. https://redmondmag.com/articles/2016/06/16/june-patch-breaks-group-policy-settings.aspx Essentially MS changed the way GPO reading works and it is now done via the computer account. All GPOs must have the "Domain Computers" as a delegated permission with "Read" access. If you still want to scope the security filter down to users and remove "Authenticated Users' (Which by default includes all domain computers, hence why it works if left to default), then you need to give Domain Computers Read access. GPanswers.com » Never a dull moment with Group Policy (or what to do about MS16-072) The second link will have scripts to help you add "Domain Computers" to all current GPOs and add the group to all future created GPOs.
×
×
  • Create New...