添加一個(gè)組策略在AD的域上面,結(jié)果居然怎么也不生效阿迈,但如果安全過(guò)濾里用內(nèi)置的Authenticated Users組就能生效典蜕。
可是需求是并不需要對(duì)所有用戶生效,而是只需要對(duì)一個(gè)特定安全組里的用戶生效疼蛾,于是開(kāi)始了GOOGLE大法肛跌,最終找到原因及解決方案如下:
"MS16-072 changes the security context with which user group policies are retrieved. This by-design behavior change protects customers’ computers from a security vulnerability. Before MS16-072 is installed, user group policies were retrieved by using the user’s security context. After MS16-072 is installed, user group policies are retrieved by using the computer's security context. This issue is applicable for the following KB articles"
現(xiàn)象是這樣的:
建了個(gè)名叫Desktop & My Documents Restriction的GPO如下圖,設(shè)置只應(yīng)用到紅色箭頭指向的用戶安全組里的人員察郁。
用命令更新組策略
gpupdate
更新成功后用命令查看結(jié)果:
gpresult /r
哦哦衍慎,顯示
<Group Policy Name>
Filtering: Not Applied (Unknown Reason)
不明原因,未應(yīng)用绳锅!
解決方案也簡(jiǎn)單:
對(duì)于針對(duì)用戶和用戶組進(jìn)行的過(guò)濾西饵,只需要在該GPO的授權(quán)策略選項(xiàng)卡,點(diǎn)添加鳞芙,然后添加組Authenticated Users眷柔,權(quán)限設(shè)為Read(讀绕谙骸)即可。
對(duì)于針對(duì)計(jì)算機(jī)的過(guò)濾驯嘱,同樣的方法镶苞,添加Domain Computers(域計(jì)算機(jī))組,設(shè)權(quán)限為Read(讀染掀馈)即可茂蚓。
達(dá)叔傻樂(lè)(darwin.zuo@163.com)