Domain Social Forums
"Deny Apply Policy" for Domain Admin not working - Printable Version

+- Domain Social Forums (http://www.domainsocial.com)
+-- Forum: Domain Discussions (http://www.domainsocial.com/Forum-Domain-Discussions)
+--- Forum: Domain Name Appraisals (http://www.domainsocial.com/Forum-Domain-Name-Appraisals)
+--- Thread: "Deny Apply Policy" for Domain Admin not working (/Thread-Deny-Apply-Policy-for-Domain-Admin-not-working)



"Deny Apply Policy" for Domain Admin not working - Williamhawk - 12-20-2017

Hi,

I have an GP on an OU that contains my terminal servers.  The GP specifies the path for roaming profile to be used when accessing the terminal server.  

I have the "Apply Policy" security setting for Domain Admins set to deny per KB816100 How To Prevent Domain Group Policies from Applying to Administrator (Windows Server 2003).  

However, when I log in as Domain Administrator a roaming profile is used.  

I used RSOP to look at the setting for the romaing profile path and it says it is being set by the GP on the terminal servers OU.

Can anyone explain why the Deny isn't working?

Please help.

Thanks!

I didn't find the right solution from the Internet.

References:
https://social.technet.microsoft.com/Forums/windowsserver/en-US/975e7272-971c-471f-9f71-7bb93ce00d0b/deny-apply-policy-for-domain-admin-not-working?forum=winserverGP

 Minimalist Animation