A Group Policy (UMROOT Deny All Logons) was linked to the Sites\Computers OU. The GPO implements logon restrictions for accounts that are a security risk to the UMROOT Active Directory domain. The GPO is maintained by the ITCS LAN/NOS group, and is linked to the top level OU in the UMROOT domain. Because inheritance is blocked on many Sites Computer OU’s, it was necessary to link the GPO in the Sites OU structure and to set the link to enforced in order to override the blocked inheritance.
--Terry
No comments:
Post a Comment