After sending this, I realized that there is a much easier, non-hacked
version to disable the local GPO. You can simply open gpedit.msc, select
the local GPO's properties and disable user and computer settings. This
is equivalent to adding a line to the end of the gpt.ini that says:

Options=3



-----Original Message-----
From: Darren Mar-Elia 
Sent: Wednesday, July 30, 2003 2:07 PM
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] GP overridden


It is possible to effectively disable the local GPO on a given machine.
Much of the local GPO is stored in %systemroot%\system32\grouppolicy.
Within that folder is a file called gpt.ini and in that file is a line
that says "Version=". If you set that version parameter to 0, the local
GPO will be skipped. Note that this is a huge hack, but it will do what
you're after.



-----Original Message-----
From: Adams, Kenneth W (Ken) [mailto:[EMAIL PROTECTED] 
Sent: Wednesday, July 30, 2003 12:18 PM
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] GP overridden


IIRC, the local policy runs no matter what as it is the first policy to
be run.  If you want to override local policies, you need to set the
policies in either the domain, site, or OU.  Note that domain based
security policies, such as password aging, cannot be overridden by site
or OU policies.

Kenneth W. (Ken) Adams, MCSA, MCSE



-----Original Message-----
From: Charles Campbell [mailto:[EMAIL PROTECTED]
Sent: Wednesday, July 30, 2003 3:05 PM
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] GP overridden


Is there a way, from the DC, to keep the local policy from being applied
at each workstation? Or is there a way to disable the local policy
(while at each workstation)?

Thanks.

Charles

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Salandra,
Justin A.
Sent: Wednesday, July 30, 2003 11:27
To: '[EMAIL PROTECTED]'
Subject: RE: [ActiveDir] GP overridden

Group Policies get applied

Local, Site, Domain, OU

Each and every computer has a local policy.

 -----Original Message-----
From:   Charles Campbell [mailto:[EMAIL PROTECTED] 
Sent:   Wednesday, July 30, 2003 10:00 AM
To:     [EMAIL PROTECTED]
Subject:        RE: [ActiveDir] GP overridden

The event log shows:
"Security policy in the Group policy objects are applied successfully."

According to GPResult: 
Group Policy applied Wed, July 30, 2003 at 9:23:37 AM
Group Policy was applied from xxxx.xxxx.com (names changed to protect
the
innocent)

Computer Received "Registry" Settings from these GPOs:
Local Group Policy
LAN Policy
LAN Policy

Computer Received "Security" settings from these GPOs:
Local Group Policy
LAN Policy
Default Domain Controllers Policy
LAN Policy

Computer received "EFS recovery" settings from these GPOs: Local Group
Policy LAN Policy LAN Policy


I guess what's confusing me here is why "Local Group Policy" is being
applied, and where, exactly is it?

Under AD, in the xxxx.com properties box/Group Policy, I only have LAN
Policy listed.


Charles



-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Tony Murray
Sent: Wednesday, July 30, 2003 09:14
To: [EMAIL PROTECTED]
Subject: Re: [ActiveDir] GP overridden

Charles

A couple of points here.

1.  Group Policy is refreshed on Domain Controllers every five minutes
by default. The default refresh cycle is every 90 minutes on client
computers. If the event log entries you mention occur on a DC this may
be perfectly normal.  What are the details of the event?

2.  It is not a good idea to mess with the Default Domain Policy, or for
that matter the Default Domain Controllers Policy.  I would recommend
that you change the name back to what it was.

3.  The use of "No Override" can cause confusion and should be used
sparingly.   Policies are applied in the order

Site - Domain - OU

...but in the event of conflict the policy that was last applied takes
priority.  For example if you have conflicting settings in domain and OU
policies the OU policy setting will win.

The GPRESULT tool is quite useful for detecting which policies have been
applied. 

Tony
---------- Original Message ----------------------------------
From: "Charles Campbell" <[EMAIL PROTECTED]>
Reply-To: [EMAIL PROTECTED]
Date:  Wed, 30 Jul 2003 08:47:53 -0400

For some reason, there is a GP being applied on the server every 5
minutes (according to the Event Viewer).

 

In AD, I changed the name of the "Default Group Policy" to be "LAN
policy" and check-marked "No Over-Ride".

 

Where would I look to see what is being applied? It's changing all the
settings that I have set under "LAN policy" (i.e. IE branding, custom
url links, etc).

Thanks.


Charles



List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/

List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/

List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to