Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Wanet Telecoms Ltd on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Local and OU GPO

Status
Not open for further replies.

penauroth

Programmer
Oct 30, 2001
325
US
How can I allow local and domain User Rights Assignments to coexist?

For example, we are using domain service accounts to run COM+ and batch jobs. We set the appropriate User Rights Assignments in GPO ( "Logon as a Batch Job" and "Logon as a Service" ). Everything seems to work OK however, certain local accounts (ASPNET and other accounts) are denied permission when the GPO refreshes.

Any ideas how I can allow both local and domain GPOs?

Thanks.

Paul

Work on Windows, play on Linux.
 
hopefully your not tinkering on DCs with this overhead

structured OUs with settings in policies at the OU level for accounts you need

local and domain GPOs do co-exist...its just that any upper level policy (which in local polciies case means any polciy attached anywhere in the domain) overwrites any settings that are configured at the local level...
this is for good reason, as the local machines do not have knowledge of the domain security, and it needs to have appropriate security settings to match the domain...

tired so that prolly lgiht explanation im sure :)

-Brandon Wilson
MCSE00/03, MCSA:Messaging, MCSA03, A+
almost got a paragraph there :)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top