Results 1 to 2 of 2

Thread: Restric User GPO in a different site

  1. #1
    strausy is offline Getting Started on GPanswers.com
    Join Date
    Dec 1969
    Posts
    1

    Default

    Is there a way to restrict a User GPO policy from being applied to a different Active Directory site?

    I have three AD sites and I only want this particular User GPO to be applied to the original (Default-First-Site-Name) site and not on the other two I created which are on different networks over VPN.

    The issue is I have computers in my AD forest that are in a specific OU. The User GPO in question runs a inventory tool on users computers when they log in. When this user logs onto a computer in another site, it runs extremely slow because the connection back to the domain from this other site is really slow.

  2. #2
    Eric is offline 100+ Helpful Posts! 50+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    112

    Default

    Instead of running this as a User Policy, have you tried running it as a loopback merge policy? You can apply the policy to the OU with all of your computers in it, and every user who logs onto computers whose account is in this OU will receive the policy. When a user logs onto a system in another site, they will not be affected by the policy because it is only applied to the specific OU containing computers.

    Here's a link to Microsoft's site talking about loopback policies:
    http://technet2.microsoft.com/WindowsServer/en/library/abe2b1a9-975f-4b2f-b771-9e6a903e97db1033.mspx?mfr=true

    Hope that helps!!

    Eric

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Search Engine Friendly URLs by vBSEO