After sending this, I realized that there is a much easier, non-hacked version to disable the local GPO. You can simply open gpedit.msc, select the local GPO's properties and disable user and computer settings. This is equivalent to adding a line to the end of the gpt.ini that says:
Options=3 -----Original Message----- From: Darren Mar-Elia Sent: Wednesday, July 30, 2003 2:07 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] GP overridden It is possible to effectively disable the local GPO on a given machine. Much of the local GPO is stored in %systemroot%\system32\grouppolicy. Within that folder is a file called gpt.ini and in that file is a line that says "Version=". If you set that version parameter to 0, the local GPO will be skipped. Note that this is a huge hack, but it will do what you're after. -----Original Message----- From: Adams, Kenneth W (Ken) [mailto:[EMAIL PROTECTED] Sent: Wednesday, July 30, 2003 12:18 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] GP overridden IIRC, the local policy runs no matter what as it is the first policy to be run. If you want to override local policies, you need to set the policies in either the domain, site, or OU. Note that domain based security policies, such as password aging, cannot be overridden by site or OU policies. Kenneth W. (Ken) Adams, MCSA, MCSE -----Original Message----- From: Charles Campbell [mailto:[EMAIL PROTECTED] Sent: Wednesday, July 30, 2003 3:05 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] GP overridden Is there a way, from the DC, to keep the local policy from being applied at each workstation? Or is there a way to disable the local policy (while at each workstation)? Thanks. Charles -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Salandra, Justin A. Sent: Wednesday, July 30, 2003 11:27 To: '[EMAIL PROTECTED]' Subject: RE: [ActiveDir] GP overridden Group Policies get applied Local, Site, Domain, OU Each and every computer has a local policy. -----Original Message----- From: Charles Campbell [mailto:[EMAIL PROTECTED] Sent: Wednesday, July 30, 2003 10:00 AM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] GP overridden The event log shows: "Security policy in the Group policy objects are applied successfully." According to GPResult: Group Policy applied Wed, July 30, 2003 at 9:23:37 AM Group Policy was applied from xxxx.xxxx.com (names changed to protect the innocent) Computer Received "Registry" Settings from these GPOs: Local Group Policy LAN Policy LAN Policy Computer Received "Security" settings from these GPOs: Local Group Policy LAN Policy Default Domain Controllers Policy LAN Policy Computer received "EFS recovery" settings from these GPOs: Local Group Policy LAN Policy LAN Policy I guess what's confusing me here is why "Local Group Policy" is being applied, and where, exactly is it? Under AD, in the xxxx.com properties box/Group Policy, I only have LAN Policy listed. Charles -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tony Murray Sent: Wednesday, July 30, 2003 09:14 To: [EMAIL PROTECTED] Subject: Re: [ActiveDir] GP overridden Charles A couple of points here. 1. Group Policy is refreshed on Domain Controllers every five minutes by default. The default refresh cycle is every 90 minutes on client computers. If the event log entries you mention occur on a DC this may be perfectly normal. What are the details of the event? 2. It is not a good idea to mess with the Default Domain Policy, or for that matter the Default Domain Controllers Policy. I would recommend that you change the name back to what it was. 3. The use of "No Override" can cause confusion and should be used sparingly. Policies are applied in the order Site - Domain - OU ...but in the event of conflict the policy that was last applied takes priority. For example if you have conflicting settings in domain and OU policies the OU policy setting will win. The GPRESULT tool is quite useful for detecting which policies have been applied. Tony ---------- Original Message ---------------------------------- From: "Charles Campbell" <[EMAIL PROTECTED]> Reply-To: [EMAIL PROTECTED] Date: Wed, 30 Jul 2003 08:47:53 -0400 For some reason, there is a GP being applied on the server every 5 minutes (according to the Event Viewer). In AD, I changed the name of the "Default Group Policy" to be "LAN policy" and check-marked "No Over-Ride". Where would I look to see what is being applied? It's changing all the settings that I have set under "LAN policy" (i.e. IE branding, custom url links, etc). Thanks. Charles List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
