- Community Home
- >
- Servers and Operating Systems
- >
- Legacy
- >
- Windows Server 2003
- >
- Group Policy in AD
Windows Server 2003
1823718
Members
3817
Online
109664
Solutions
Forums
Categories
Company
Local Language
юдл
back
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
юдл
back
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Blogs
Information
Community
Resources
Community Language
Language
Forums
Blogs
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-23-2004 01:46 AM
тАО09-23-2004 01:46 AM
Group Policy in AD
We have one 2003/AD domain across four sites with four OUs representing each site. In terms of Group Policy we have one overall GPO for the domain (with very general settings) and one for each OU (with more specific settings relating to each OU). I noticed that we also had a default Domain Controllers GPO as well. In addition all the XP workstations have local policies.
Is it the case that GPOs are applied first locally then at Site, Domain, OU and finally sub OU level and that policies lower down in the chain will be effective even if they have been set higher up in the hierarchy (unless Block Inheritance is turned on or No Overide is set) ? Where or when is the Default Domain Controller GPO applied in all this ?
Secondly I am trying to log a new workstation onto the new domain but I keep getting the message Local Policy of this system does not permit you to log on interactively - I can only seem to log onto the domain as an administrator (or member of the administrators group). Which GPO setting do I configure so anyone from this domain can logon on this workstation
Is it the case that GPOs are applied first locally then at Site, Domain, OU and finally sub OU level and that policies lower down in the chain will be effective even if they have been set higher up in the hierarchy (unless Block Inheritance is turned on or No Overide is set) ? Where or when is the Default Domain Controller GPO applied in all this ?
Secondly I am trying to log a new workstation onto the new domain but I keep getting the message Local Policy of this system does not permit you to log on interactively - I can only seem to log onto the domain as an administrator (or member of the administrators group). Which GPO setting do I configure so anyone from this domain can logon on this workstation
3 REPLIES 3
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-23-2004 07:48 AM
тАО11-23-2004 07:48 AM
Re: Group Policy in AD
Hi Wayne,
GPOs do indeed apply in that order, first locally, then by site, domain, OU< sub OU. A policy remains constant until a setting higher in the chain takes over. For example, if you enable the "Add Logoff to the Start Menu" policy on the local machine, it will apply until a higher policy changes it. If no higher GPO sets that policy, then the Logoff button is added to the Start Menu. If, however, the OU policy disables this setting, the Log off button will never appear on the start menu as the OU policy takes priority over the local policy.
The error you are getting on the workstation . . . are you trying to remotely access the machine? If so, you will need to add your username/security group to the Remote Desktop users group (using "Everyone" will allow anyone to log onto that machine).
I hope this is of help,
Mason
GPOs do indeed apply in that order, first locally, then by site, domain, OU< sub OU. A policy remains constant until a setting higher in the chain takes over. For example, if you enable the "Add Logoff to the Start Menu" policy on the local machine, it will apply until a higher policy changes it. If no higher GPO sets that policy, then the Logoff button is added to the Start Menu. If, however, the OU policy disables this setting, the Log off button will never appear on the start menu as the OU policy takes priority over the local policy.
The error you are getting on the workstation . . . are you trying to remotely access the machine? If so, you will need to add your username/security group to the Remote Desktop users group (using "Everyone" will allow anyone to log onto that machine).
I hope this is of help,
Mason
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-24-2004 08:05 PM
тАО11-24-2004 08:05 PM
Re: Group Policy in AD
Thanks Mason but I've managed to get to the bottom of this now. The problem was in my Group Policy setting at Computer Configuration - Windows Setting - Security Settings - Local Policies - User Rights Assignment - Allow Logon Locally. If you don't add the users or domain users group to this then they cannot logon interactively (onto the domain).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-24-2004 08:06 PM
тАО11-24-2004 08:06 PM
Re: Group Policy in AD
As in my reply above I have since found a solution to the problem and was unaware I left the thread open. Sorry!
The opinions expressed above are the personal opinions of the authors, not of Hewlett Packard Enterprise. By using this site, you accept the Terms of Use and Rules of Participation.
Company
Learn About
News and Events
Support
© Copyright 2025 Hewlett Packard Enterprise Development LP