Apply GPO in resource forest to users in another forest


domain.com  (contains user accounts)
windows server 2003 forest/domain
contains universal security group "resource app users" containing user accounts in domain.com

resource.com
windows server 2003 forest \ windows server 2008 r2 domain
contains "appusers" ou
in ou domain local security group "appgroup" containing "domain\resource app users" , few test accounts in resource domain

one-way trust:  resource.com trusts domain.com

there gpo set on "appusers" ou restricts programs can run along ie browser settings, security filtering set apply policy resource\appgroup
gpo applies test accounts in resource not members of "domain\resource app users" group
want users in "domain\resource app users" group log onto resource domain have policy applied

possible set one-way trust in place? if yes, needed working?

first, som comes mind (scope of management). gpos applied users reside in ou gpo linked to. groups add means of filtering, not of "applying". dlg appgroup meaningless.

in cross forest scenario, impossible within resource domain (the users - spoken - living in universe), need use loopback processing. , far know, not work 1 way trust. remember having read kb article long time ago confirms that, couldn't find right now.


martin

no not evil, if know doing: or bad gpos?
, if bothers me - coke bottle design refreshment :))

restore forum design - user defined cascading style sheet!



Windows Server  >  Group Policy



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B

DFSR RPC replication errors 5014 1726 with large files over VPN