QuestionQ3

Deploy and manage AD DS

Your network includes an Active Directory Domain Services (AD DS) domain.

A Group Policy Object (GPO) named Security Baseline is linked to the domain, and its link is configured as Enforced.

A GPO named Kiosk Baseline is linked to an organizational unit (OU) named Kiosks.

Client computers in the Kiosks OU receive Group Policy settings from the Security Baseline GPO.

You need to ensure that computers in Kiosks receive settings from the Kiosk Baseline GPO. Security Baseline must continue to apply to other client computers in the domain.

What should you do?

Explanation

An enforced domain-level GPO cannot be overridden by GPOs linked to lower-level OUs. Clearing Enforced from the Security Baseline link restores normal Group Policy precedence, under which the GPO linked directly to the Kiosks OU is processed later and can override conflicting domain settings for those computers. The Security Baseline GPO remains linked to the domain and therefore still applies to other domain client computers.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!