Jump to content

Recommended Posts

Posted

We decided to lock down our domain controllers through the use of a GPO in the Domain Controllers OU but no matter what we've tried, the DC's will not take those settings.

If we make the same exact changes to the local group policy, it works flawlessly.

The domain GPO is enabled and enforced.

Anyone have any ideas?


Posted

Perhaps adding the User accounts that the DCs use? Of course you did add your Domain Controllers into that group right? And are you enforcing known vs. unknown computers?

Posted (edited)
the DC's will not take those settings.

are you adding a new adm file to the gp with just that small section or are you replacing the entire exisitng structure?

Editing or creation of Group Policy Objects (GPO) is always done from the GPO copy found in the PDC Emulator's SYSVOL share, unless configured not to do so by the administrator.

http://www.petri.co.il/understanding_fsmo_roles_in_ad.htm

edit: '......entire existing adm' :thumbdown + quote and ref in case that helps

Edited by iamtheky

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...