Domain Member Server Group Policies


this two-part question. i'm trying understand why configure member server group polices when domain controller governs (group) policies member servers in domain? sounds redundant though there may reason though not clear me. second question similar - why configure local policies of member server if dc governs member policies? done backup measure if dc become unavailable?

thanks

hi steve,

thanks post.

based on knowledge, there's precedence group policy. domain controller control domain computers group policy. set group policy in member server apply member server and not afffect other computer. group policy objects (gpos) apply user (or computer) not have same precedence. settings applied later can override settings applied earlier.

the order of  group policy processing local group policy, site, domain , ou. order means local gpo processed first, , gpos linked organizational unit of computer or user direct member processed last, overwrites settings in earlier gpos if there conflicts. (if there no conflicts, earlier , later settings merely aggregated.)

https://technet.microsoft.com/en-us/library/cc785665(v=ws.10).aspx

best regards,

mary dong


please remember mark replies answers if , unmark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Group Policy



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS