Jump to content

Recommended Posts

Posted

We decided to lock down our domain controllers through the use of a GPO in the Domain Controllers OU but no matter what we've tried, the DC's will not take those settings.

If we make the same exact changes to the local group policy, it works flawlessly.

The domain GPO is enabled and enforced.

Anyone have any ideas?


Posted

Perhaps adding the User accounts that the DCs use? Of course you did add your Domain Controllers into that group right? And are you enforcing known vs. unknown computers?

Posted (edited)
the DC's will not take those settings.

are you adding a new adm file to the gp with just that small section or are you replacing the entire exisitng structure?

Editing or creation of Group Policy Objects (GPO) is always done from the GPO copy found in the PDC Emulator's SYSVOL share, unless configured not to do so by the administrator.

http://www.petri.co.il/understanding_fsmo_roles_in_ad.htm

edit: '......entire existing adm' :thumbdown + quote and ref in case that helps

Edited by iamtheky

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...