A
adfreak
Here is my situation. The "Default Domain Controller Policy" for my
production AD has been modified numerous times (just the user rights
section). We are going to be moving to native mode from mixed mode shortly.
We would like to link a newly created DC Security policy.inf file via a GPO
to the Domain Controllers Container.
For now, we want to keep the existing settins for the default DC GPO
(because we're not sure what will happen if we delete it because previous
admins added numerous users/groups to certain user rights policies). How
should we go about linking the newly created .inf? Do we simply "add" a GPO
and precede it before the Default DC one? What happens when some of the
user rights management settings conflict between the two as I know they
will? Which one will take affect? or will both?
Is it bad to have two of them?
Please advise
production AD has been modified numerous times (just the user rights
section). We are going to be moving to native mode from mixed mode shortly.
We would like to link a newly created DC Security policy.inf file via a GPO
to the Domain Controllers Container.
For now, we want to keep the existing settins for the default DC GPO
(because we're not sure what will happen if we delete it because previous
admins added numerous users/groups to certain user rights policies). How
should we go about linking the newly created .inf? Do we simply "add" a GPO
and precede it before the Default DC one? What happens when some of the
user rights management settings conflict between the two as I know they
will? Which one will take affect? or will both?
Is it bad to have two of them?
Please advise