Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Active Directory: group policy precedence

Loading...

Sign in or sign up now!
15,612
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Sep 17, 2009

It's important to understand the sequence that group policy uses. I'm creating this video on Server 2008 domain controller, but it could've been done on server 2003 or 2000. Group policies affect all Microsoft operating systems. (2000, xp, vista, 7)
ou=organizational unit
gpo=group policy object
requires a domain controller (active directory)

Group Policy Precedence
1. Computer turns on
2. Local GPOs for the computer
3. Site GPOs for the computer
4. Domain GPOs for the computer
5. OU GPOs for the computer
6. Enforced GPOs for the computer
7. User logs in
8. Local GPOs for the user
9. Site GPOs for the user
10. Domain GPOs for the user
11. OU GPOs for the user
12. Enforced GPOs for the user

Rule A
user policies are more important than computer policies

Rule B
If a policy has Blocked Inheritance, it does not apply.

Rule C
Unless it is enforced. Then it does apply. (More than all others.

Rule D
Unless you deny read permissions to a user/computer for that GPO.

Rule E
You should never give a deny permission.

Rule F
Group policy loopback can make computer GPOs over rule User GPOs
(computer configuration\policies\admin templates\system\group policy\user group policy loopback processing mode)

Rule G
Computer policies are updated every 90-120 minutes after the computer is turned on. User policies are updated every 90-120 minutes after the user logs in.

Rule H
Never get involved in a LAN war in Asia

Providing training videos since last Tuesday.
http://technoblogical.com
Thanks for watching.

  • likes, 0 dislikes

Link to this comment:

Share to:
see all

All Comments (16)

Sign In or Sign Up now to post a comment!
  • one of the fantastic video i ever to see and very easy to understand

    thanks a lot, Keep it up.

    Much appreciated

  • thanks

    

  • Very nice ... thanks

  • I love Rule H - Never get involved in a LAN war in Asia... :)

  • Hahahaha, never get involved in a LAN war in Asia :D

  • Brilliant Video...thank you made what I was reading make sense. Well done

  • That was great, really appreciate it.

  • You don't have to Deny Read Permissions (and block yourself), you can just Deny the Apply group Policy permission instead.

  • Thanks for this vid.

  • Ditto;-)

Loading...

0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more