Re: [Samba] Group Policy Permissions
- Date: Tue, 14 Aug 2018 20:52:04 +0200
- From: Michal Sládek via samba <samba@xxxxxxxxxxxxxxx>
- Subject: Re: [Samba] Group Policy Permissions
2018-08-14 20:38 GMT+02:00 Rowland Penny via samba <samba@xxxxxxxxxxxxxxx>:
> On Tue, 14 Aug 2018 20:15:04 +0200
> Michal Sládek via samba <samba@xxxxxxxxxxxxxxx> wrote:
> > Thank you for your suggestion, I read the whole discussion.
> > My situation is little bit different - my machine policy works, but it
> > stops working once I remove Apply permission from Authenticated Users
> > and replace it with Read and Apply permission for Domain Computers.
> > Group Policy Results in RSAT shows Reason Denied: Access Denied
> > (Security Filtering) for affected computer.
> > The same result I get with command gpresult /Z /SCOPE COMPUTER:
> > The following GPOs were not applied because they were filtered out
> > -------------------------------------------------------------------
> > Import CA Certificates
> > Filtering: Denied (Security)
> > I don't understand why Domain Computers group is not enough...
> That triggered a memory 'MS16-072', see here:
> and here:
> Also here:
I know about those changes, but they affected only user policies (context
changed from user to computer account while retrieving the policy from
I would appreciate a lot if somebody could test my scenario on Samba AD
domain - create any group policy that affects computer configuration and
set Security Filtering to Domain Computers only.
To unsubscribe from this list go to the following URL and read the