[prev in list] [next in list] [prev in thread] [next in thread] 

List:       thin
Subject:    [THIN] Re: GPO's using loop back
From:       Anthony_Baldwin () mhsnr ! org
Date:       2007-02-27 18:09:07
Message-ID: OF465D81AD.275D5CBA-ON8525728F.0063226B-8525728F.0063B68A () health-partners ! org
[Download RAW message or body]

This is a multipart message in MIME format.
--=_alternative 0063B6878525728F_=
Content-Type: text/plain; charset="US-ASCII"

I thought that if you added a user/group under the scope tab of the GPMC 
it would set the 'read (from security filtering)' right by default (which 
should include 'read' and 'apply group policy').

Were you adding the user/group in the delegation tab?

By the way, I just figured out that you can get to the same detailed 
security listing (as you get editing the GPO) by clicking the advanced 
button on the delegation tab in the GPMC.

Tony




"Jason Benway" <benwayj@ghsp.com> 
Sent by: thin-bounce@freelists.org
02/27/2007 12:57 PM
Please respond to
thin@freelists.org


To
<thin@freelists.org>
cc

Subject
[THIN] Re: GPO's using loop back






I used a computer that didn't have the GPMC and checked the security on 
the GPO and I have a checkbox for apply group policy. Checked it, did a 
gpupdate and its working now.
 
Thank you very much. I wonder where the option of "apply group policy" is 
in the GPMC
 
jb

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On 
Behalf Of Jason Benway
Sent: Tuesday, February 27, 2007 12:51 PM
To: thin@freelists.org
Subject: [THIN] Re: GPO's using loop back

using the GPMC my only options seem to be 
read
edit settings
edit settings,delete, modify security
 
jb

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On 
Behalf Of Anthony_Baldwin@mhsnr.org
Sent: Tuesday, February 27, 2007 12:01 PM
To: thin@freelists.org
Subject: [THIN] Re: GPO's using loop back


Jason, 

Did you give the group and/or test user the "Apply group policy" right 
also? 

Tony 



"Jason Benway" <benwayj@ghsp.com> 
Sent by: thin-bounce@freelists.org 
02/27/2007 11:12 AM 

Please respond to
thin@freelists.org



To
<thin@freelists.org> 
cc

Subject
[THIN] GPO's using loop back








I'm running my citrix server in loop back merged mode. I have the IE
home page setup in my main GPO for citrix. But now I'm trying to add
another GPO in loop back merge so users from another domain that log in
have a differen home page.

On the new GPO I removed authenicated users and add jsjdist\domain users
with read access. But when I run gpresult I get: jsjdist Intranet Site
   Filtering:  Denied (Security)

I even directly added a test user with read access to the policy and get
the same thing.

The servers have been rebooted and gpupdate has been ran. I created the
policy a week ago, so I doubt its any replication type issue.

Please help.

Thanks,jb
SBC SITES ONLY GOOGLE SEARCH: http://www.F1U.com 
************************************************
For Archives, RSS, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link:
http://www.freelists.org/list/thin
************************************************



--=_alternative 0063B6878525728F_=
Content-Type: text/html; charset="US-ASCII"


<br><font size=2 face="sans-serif">I thought that if you added a user/group
under the scope tab of the GPMC it would set the 'read (from security filtering)'
right by default (which should include 'read' and 'apply group policy').</font>
<br>
<br><font size=2 face="sans-serif">Were you adding the user/group in the
delegation tab?</font>
<br>
<br><font size=2 face="sans-serif">By the way, I just figured out that
you can get to the same detailed security listing (as you get editing the
GPO) by clicking the advanced button on the delegation tab in the GPMC.</font>
<br>
<br><font size=2 face="sans-serif">Tony</font>
<br>
<br>
<br>
<br>
<table width=100%>
<tr valign=top>
<td width=40%><font size=1 face="sans-serif"><b>&quot;Jason Benway&quot;
&lt;benwayj@ghsp.com&gt;</b> </font>
<br><font size=1 face="sans-serif">Sent by: thin-bounce@freelists.org</font>
<p><font size=1 face="sans-serif">02/27/2007 12:57 PM</font>
<table border>
<tr valign=top>
<td bgcolor=white>
<div align=center><font size=1 face="sans-serif">Please respond to<br>
thin@freelists.org</font></div></table>
<br>
<td width=59%>
<table width=100%>
<tr valign=top>
<td>
<div align=right><font size=1 face="sans-serif">To</font></div>
<td><font size=1 face="sans-serif">&lt;thin@freelists.org&gt;</font>
<tr valign=top>
<td>
<div align=right><font size=1 face="sans-serif">cc</font></div>
<td>
<tr valign=top>
<td>
<div align=right><font size=1 face="sans-serif">Subject</font></div>
<td><font size=1 face="sans-serif">[THIN] Re: GPO's using loop back</font></table>
<br>
<table>
<tr valign=top>
<td>
<td></table>
<br></table>
<br>
<br>
<br><font size=2 color=blue face="Arial">I used a computer that didn't
have the GPMC and checked the security on the GPO and I have a checkbox
for apply group policy. Checked it, did a gpupdate and its working now.</font>
<br><font size=3>&nbsp;</font>
<br><font size=2 color=blue face="Arial">Thank you very much. I wonder
where the option of &quot;apply group policy&quot; is in the GPMC</font>
<br><font size=3>&nbsp;</font>
<br><font size=2 color=blue face="Arial">jb</font>
<br>
<br>
<hr><font size=2 face="Tahoma"><b>From:</b> thin-bounce@freelists.org [mailto:thin-bounce@freelists.org]
<b>On Behalf Of </b>Jason Benway<b><br>
Sent:</b> Tuesday, February 27, 2007 12:51 PM<b><br>
To:</b> thin@freelists.org<b><br>
Subject:</b> [THIN] Re: GPO's using loop back</font><font size=3><br>
</font>
<br><font size=2 color=blue face="Arial">using the GPMC my only options
seem to be </font>
<br><font size=2 color=blue face="Arial">read</font>
<br><font size=2 color=blue face="Arial">edit settings</font>
<br><font size=2 color=blue face="Arial">edit settings,delete, modify security</font>
<br><font size=3>&nbsp;</font>
<br><font size=2 color=blue face="Arial">jb</font>
<br>
<br>
<hr><font size=2 face="Tahoma"><b>From:</b> thin-bounce@freelists.org [mailto:thin-bounce@freelists.org]
<b>On Behalf Of </b>Anthony_Baldwin@mhsnr.org<b><br>
Sent:</b> Tuesday, February 27, 2007 12:01 PM<b><br>
To:</b> thin@freelists.org<b><br>
Subject:</b> [THIN] Re: GPO's using loop back</font><font size=3><br>
</font>
<br><font size=2 face="sans-serif"><br>
Jason,</font><font size=3> <br>
</font><font size=2 face="sans-serif"><br>
Did you give the group and/or test user the &quot;Apply group policy&quot;
right also?</font><font size=3> </font><font size=2 face="sans-serif"><br>
<br>
Tony</font><font size=3> <br>
<br>
<br>
</font>
<table width=100%>
<tr valign=top>
<td width=55%><font size=1 face="sans-serif"><b>&quot;Jason Benway&quot;
&lt;benwayj@ghsp.com&gt;</b> <br>
Sent by: thin-bounce@freelists.org</font><font size=3> </font>
<p><font size=1 face="sans-serif">02/27/2007 11:12 AM</font><font size=3>
</font>
<br>
<table border=4 width=100%>
<tr valign=top>
<td width=100% bgcolor=white>
<div align=center><font size=1 face="sans-serif">Please respond to<br>
thin@freelists.org</font></div></table>
<p>
<td width=44%>
<br>
<table width=100%>
<tr valign=top>
<td width=21%>
<div align=right><font size=1 face="sans-serif">To</font></div>
<td width=78%><font size=1 face="sans-serif">&lt;thin@freelists.org&gt;</font><font size=3>
</font>
<tr valign=top>
<td>
<div align=right><font size=1 face="sans-serif">cc</font></div>
<td>
<tr valign=top>
<td>
<div align=right><font size=1 face="sans-serif">Subject</font></div>
<td><font size=1 face="sans-serif">[THIN] GPO's using loop back</font></table>
<br>
<br>
<table width=100%>
<tr valign=top>
<td width=49%>
<td width=50%></table>
<br></table>
<br><font size=3><br>
<br>
</font><font size=2><tt><br>
I'm running my citrix server in loop back merged mode. I have the IE<br>
home page setup in my main GPO for citrix. But now I'm trying to add<br>
another GPO in loop back merge so users from another domain that log in<br>
have a differen home page.<br>
<br>
On the new GPO I removed authenicated users and add jsjdist\domain users<br>
with read access. But when I run gpresult I get: jsjdist Intranet Site<br>
 &nbsp; Filtering: &nbsp;Denied (Security)<br>
<br>
I even directly added a test user with read access to the policy and get<br>
the same thing.<br>
<br>
The servers have been rebooted and gpupdate has been ran. I created the<br>
policy a week ago, so I doubt its any replication type issue.<br>
<br>
Please help.<br>
<br>
Thanks,jb<br>
SBC SITES ONLY GOOGLE SEARCH: http://www.F1U.com <br>
************************************************<br>
For Archives, RSS, to Unsubscribe, Subscribe or <br>
set Digest or Vacation mode use the below link:<br>
http://www.freelists.org/list/thin<br>
************************************************<br>
</tt></font><font size=3><br>
</font>
<br>
--=_alternative 0063B6878525728F_=--

SBC SITES ONLY GOOGLE SEARCH: http://www.F1U.com 
************************************************
For Archives, RSS, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link:
http://www.freelists.org/list/thin
************************************************
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic