Using Security Filtering on Group Policies.

  • Thread starter Thread starter Brian Gavin
  • Start date Start date
B

Brian Gavin

I was wondering if someone could explain what the use of using Domain
Computers on a group policy in addition to a local AD group would be needed
on certain group policy? I am trying to understand someone elses work here
and they have Domain Computers + some local Groups applied on the policy.
Couldn't I just use the Local Groups for the policy and not the Domain
Computers group?
 
Group Policy is applied in this order - local>site>domain>OU in which the
last applied setting wins. This means that if settings are defined at the
local and domain level, the domain level will apply. Normally you want to
use domain/OU policy on domain computers. In Windows 2000 for Local Security
Policy you will see two settings - local and effective. If the effective
setting is different than the local setting then a domain/OU policy is
overriding the local setting. --- Steve
 
Back
Top