Apply GPO in resource forest to users in another forest
windows server 2003 forest/domain
contains universal security group "resource app users" containing user accounts in domain.com
resource.com
windows server 2003 forest \ windows server 2008 r2 domain
contains "appusers" ou
in ou domain local security group "appgroup" containing "domain\resource app users" , few test accounts in resource domain
one-way trust: resource.com trusts domain.com
there gpo set on "appusers" ou restricts programs can run along ie browser settings, security filtering set apply policy resource\appgroup
gpo applies test accounts in resource not members of "domain\resource app users" group
want users in "domain\resource app users" group log onto resource domain have policy applied
possible set one-way trust in place? if yes, needed working?
first, som comes mind (scope of management). gpos applied users reside in ou gpo linked to. groups add means of filtering, not of "applying". dlg appgroup meaningless.
in cross forest scenario, impossible within resource domain (the users - spoken - living in universe), need use loopback processing. , far know, not work 1 way trust. remember having read kb article long time ago confirms that, couldn't find right now.
martin
no not evil, if know doing: or bad gpos?
, if bothers me - coke bottle design refreshment :))
restore forum design - user defined cascading style sheet!
Windows Server > Group Policy
Comments
Post a Comment