Hot Downloads

Welcome, Guest
Username: Password: Remember me

TOPIC: Removing Computers from an OU

Re: Removing Computers from an OU 10 years 3 days ago #23525

  • skepticals
  • skepticals's Avatar
  • Offline
  • Expert Member
  • Posts: 783
  • Karma: 0
My question is regarding OUs that are not nested. These are all separate OUs.

So, if I have 10 GPOs spread accross 10 different OUs for a Lab user. This user will get a combination of all the GPO settings?
The administrator has disabled public write access.

Re: Removing Computers from an OU 10 years 3 days ago #23589

  • KiLLaBeE
  • KiLLaBeE's Avatar
  • Offline
  • Expert Member
  • Posts: 466
  • Karma: 0
No.

The user will get the GPO of its "home" OU ("home," meaning, the OU where the user object is in) and will inherit the user configuration GPO of the OU where the computer the user logs into is in

This is one of those things where you may have to visually see it to understand it.

if you want to know the combined policy applied to a user and computer, on the command prompt, type "gpresult." you'll see the policies applied to computer and user and at what time.

Hope that helps
The administrator has disabled public write access.

Re: Removing Computers from an OU 10 years 2 days ago #23601

  • skepticals
  • skepticals's Avatar
  • Offline
  • Expert Member
  • Posts: 783
  • Karma: 0
I think I understood how it works all along, but the wording on here made me think you were saying something else.

To me, it sounded like you were saying that a user would get the user policies of any OU.

But, I think what you were saying is check the computer policies to see if they are what is applying.
The administrator has disabled public write access.

Re: Removing Computers from an OU 9 years 11 months ago #23637

  • GTM
  • GTM's Avatar
  • Offline
  • Frequent Member
  • Posts: 77
  • Karma: 0
If this is still ongoing then you may want to check your domain level group policy settings as there is a setting that prevents OU'S from blocking inheritance so basically even though you have the block inheritance setting ticked at the OU in question if the deny blocking inheritance is set at the domain level then the OU will have the domain level settings applied.
The administrator has disabled public write access.

Re: Removing Computers from an OU 9 years 11 months ago #23684

Just a word of advice, if you're not using the Group Policy Management Console already, I highly recommend that you download it from the Microsoft site. It makes group policy management a breeze! Link.

The original problem in the opening post, was it that you suspected computer objects were retaining settings configured in GPOs which were linked to former OUs where the object was situated?
The administrator has disabled public write access.
Time to create page: 0.102 seconds

CCENT/CCNA

Cisco Routers

  • SSL WebVPN
  • Securing Routers
  • Policy Based Routing
  • Router on-a-Stick

VPN Security

  • Understand DMVPN
  • GRE/IPSec Configuration
  • Site-to-Site IPSec VPN
  • IPSec Modes

Cisco Help

  • VPN Client Windows 8
  • VPN Client Windows 7
  • CCP Display Problem
  • Cisco Support App.

Windows 2012

  • New Features
  • Licensing
  • Hyper-V / VDI
  • Install Hyper-V

Linux

  • File Permissions
  • Webmin
  • Groups - Users
  • Samba Setup