Got myself thinking about an issue….
User logs into a machine which has all the various Machine & User GPO’s that get run that tightly lock it down. No problem….
However, on a certain batch of machines I don’t want them locked down as much. Ie. Same user with the same login, just different machine gets a different User GPO applied depending on which machine they log onto. (as well as a different machine GPO, but that’s not the problem).
The problem I see is that the User GPO gets applied depending on the OU container the user sits in, you can obviously apply different Machine GPO depending on the machines OU container, but not specify a different User GPO.
Am I making sense, or just babbling ! 😉
I work for a School, traditionally two networks, one for curriculum & one for admin. Various reasons moving to just one network so I don’t want users having two seperate logins.
But, depending on where the machine is (and what it generally gets used for) determies what is available (and is locked down).
Just the idea whirring around in my head, and am going to play with OU’s and GPO’s when back in the office, but needed to see if I suspicions are true and if anybody can offer advice.
Cheers
Pete