It's important to understand the sequence that group policy uses. I'm creating this video on Server 2008 domain controller, but it could've been done on server 2003 or 2000. Group policies affect all Microsoft operating systems. (2000, xp, vista, 7)
ou=organizational unit
gpo=group policy object
requires a domain controller (active directory)
Group Policy Precedence
1. Computer turns on
2. Local GPOs for the computer
3. Site GPOs for the computer
4. Domain GPOs for the computer
5. OU GPOs for the computer
6. Enforced GPOs for the computer
7. User logs in
8. Local GPOs for the user
9. Site GPOs for the user
10. Domain GPOs for the user
11. OU GPOs for the user
12. Enforced GPOs for the user
Rule A
user policies are more important than computer policies
Rule B
If a policy has Blocked Inheritance, it does not apply.
Rule C
Unless it is enforced. Then it does apply. (More than all others.
Rule D
Unless you deny read permissions to a user/computer for that GPO.
Rule E
You should never give a deny permission.
Rule F
Group policy loopback can make computer GPOs over rule User GPOs
(computer configuration\policies\admin templates\system\group policy\user group policy loopback processing mode)
Rule G
Computer policies are updated every 90-120 minutes after the computer is turned on. User policies are updated every 90-120 minutes after the user logs in.
Rule H
Never get involved in a LAN war in Asia
Providing training videos since last Tuesday.
http://technoblogical.com
Thanks for watching.
one of the fantastic video i ever to see and very easy to understand
thanks a lot, Keep it up.
Much appreciated
shaffeek 1 week ago
thanks
DiakoNourfardi 2 months ago
Very nice ... thanks
MrDarkonije 3 months ago
I love Rule H - Never get involved in a LAN war in Asia... :)
meowser2k6 4 months ago
Hahahaha, never get involved in a LAN war in Asia :D
miljansimonovic 4 months ago
Brilliant Video...thank you made what I was reading make sense. Well done
AJJ28 11 months ago
That was great, really appreciate it.
bxblack 1 year ago
You don't have to Deny Read Permissions (and block yourself), you can just Deny the Apply group Policy permission instead.
amvegan 1 year ago
Thanks for this vid.
Fragffs 1 year ago
Ditto;-)
veganath 1 year ago