Tech Support > Microsoft Windows > Security & Administration > Re: make domain GP not apply to local computer?
Re: make domain GP not apply to local computer?
Posted by Shenan Stanley on May 7th, 2006


Leythos wrote:
Don't want the group policies applying to what? The laptop?
If so - don't join the laptop to the domain.
If to the machine they are remoting into - the GPs are already applied to
it..

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html



Posted by Steven L Umbach on May 8th, 2006


It sounds like the specific setting you talk about is a user right for shut
down the system which is "computer" configuration Group Policy. Group Policy
can be configured so that only authorized users can shut down the TS and
then a different GP can be set for the laptop computers to allow users to
shut down the system. It is usually best to have a TS in a different
Organizational Unit that other domain computers so that it can have it's own
Group Policy linked to the OU and configured as needed for the TS.

For TS often "loopback processing" of Group Policy is used for "user"
configuration in which case the user configuration settings applied to the
GPO for the TS are applied to users logging onto the TS instead of their
normal Group Policy user configuration settings in a merge or replace mode.
The links below explains more on that if that would be helpful and running
rsop.msc on an XP Pro computer or using the Resultant Set of Policy mmc
snapin on Windows 2003 domain controller can show the current Group Policy
settings and what Group Policy is applying them. When running RSOP on a
domain controller in "planning" mode instead of logging mode you can see
what Group Policy settings will apply to a user/computer when loopback
processing is implemented or other scenarios. --- Steve

http://technet2.microsoft.com/Window...21bad1033.mspx
http://support.microsoft.com/default...231287&sd=tech ---
applies to Windows 2003 also

"Leythos" <void@nowhere.lan> wrote in message
news:dVu7g.21925$YI5.11914@tornado.ohiordc.rr.com. ..


Posted by Steven L Umbach on May 8th, 2006


Cool. Glad to help you jog your memory on what to do. Have fun on
nday. --- Steve



"Leythos" <void@nowhere.lan> wrote in message
news0z7g.32933$P2.30785@tornado.ohiordc.rr.com.. .