GPO delegation permission

  • 94 Views
  • Last Post 14 January 2016
nidhin_ck posted this 14 January 2016

Hi Experts,
As you know at the time of GPO creation, authenticated users group will be added in to the "security filtering" section of the gpo as well as in the delegation tab. But when we remove authenticated users from security filtering, it will also get removed from delegation tab. Is there any way to stop this default behavior. I just dont want "authenticated users" group get removed from delegation tab when we remove this group from security filtering.

Regards,
Nidhin CK

Order By: Standard | Newest | Votes
slavickp posted this 14 January 2016

No.
You’re trying to solve a non-issue. Think of Windows administration as that without tabs you click on.
Regards
Slav
MCM-AD

show

darren posted this 14 January 2016

The key thing that controls whether that ACE shows up in the “Security Filtering” tab, is the “Apply Group Policy” permission. If you simply remove that permission

using Delegation/Advanced, then it will just show up under Delegation with Read permissions only.

 

Darren

 

 

 

show

Close