Jennifer-
If you don't have to do this for a large number of computers, then you
can put an Deny Read ACE on the ACL for the GPO that is sending down
this policy for that particular machine (or a group of machines). This
would be the easiest way to prevent that policy from applying. If the
policy you're delivering is a user-specific one, then you could use
loopback policy on the machine to override the user's "normal" policy
with one that is specific for this machine.

Darren



Darren Mar-Elia
CTO, Microsoft Business Unit
Quest Software


-----Original Message-----
From: Jennifer Fountain [mailto:[EMAIL PROTECTED] 
Sent: Wednesday, July 23, 2003 9:56 AM
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Block User and Computer Group Policy on a
particular machine


Is there a way to block both user and computer group policies on a
particular machine?  Would block inheritance do the trick?
IE:  We have 7 min idle time for users to lock stations.  However, this
is a problem when someone is doing a presentation and they are sitting
at a slide for 10 mins.  




Thanks
Jenn
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to