Windows 7 Clients on 2003 DC Group Policy Problem


we have windows 7 enterprise clients managed server 2003 r2 ent domain controller. know need server 2008 realize group policy compatibility here's problem in meantime.

i didn't build windows 7 image, is, domain user can run gpedit.msc , make alterations in parts of local machine policy (those not controlled policy objects of server 2003).

if restrict authoring under user configuration > administrative templates > windows components > microsoft management console, applies exact same restrictions administrators. in fact can lock admins out of mmc , related components.

the funny part is, when user access gpedit.msc, don't uac prompt, whereas if administrator (local or domain), uac prompt.

until server 2008, there anyway rectify this? users should have no access group policy editing features, yet image i'm working with, can , do, , have necessary rights turn on , off settings under both machine , user administrative template settings.

totally stumped here...any assistance appreciated.

 
> have windows 7 enterprise clients managed server 2003 r2 ent
> domain controller. know need server 2008 realize
> group policy compatibility here's problem in meantime.
>
 
no, don't. client not care dc,
thing need schema update able use wireless policies
and bitlocker ad integration. else (regarding gpos)
file system (sysvol) based.
 > if restrict authoring under user configuration > administrative
> templates > windows components > microsoft management console,
> applies exact same restrictions administrators. in fact can
> lock admins out of mmc , related components.
 
then apply appropriate security filter policy - exclude
administrators group.
 
> funny part is, when user access gpedit.msc, don't
> uac prompt, whereas if administrator (local or domain),
> uac prompt.
>
 
this result of mmc.exe's manifest - has "highestavailable", ,
that means "normal user - no prompt", "admin user - prompt". same
true event viewer.
btw: sure not - accident possibly - local
administrators? if can make changes through gpedit.msc,
believe in fact admins...
 
regards, martin
 

no not evil, if know doing: or bad gpos?
wenn meine antwort hilfreich war, freue ich mich über eine bewertung! if answer helpful, i'm glad rating!


Windows Server  >  Group Policy



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS