|
How Do I Disable Inheritance of Domain GPOs on Domain Client?
Hello,
I read the following in a Microsoft publication:
"If you have a requirement for a domain client *not* to execute domain
GPOs, you need to change a setting in the LGPO that will make a registry
change on that local client when it is next booted. This key is checked both
when the client boots and when a user logs onto the domain. If the key is
properly set, the user and computer...
|
1 |
07.05.2007 16:21:00 |
|
WPA2 Wireless settings for Group Policy
Greetings,
I have seen several others post this same question, but nowhere have I seen
a response that gives even a clue as to how to resolve.
I have an environments with wireless networks that are using WPA2. I would
like to use group policy to configure clients to use these wireless networks.
Even after applying SP2 to my Windows Server 2003 R2 machines, I still do not
see any option...
|
3 |
07.05.2007 05:41:00 |
|
GPO- Profile replicating Local settings and applcation data folders- not set??
Hello,
I know that by default a roaming profile does not include Local
settings and applcation data (temporary internet files, and cookies)
I have checked my GPO's and nothing is set to send these to the DFS
only the my documents, desktop, and the standard profile settings.
Local settings and applcation data is not specified so how can it be
copying them?
The local settings syncronise every...
|
2 |
07.05.2007 03:38:24 |
|
WPA2 support in 2003 R2
Was WPA2 support in GPO ever implemented? I only see WEP, WPA. I was
under the impression that SP2 would add the functionality.
...
|
2 |
06.05.2007 17:00:00 |
|
Deployment GPO for Office 2007 Professional Plus
Hello,
I have configured Deployment GPO for Office 2007 Professional Plus. I have
pated the configuration file here with. What is happening is when I reboot a
workstation which has office installed already and is under the scope of
this GPO, first thing happens is GPO uninstalls the previous office
installation and waits. I have to reboot the workstation and then again GPO
installs offi...
|
1 |
06.05.2007 07:21:42 |
|
Re-instating a GPO
OK, I should have backed up using GPMC :-(
Unintentionally, the wrong GPO was "link and object" deleted (I must
remember, in future, to use easily distinguished names) and I would like
to re-instate this, rather than create anew (it has settings for Office
and other extra items).
I have a normal backup, but not a GPMC backup. Is there a way, after
recovering the files in SYSVOL, to a...
|
3 |
05.05.2007 15:41:01 |
|
Search capabilities
Is there a way to prevent a basic user from using the search function for
Active directory users or groups searches? ie (start>search>other search
options>printers,computers,or people>). This seems to be a back door into
viewing any and ALL global group membership. I can't remove search entirely
since file and folder search is still needed....
|
3 |
04.05.2007 22:07:01 |
|
auditing account lock-outs
I have some confusion regarding auditing. I understand that 'Account Logon
Events' tracks domain log-ins while 'Logon Events' are local log-ins.
However, domain account lock-outs create event id 539 which is tracked as a
'Logon Event' not as a 'Account Logon Event' as I would have expected...so,
am I correct then in my understanding that if I want to track accounts that
get locked out I ...
|
2 |
04.05.2007 21:45:05 |
|
Prevent changes to All Users Start Menu
I have a bunch of test stations where user Move icons from the Start Menu to
their own desktops and then subsequent users can't get to the programs.
I know I can script a file system change, but is there a way to do this via
GP? The All Users desktop folder would also be great.
...
|
2 |
04.05.2007 21:28:59 |
|
Apply Corporate Wallpaper, but ALLOW subsequent changes.
I understand that it is possible to deploy a corporate wallpaper and enforce
its application. However, I have a slightly different requirement in that I
need to be able to deploy the wallpaper at first log on but allow the user to
change it thereafter.
(I use roaming profiles so that the wallpaper and other appliction settings
roam with the user around the estate).
I can't work out ...
|
8 |
04.05.2007 20:27:30 |
|
Restrict dragging of folders and specific file types
I am archiving out old folders to another drive. How can I set up a group
policy that prevents users from dragging back whole folders instead of
selectively choosing files they may need to bring back. Also, how can I
restrict the saving of certain file types, i.e., .jpg, .gif, .mp3 to my
server?...
|
4 |
04.05.2007 19:24:01 |
|
Rogue GPO - Help Please
Help !!!
We have no idea how or who, but a domain wide GPO was applied today
affecting every account including admins. The domain consists of 36 DC's all
running windows 2003 which serve 7000+ students and 1000+ staff.
I guess the question is how do I regain access to the mmc console dsa or
kill all GPO's?
Any help would be appreciated
Thanks,
Marc
...
|
3 |
04.05.2007 17:29:00 |
|
GPO to screen resolution
I want to apply GPO to screen resolution
setting: 800x600
That is possible, let know please...
|
2 |
04.05.2007 16:40:01 |
|
Assign Logon Scripts to Group of Computers
Hello All,
I just wonder, is it possible to have a group policy that runs a logon
script and be assigned to an OU which contains a group of computers?
For example, we have computers organized by floors, and we have a logon
script to add a new printer on that floor. We want to assign that script to
those computers on that floor, so next time an user logs in to that
computer, he gets t...
|
5 |
04.05.2007 15:55:13 |
|
Vista Group Policy with startup scripts
In my Vista test environment, I am experiencing extremely long startup times
(up to 14 minutes) when booting up outside of the domain, but connected to
the Internet (like at home). It hangs at the "Please Wait" screen. After a
great deal of troubleshooting and log parsing, I was able to determine that
this was caused by startup scripts in my Group Policy. A representation of
my Group Policy O...
|
1 |
04.05.2007 13:47:05 |
|
synchronize folders
Hi
I have a sbs2003 server and have user profile redirected.
I am a bit baffled. I only expect the user profile being synchronized when
logon however I found that the 'share folders' which is a folder on the
server, are being synchronized as well. I know where to turn it off but I
just don't understand why the share folders are being syn or what had
trigged it.
I have user profil...
|
1 |
04.05.2007 12:13:08 |
|
Internet Explorer - tools menu
Can I disable the Tools menu in Internet Explorer using Group Policy.
I know I can disable Internet Options,but I also need to prevent users from
being able to manage add-ons....
|
4 |
04.05.2007 12:08:25 |
|
Disallow PST file
Is there a way to disallow Outlook2003 users from opening Outlook Data File
(PST)?
I check the GPO, it can only prevent from creating one but I cannot find
anything for opening.
...
|
2 |
04.05.2007 09:26:45 |
|
GPO to force Screen saver on Login Screen
We go stuck purchasing some cheapo LCDs that are prone to burn-in. We also
have a GPO set to show the legal statement prior to logon. The problem is
that if no one logs in, the screen does not blank out or go into a screen
saver mode.
I don't want to force a certain screen saver for every user but I want to
force something to happen to either blank the display or kick in a screen
sa...
|
2 |
04.05.2007 08:07:55 |
|
Deny Change IP address with win xp
Hi there
I had a win 2003 sbs premium with isa and exchange configured
we can't find a policy that deny sbs users to change the ip address
(they want to bypass isa server!!!)
NOTICE tha all tha users must be local administrator because they use
Autodesk Autocad!
we have find one gpo but it work only with win 2000!!!
PLEASE HELP!!!
...
|
7 |
04.05.2007 00:34:13 |
|
password change problem
I am having problems with accounts on my Windows 2003
active directory to change passwords. I first setup my
password policy on the top of the domain to be atleast 8
characters long, remember 10 previous passwords...thats
about it...all my OU's are clean and dont have any other
password restrictions, like i said, i made this at the
top and want this password policy accross the domain.
At ...
|
2 |
03.05.2007 19:10:58 |
|
W2K3 R2 is not logging/auditing failure events
Hello.
I'm running 2003 Server R2 here. I went to Default Domain Security
Settings, Local Policies, Audit Policy, Audit Logon Events ***AND***
Audit Account Logon Events, and selected audit success and failure.
I then did a gpupdate /force.
Now, from any host, when I supply a bad password or a username which
does not exist in AD, I don't get the failure event(s) in the security
log, ...
|
3 |
03.05.2007 16:40:09 |
|
User rights assignment for SQL Server Help .... ;-(
Hi I need some urgent help please......
I'm doing the user rights assignment for SQL Server 2k5 and I just
want to clarify something before I do it just in case I break the
server.
In the current Local Policy of the SQL 2k5 Server in the "User Rights
Assignment" I can see some accounts IWAM_Servername and
IUSR_Servername assigned to some of the settings.
If I deploy these via GPO do I...
|
1 |
03.05.2007 13:15:59 |
|
strange behavior on netshare homefolders
s2003
I have some users, folder redirection for home folders to a share on the net.
If users log in, the netshare shows the home folders, but for some users the
name of the homefolder is "my documents", and for others the name is "marc's
documents"...
second question
If users navigate from within windows explore to the netshare, they can also
see the homefolders from other users and ...
|
2 |
03.05.2007 12:48:09 |
|
Enable USB mass storage after disable!?
We set a policy on an old AD domain that disabled USB mass storage but
nobody can remember how it was done. This domain has since gone. One of the
computers on the domain is now on a new domain (with no policies on of any
interest).
This computer now cannot use USB mass storage devices. I just can't think
why or what to check? I've tried reg settings but all seem fine. I would
like to...
|
3 |
03.05.2007 10:54:43 |