ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Block GPO Inheritance

    IT Discussion
    7
    21
    2.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BrainsB
      Brains
      last edited by

      What method did you use to block the OU?

      alex.olynykA 1 Reply Last reply Reply Quote 0
      • nadnerBN
        nadnerB
        last edited by

        Did you make it a Computer or User policy?
        Even though you have blocked the inheritance on an OU, it might be applied elsewhere and still get through.

        If it's a Computer policy and you are blocking the inheritance on the User OU, you might find that the policy is also applied on the Computer OU and hence why it is still active.

        1 Reply Last reply Reply Quote 1
        • nadnerBN
          nadnerB
          last edited by

          Where have you applied it to? Domain level or lower?

          alex.olynykA 1 Reply Last reply Reply Quote 0
          • alex.olynykA
            alex.olynyk @Brains
            last edited by

            @Brains Open group policy management
            Right click OU
            Enable block inheritance

            1 Reply Last reply Reply Quote 0
            • alex.olynykA
              alex.olynyk @nadnerB
              last edited by

              @nadnerB applied at the OU

              1 Reply Last reply Reply Quote 0
              • alex.olynykA
                alex.olynyk
                last edited by

                is there a way to set password policies in a GPO's user configuration?
                I only see them in computer configuration

                BrainsB 1 Reply Last reply Reply Quote 0
                • alex.olynykA
                  alex.olynyk
                  last edited by

                  or should I create a GPO for just the password policies?

                  DustinB3403D 1 Reply Last reply Reply Quote 0
                  • alex.olynykA
                    alex.olynyk
                    last edited by

                    some background...we have ricoh scanners and these scanners do not accept a special character in the password field. our company policy requires a special character in the password so we need to exclude the accounts used for the ricoh scanners

                    1 Reply Last reply Reply Quote 0
                    • alex.olynykA
                      alex.olynyk
                      last edited by

                      i applied at the domain level now

                      1 Reply Last reply Reply Quote 0
                      • IRJI
                        IRJ
                        last edited by

                        Filter using by OU using WMI. In your case, you would deny the specific WMI filter for that OU.

                        https://social.technet.microsoft.com/Forums/windowsserver/en-US/efa8d1f8-1ef9-47b6-8a1b-ea633a5c213a/seacrhing-computers-ou-or-dn-in-wmi-filter?forum=winserverGP

                        BrainsB 1 Reply Last reply Reply Quote 1
                        • IRJI
                          IRJ
                          last edited by

                          This might be a little easier....

                          www.grouppolicy.biz/2010/02/how-to-find-and-use-wmi-values-for-group-policy-filtering/

                          BrainsB 1 Reply Last reply Reply Quote 1
                          • BrainsB
                            Brains @IRJ
                            last edited by

                            @IRJ said in Block GPO Inheritance:

                            Filter using by OU using WMI. In your case, you would deny the specific WMI filter for that OU.

                            https://social.technet.microsoft.com/Forums/windowsserver/en-US/efa8d1f8-1ef9-47b6-8a1b-ea633a5c213a/seacrhing-computers-ou-or-dn-in-wmi-filter?forum=winserverGP

                            This is the way I would do it if there isnt a SG you can filter by

                            chrisnbrooksC 1 Reply Last reply Reply Quote 1
                            • BrainsB
                              Brains @alex.olynyk
                              last edited by

                              @alex.olynyk said in Block GPO Inheritance:

                              is there a way to set password policies in a GPO's user configuration?
                              I only see them in computer configuration

                              They are located in computer configuration, why do you want to set them as user config?

                              1 Reply Last reply Reply Quote 0
                              • DustinB3403D
                                DustinB3403 @alex.olynyk
                                last edited by

                                @alex.olynyk said in Block GPO Inheritance:

                                or should I create a GPO for just the password policies?

                                Discrete policies are best

                                1 Reply Last reply Reply Quote 1
                                • BrainsB
                                  Brains @IRJ
                                  last edited by

                                  @IRJ said in Block GPO Inheritance:

                                  This might be a little easier....

                                  www.grouppolicy.biz/2010/02/how-to-find-and-use-wmi-values-for-group-policy-filtering/

                                  great reference site for a whole host of questions!

                                  1 Reply Last reply Reply Quote 2
                                  • chrisnbrooksC
                                    chrisnbrooks @Brains
                                    last edited by

                                    @Brains Agree. I much rather manage SG memberships for GPO, than OU placement. Less clutter, less margin of error, easier access and oversight. I also understand that people often inherit their AD schema from predecessors and can't afford the time and risk for a complete redesign.

                                    alex.olynykA 1 Reply Last reply Reply Quote 1
                                    • alex.olynykA
                                      alex.olynyk @chrisnbrooks
                                      last edited by

                                      @chrisnbrooks What is SG?

                                      1 Reply Last reply Reply Quote 1
                                      • alex.olynykA
                                        alex.olynyk
                                        last edited by

                                        security group

                                        1 Reply Last reply Reply Quote 1
                                        • 1
                                        • 2
                                        • 1 / 2
                                        • First post
                                          Last post