Software Restriction

  • Thread starter Thread starter Jmnts
  • Start date Start date
J

Jmnts

Hi
I'm having a problem with Restriction Software Policy:

I created a Hash Rule to deny to some users access to some admin tools: for
now i'm testing the dssite.msc.

I applied a restriction software policy (Hash Rule) to dssite.msc, then went
to the workstation installed the adminpak.msi and i try to run the Active
Directory Sites and Services from the start menu and it worked???, but if i
try to run the console directly from the %SystemRoot%\System32\dssite.msc
the software isn't allow to run as espected.

Does anyone knows what i'm missing here?

Another Question.

I've a group of users and I want to allow them only to create and modify
policies in the domain.
To achive this I add this group to the Group Policy Created Owners, the
problem is that this group only can add or edit their own policies??
I want to allow them to have total access to all policies in the domain.

Best Regards.
 
Answering second part: you should add explicit permissions to each GPO
link/object allowing access to group edit them. The GPO Owners group has
rights just over their created objects.
--
Danilo Bordini
http://blogs.technet.com/dbordini

Esta mensagem é fornecida "como apresentada" sem garantias ou cessão de
quaisquer direitos.
 
Back
Top