View: 2059|Reply: 18
|
group policy in windows server 2003
[Copy link]
|
|
to all system admin,
i have some problem in group policy object .. in windows server 2003 . kenapa aku apply kat server kepada group "autenticated users" group policy aku boleh jalan.. tp bila aku apply pada user id.. like userid aku.. group policy tak applied.. pening kepala aku...any suggestion to who familiar with group policy object.. thanksss.
|
|
|
|
|
|
|
|
oobi u must familiar with this issue rite..? |
|
|
|
|
|
|
|
Reply #2 testas's post
sabar ye testas. oobi tengah sibuk sekarang ni. oobi dah baca your problem, cuma belum sempat nak digest. been working since before 6 am this morning. may be have to stay up all night tonight. kalau sempat, oobi sambil nanti.
also, kalau you boleh layout kat sini step by step apa yang you buat, for both, group and your id, mudah sikit oobi nak check (kalau ada beza between the two). also, let us know if you're deploying active directory or just workgroup.
|
|
|
|
|
|
|
|
Reply #1 testas's post
can you explain what are you trying to do (what kind of output do you expect by deploying GPO)? does your user id belongs to any admin group? if you could provide detail info, may be i can simulate it in my lab, and see if i get the same result or different.
|
|
|
|
|
|
|
|
heheh.. sibuk ke... sempat lagi masuk cari forum. ok just assume i have only 1 group policy. at security filtering i assign this GPO to "authenticated users" (by default server set this). All users including me get the policy.. but if i buang this "authenticated users", and put to user id like mine... GPO tak apply.. cam system tak nampak my ID or other ID. strange.. i am using active directory.k |
|
|
|
|
|
|
|
Reply #5 testas's post
not clear. you're authenticated users. what do you mean the GPO doesn't work? need to explain in detail. what kind of output do you expect? your user id, is it admin id? regular user? need more detail.
|
|
|
|
|
|
|
|
tak jalan kalau i use my ID or other user id. simple example i want disable windows update to all users. i just edit GPO to disable windows update. then at security filtering i assign this setting to user "authenticated users"'s group. u know kan this authenticated users?. kalau cam ni semua user kat opis ni tak bole ubah settings windows update... ok that good. but i want to apply this setting to only certain users. i buang authenticated users... and ganti dengan user cth karen([email protected]l).. but bila apply this settings computer karen tak disable windows update... why? |
|
|
|
|
|
|
|
Reply #7 testas's post
i tested and it worked for me. i used two users, A and B. i removed authenticated users group and add user B to GPO. then i disabled user B ability to change password from ctrl+atl+del.
when you look at group policy objects, it has two policies underneath it. make sure you use the second one, default domain policy. the first one only for domain controllers.
|
|
|
|
|
|
|
|
Reply #7 testas's post
by the way, the policy is in effect at next logon.
|
|
|
|
|
|
|
|
Originally posted by oobi at 29-6-2007 03:04 PM
by the way, the policy is in effect at next logon.
gpupdate/force ... u no need o restart .. k .. sometimes need to log off... depends on policy.
there something yg tak kena kat server i la.. i check my server 1st.. k |
|
|
|
|
|
|
|
still tak bole... GPO still carik autenticated users... lain2 group.. users.. semua tak jalan ... ur user tick for " this users trusted for delegation"? |
|
|
|
|
|
|
|
Originally posted by testas at 29-6-2007 04:31 PM
gpupdate/force ... u no need o restart .. k .. sometimes need to log off... depends on policy.
there something yg tak kena kat server i la.. i check my server 1st.. k
that's what i meant by next logon. doesn't mean you have to restart. but if you want to restart, that's okay too.
|
|
|
|
|
|
|
|
Originally posted by testas at 29-6-2007 05:03 PM
still tak bole... GPO still carik autenticated users... lain2group..users.. semua tak jalan ... ur user tick for " this userstrusted fordelegation"?
i assume you're not using gpo for domain controller, but rather gpo for domain.
do you install AD from scratch or upgrade/migrate from NT4? if the later, try disjoin the device from the domain and rejoin before next try.
[ Last edited by oobi at 30-6-2007 01:27 AM ] |
|
|
|
|
|
|
|
Originally posted by oobi at 29-6-2007 10:02 PM
i assume you're not using gpo for domain controller, but rather gpo for domain.
do you install AD from scratch or upgrade/migrate from NT4? if the later, try disjoin the device from the ...
install from scratch. i dah try rejoin domain.. but tak bole gak.. u said iam not using GPO for domain controller? i dont understand laaa... |
|
|
|
|
|
|
|
Reply #14 testas's post
read my post #8, 2nd paragraph, carefully.
|
|
|
|
|
|
|
|
i dah try 2 2 daa... domain policy and also controller.. still cannot go... no idea laaa... |
|
|
|
|
|
|
|
Originally posted by testas at 30-6-2007 11:36 AM
i dah try 2 2 daa... domain policy and also controller.. still cannot go... no idea laaa...
why don't you try create a new group that you want to custom control in AD (add affected users to that group). then, instead of using individual ID, add that group to security filtering. see if that helps.
|
|
|
|
|
|
|
|
ooo..ni mcm kat tmpt aku la ni..
taknak bg user..tukar desktop setting, wallpaper..bla..bla..
mula2 tak jd..
logoff/restart..
kdg2 jadi..ada yg kena tunggu lama skit..err..x la lama sgt |
|
|
|
|
|
|
|
ok. i think i know the problem. i can apply to users configuration.. but computer config cannot go la. oobi u try any settings under computer sconfiguration...
i dah try under users setinggs like remove ctrl +alt+del .. it workings.. |
|
|
|
|
|
|
| |
|