Restricting GPO snap-ins and filtering the policy

G

Guest

Guest
Archived from groups: microsoft.public.win2000.group_policy (More info?)

Hi all, I need a reality check on my logic here before I apply it.

I want to explicitly deny the ability to add certain snap-ins to GPO and
also want to prevent most MMC users (PC Tech Group) from entering author
mode, however I want DomainAdmins to have full access. If I apply this
policy at the root of the domain, then deny read/apply access to the Domain
Admins group, will this work?

Thanks in advance,

Mike
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.group_policy (More info?)

Yes. Just deny Apply only - if you deny read, you won't be able to edit the
policy.

--
--
Brian Desmond
Windows Server MVP
desmondb@payton.cps.k12.il.us

Http://www.briandesmond.com


"Mike Towan" <mtowan@ci.fremont.ca.us> wrote in message
news:OPgFDI8iEHA.3148@TK2MSFTNGP10.phx.gbl...
> Hi all, I need a reality check on my logic here before I apply it.
>
> I want to explicitly deny the ability to add certain snap-ins to GPO and
> also want to prevent most MMC users (PC Tech Group) from entering author
> mode, however I want DomainAdmins to have full access. If I apply this
> policy at the root of the domain, then deny read/apply access to the
Domain
> Admins group, will this work?
>
> Thanks in advance,
>
> Mike
>
>