Policy Security on 2003 vs. 2000

  • Thread starter Thread starter itreman
  • Start date Start date
I

itreman

On Windows 2000 Server, you have the ability to completely customize
the security settings for a GPO. By right clicking on the GPO and
choosing properties, you can go to the security tab and tell Windows
who that that GPO should run for and who it shouldn't (via "deny"). In
Windows 2003 Server, you use the Group Policy Management console to
manage group policies and it doesn't have a method for adjusting the
security like 2K. You can add users, computers, or groups to the
filtering section, but this doesn't allow you to deny the GPO from
running on an Admin, or other AD group. Does anyone know how to do
this? I've been creating policies on my XP workstation via the GPO
Management console, but when I need to adjust the security for those
policies, I go to a Windows 2000 server and do it there. Seems lame.
Any ideas??
 
In the 2003 group policy management tool, if you click on the policy, then
click the delegation tab on the right hand pane you can set your deny
permission there. I had mixed success with it. It worked when I denied
permission to apply for the domain admin group, but not for a group that I
created. Hope this helps.

Andy
 
Back
Top