Applying Group Policy to Domain Local Groups?

  • Thread starter Thread starter Brian
  • Start date Start date
B

Brian

Ok,

Here is the scenario, we are currently testing ads at our locations
for eventual Deployment. The test Domain is in a mixed mode
enviorment. Here is my issue.

I have an OU called PD Users. All users for PD reside in this OU. I
created a GPO, and assigned it directly to this OU. I created a
Security Group with a scope of Domain Local called PD Group. I applied
this group to the Policy gave it Read and Apply Group Policy for this
group, then removed the Apply Group Policy from Authenticated Users.

I log off, and then log back in. Nothing.

Now I get the desired results if I use a Security Group with a scope
of Global applied to it.

So I wanted your take on this. Is what I am experiencing correct or am
I doing something wrong?
 
Hey Brian,

First, only the users in the OU would get the policy even without having to
set the rights, so creating a domain local group was not necessary. The
only reason for setting security is to filter who can receive the group
policy within the scope of the GPO (in this case, the OU). If you created
this group and did not add all the users in this OU to the group, they
would not get it.

The easiest solution is to remove the security for the Domain Local group
and add Authenticated Users with Read and Apply GPO and that should resolve
it.

Jim
 
Back
Top