#145664 - 2005-08-16 03:16 PM
Re: AD GPO Gurus - Group Exceptions
|
Richard H.
Administrator
   
Registered: 2000-01-24
Posts: 4946
Loc: Leatherhead, Surrey, UK
|
Quote:
Not sure I follow... no local administration required. Everything is done at the OU. GPOs have an ACL so you simply remove whoever you don't want it to apply to.
Yeah, this is the way I thought of going, but I just don't know AD well enough to know if I'm likely to bugger things up.
What I'd need to do is add an ACL which explicitly denies access to admins. Would that deny access to manage the GPO as well? Or would it simply stop the GPO being applied?
I could just try it and see what happens, but I'd rather get a consensus on the best approach from you guys with AD experience first!
|
|
Top
|
|
|
|
Moderator: Arend_, Allen, Jochen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Mart
|
0 registered
and 476 anonymous users online.
|
|
|