local policy exception to group policy

Here's our situation:

We're running SBS 2003 and I have the security policy of having the 
computers "lock" after 30 minutes, so to prevent unauthorized usage ~ we have 
many organizations and students wandering about.

We just added a security system that's based on XP and I added the computer 
to our network, so staff can monitor alley ways and exits.  Unfortunately, 
this computer now locks as well, defeating the purpose of a 24-7 monitor.

Is there a way to create an exception to the local policy?

Thanks!
-- 
"I''m a IT administrator, Jim, not a doctor!"

~Leonard McCoy in a parallel universe
0
Utf
1/14/2010 4:04:01 AM
windows.server.sbs 1975 articles. 0 followers. Follow

4 Replies
877 Views

Similar Articles

[PageSpeed] 14

Create a security group and add computers you want to override the policy 
on.

Create a new group policy and add the settings you want.

Apply the group policy only to the security group you created above instead 
of the default of everything/everyone.  And check the option to enforce it 
so it overrides other settings.

-Cliff


"Dano" <Dano@discussions.microsoft.com> wrote in message 
news:EE361273-AC19-42DC-8C45-631478C4F69A@microsoft.com...
> Here's our situation:
>
> We're running SBS 2003 and I have the security policy of having the
> computers "lock" after 30 minutes, so to prevent unauthorized usage ~ we 
> have
> many organizations and students wandering about.
>
> We just added a security system that's based on XP and I added the 
> computer
> to our network, so staff can monitor alley ways and exits.  Unfortunately,
> this computer now locks as well, defeating the purpose of a 24-7 monitor.
>
> Is there a way to create an exception to the local policy?
>
> Thanks!
> -- 
> "I''m a IT administrator, Jim, not a doctor!"
>
> ~Leonard McCoy in a parallel universe 

0
Cliff
1/14/2010 5:49:53 AM
Thanks Cliff,

That kinda worked:

I can now change the screen saver settings, the time amount setting, but the 
password protect is still grayed out...

I tried several combos and none seem to allow me to unselect password 
protect...
0
Utf
1/16/2010 1:19:01 AM
Don't try to set this locally.  Once a group policy sets this, you have to 
override it via group policy as well, you can't simply make it available 
again.

In the group policy you created and enforced, go to user 
settings->policies->admin templates->control panel->display

Now the right panel has several options including "password protect the 
screen saver"

If you set that to DISABLED (and have set up everything else as I outlined) 
because it is a USER setting, it applies to all users.  BUT with the 
security group filter you created, it will only apply to those users when 
they log onto a computer in that security group.  Aka, no screen saver lock.

Hope that helps,

-Cliff


"Dano" <Dano@discussions.microsoft.com> wrote in message 
news:19D63255-600E-43F8-851B-9C04E35D21D7@microsoft.com...
> Thanks Cliff,
>
> That kinda worked:
>
> I can now change the screen saver settings, the time amount setting, but 
> the
> password protect is still grayed out...
>
> I tried several combos and none seem to allow me to unselect password
> protect... 

0
Cliff
1/16/2010 4:34:32 PM
Thanks Cliff, that helps alot.

I guess what was confusing me was the fact the check box for pw protect was 
greyed out.


-- 
"I''m a IT administrator, Jim, not a doctor!"

~Leonard McCoy in a parallel universe


"Cliff Galiher - MVP" wrote:

> Don't try to set this locally.  Once a group policy sets this, you have to 
> override it via group policy as well, you can't simply make it available 
> again.
> 
> In the group policy you created and enforced, go to user 
> settings->policies->admin templates->control panel->display
> 
> Now the right panel has several options including "password protect the 
> screen saver"
> 
> If you set that to DISABLED (and have set up everything else as I outlined) 
> because it is a USER setting, it applies to all users.  BUT with the 
> security group filter you created, it will only apply to those users when 
> they log onto a computer in that security group.  Aka, no screen saver lock.
> 
> Hope that helps,
> 
> -Cliff
> 
> 
> "Dano" <Dano@discussions.microsoft.com> wrote in message 
> news:19D63255-600E-43F8-851B-9C04E35D21D7@microsoft.com...
> > Thanks Cliff,
> >
> > That kinda worked:
> >
> > I can now change the screen saver settings, the time amount setting, but 
> > the
> > password protect is still grayed out...
> >
> > I tried several combos and none seem to allow me to unselect password
> > protect... 
> 
> .
> 
0
Utf
1/16/2010 8:25:01 PM
Reply:

Similar Artilces:

Unhandled Form Exception
Hi, On Citrix boxes, GP 7.5, SQL Server 2000 all of a sudden on one of the citrix boxes users cannot get into great plains. The get the following error message: Unhandled form exception: Cannot open form. Script terminated EXCEPTION_CLASS_FORM_MISSING We got everyone off of that citrix box and rebooted the box but we still have the issue. Any ideas? TIA Ok I solved it! In Yahoo Great Plains groups I was able to search the archives for Unhandled Form Exception and found some reports. Most of these errors come from some kind of trouble with the .dic file it seems. Some are secu...

Unhandled Exception
When I try to add a new product, I get the following message: <description>The specified object was not found.</description> I checked to make sure that the description field was there. What could be wrong? Kathyc, Have you made any customizations to the system? Checking the event log on the Event Viewer (on the server) could also help you try to find out what happened. Regards, Leo Lopes @ L3 ...

keep record and groups in record together
I just posted this but I'm not sure if it actually posted so I am reposting. Sorry if this is twice. I am trying to keep records from splitting, bleeding onto the next page. I don't want each record on one page, but I don't want a record to start on one page and continue on the next page. Any help would be appreciated. Thank you, Debbie Go the section header and right click to get properties. Set force new page to before section, after section, or both depending on what you need. "Debbie S." wrote: > I just posted this but I'm not sure if it actually post...

Getting both gmt and local date time
I'm trying to get both gmt and local date time (in CTime type) using the following approach. Am I correct? If not, what is the correct way? // code starts CTime time(CTime::GetCurrentTime()); tm local_tm_time = *(time.GetLocalTm()); tm gmt_tm_time = *(time.GetGmtTm()); const CTime gmt_date_time(1900+gmt_tm_time.tm_year, gmt_tm_time.tm_mon, gmt_tm_time.tm_mday, gmt_tm_time.tm_hour, gmt_tm_time.tm_min, gmt_tm_time.tm_sec); const CTime local_date_time(1900+local_tm_time.tm_year, local_tm_time.tm_mon, local_tm_time.tm_mday, local_tm_time.tm_hour, local_tm_time.tm_min, local_tm_time.tm_...

mail stays in local queue of smtp connector & Event ID: 327
We have replicated exchange 5.5 server PF's to E2k server and later created new SMTP connector on E2K server and we are seeing these messages. Microsoft kb article mentions the corruption of store and says a fix is available but the error number is different in our case to the one mentioned in KB article. What could be the reason ? ---------------------------------------------------------------------------- ---------------------------------------------- Source : MSExchangeTransport Category : Exchange Store Driver event ID : 327 Description : The following call : EcLocallyDel...

Edit a group of cells with a macro
I have imported data from another program which combines numeric and alpha characters into a single cell. I need to split the numeric data into one column and the alpha characters into an adjacent column. I copied the imported column into the adjacent column, then went to first column and created a macro which deletes the first 7 characters (the numeric values). When I run the macro on other cells it takes the information from the very first cell and keeps repeating it. What am I doing wrong? Hi! Can you post a few examples of the data you want to separate? Al -- Message posted from h...

Unhandled exception at 0x10001e80 in EXCEL.EXE: 0xC0000005: Access violation reading location 0x10001e80.
Hi All, Does somebody know what's a shit is that? I installed XP from scratch, then all service packs and update, VS etc., finally I installed the Office 2000. When I close Excel (and Word as well) I get this error. Unhandled exception at 0x10001e80 in EXCEL.EXE: 0xC0000005: Access violation reading location 0x10001e80. I installed all service packs and updated over the office, no results. My friend told me that it's a big difference how did we install Office, in what order. If I install the Office exactly after Windows main installation, then install all other packages, updates, ...

account group
Hi all, Am very new to Exchange administration and am not sure if this query is in the correct newsgroup. My problem is as follows: In our company everyone has a seperate login and a seperate mailbox. Everyone is divided into groups. Eg: Accounts, Payroll etc. In case a mail is sent to a group like accounts, everyone in that group would get a copy, and it they are not in communication, all might attempt to solve the same problem. What i need is how do i mark a mail as read, if one person in the group has attended to a problem that has been sent to a group? Idealy if person A ha...

Distrobution Groups
I created a Distrobution /Universal group. Added members but it does not send email to them when i select the group in outlook any ideas? On Sun, 2 Oct 2005, Kidem wrote: > I created a Distrobution /Universal group. Added members but it does > not send email to them when i select the group in outlook any ideas? Did you refresh the GAL? Did you force an explicit rebuild of the offline address book? And an explict address book download in Outlook? -- http://www.munted.org.uk If kernel developers were diplomats, we'd all be nuked by now... yes, its working now!!thx "...

Creating a process as the local user from a program in the system account?
Assuming that I have an executable that runs in the system context (for example started from AT without /interactive). How would I go about starting a program for the current, logged in user? - Anders G Have you looked at CreateProcessAsUser, maybe that one can help. /Niklas "Anders Gustafsson" <dalNOton@peSPAMdago.fi> wrote in message news:VA.00000066.00b3d048@pespamdago.fi... > Assuming that I have an executable that runs in the system context (for > example started from AT without /interactive). How would I go about > starting a program for the current, logg...

Christmas labels from Entourage group
Version: 2004 Operating System: Mac OS X 10.5 (Leopard) Processor: Intel Email Client: pop Every Christmas I spend hours trying to print labels from the Christmas group in my Entourage address book. I do not want to merge the entire Entourage address book to the labels. Just the Christmas group of 100 names and addresses. Currently I get only a choice of all 683 or nothing. <br> Where do I indicate just the Christmas Group? Am going to resort to handwriting the addresses if I don't get help. Thanks. How did you go about creating the labels? Did you use the Mail Merge Ma...

Window focus policy
Where can I find some info about how MFC's focus policy works, and how to change it in an SDI with mulltiple views. I GetFocus, but my mouse cursor is still in the other CView. Specifically how do I make my view the Active view by clicking on it? My project looks a lot like; http://www.codeproject.com/treectrl/ctreeview_iterator.asp Is all I need to do is write the code for SetTopLevelParent(CView * pV) for CView3::OnLButtonDown(...) { SetForegroundWindow(); // need to SetTopLevelParent(this); pMainFrame->ActiveTopPanret() pMainFrame->SetActiveView; } That last sugges...

User/group relationship for security in FRx
In FRx security, the security settings for groups immediate cascade down to the users so later changes need to be applied to each member individually. It would be helpful to have the security setting remain at a group level so later updates could be done more easily. ---------------- This post is a suggestion for Microsoft, and Microsoft responds to the suggestions with the most votes. To vote for this suggestion, click the "I Agree" button in the message pane. If you do not see the button, follow this link to open the suggestion in the Microsoft Web-based Newsreader and then...

Grouping??
Let's say I have a test matrix that has the following columns: TC_NAME, REQ#, TESTER, AUTOMATE In the TC_NAME are the test cases where the TCs appear multiple times when they address multiple requirements. E.g. TC_NAME REQ# REQ TESTER AUTO PrintQueue001 1.2.1234 Print Queue contents Joe Blow Yes PrintQueue001 1.2.1235 Print Queue config Joe Blow Yes PrintQueue001 1.2.1236 Print Queue Owner Joe Blow Yes SaveQueue001 2.1.1234 Save a Queue Moe Blow No SaveQueue002 2.1.1235 Save a Queue w/ bad path Moe Blow No SaveQueue003 2....

Community Group user of Ms CRM
Hi We have a client who wishes to implement MS CRM. They have asked us to find a reference site who is a community, or not-for-profit group who has at least started an implementation. If nyou are such an orgnaisation, or have worked with one, and are willing to be such a reference site, please contact me via the newsgroup or on gillwalker@ozemail.com.au Thanks Gill ...

Applying a policy to groups
Hello All, I am trying to apply a policy in Exchange 2003 for the first time. I want to limit a number of users mailboxes to 500mb. How can i do this via a policy. I followed http://support.microsoft.com/default.aspx?scid=kb;en-us;822938&Product=exch2003 but this is only how to do it for an entire server. Surely this can be done just for a container of users. Limits can be set at the Store level or on the individual mailboxes, not via groups or OU's -- Mark Fugatt Exchange MVP http://www.exchangetrainer.com http://www.msexchange.org "aaron.whittaker" <aaronwhittak...

Recipient Policy Question #6
My company is changing its name and obviously wants to reflect this with their email addresses. They want to use firstname.surname@newdomain.com format. Currently, there are a lot of bespoke email addresses with multiple domain names being used. The management would like to change this from the 1st of January for everyone at the same time. There are over 1000 users and manually changing each address is not viable (so I hope!) The vast majority of users have the "Automatically update e-mail addresses based on recipient policy" under AD Users and Computers unchecked. I have already ...

pay code is not subjet to local tax
i need to creat a pay code that is not subject to local tax the help files say that there is a checkbox called local in the paycode setup form, but i can not find it. i tryed to find any option in setups but i did not. thanx in advance I solved the problem i installed dynamics a country other than U.S so it hides the "subject to taxes" checkboxes in some windows like pay code master window but i do not know why it still calculating it so what i did is that i reinstalled the system with U.S choice and the checkboxes is visible now but i still do not know how it will affect the ...

Non-local users?
Hi, When adding a group to mailbox permissions in Outlook 2K7 there are a number of groups, new and old, that have a circle with a line through it on the icon. When I try to use these groups I receive this message: "One or more users cannot be added to the folder access list. Non-local users cannot be given rights on this server." Using Outlook 2K3, I can add the group, but it doesn't work. I've created/recreated groups with ECM on the Exchange server as well as on a DC. I've tried assigning mailbox permissions via the ECS which doesn't error out, but still d...

OWA and Group Policy
I have E3K with OWA running. I have a OU with a lockdown policy running for Users and Computers. I logon to a pc and user thats in the lockdown OU and can open OWA, but get a "access denied" when I try to open a email. I'm looking for a doc that will tell me what GP's need to be open for OWA to work. thansk., On 8 Mar 2006 09:16:35 -0800, "Rick" <drummer10980@gmail.com> wrote: >I have E3K with OWA running. I have a OU with a lockdown policy running >for Users and Computers. I logon to a pc and user thats in the lockdown >OU and can open OWA, but g...

Set which local email account can send mail to contacts in address book. (associating an email address with a contact)
I use Outlook 2k3 with 3 separate email addresses configured to send and receive email. Is there a way when I create a new contact in my address book (and to go back and assign to old contacts) which email address will be used to send that person email? For example I want to send email to Thomas at company X if i hit new message button and pick his name out of the address book is there a way have outlook automatically default to which email address I have assigned to his contact information? I am afraid that I will send email from the wrong account. Also using different identities is not ...

concatenate while grouping
Thanks for any help. I am trying to concatenate a field from record(s) into a field, while grouping them. For example, the query (with no concatenation, but with grouping) is like: SELECT Table!name, Table!date FROM Table GROUP BY Table!name, Table!date I would like to make a query that along with grouping by name and date, makes another field, that is a concatenation of all fields called Policy. I am trying to do this with Duane Hookum's concatenation function, but can't figure it out, I think because his function doesn't need a grouping to do it. But I have to use a groupi...

Recovery Storage Groups
Is there any way to implement a Recovery Storage Group in Exchange 2000? I know it is a feature new to Exchange 2003, but we have a situation where this would be extremely helpful in an Exchange 2000 environment. A user needs to recover a mailbox, but only has database backups. Thanks not that I know of...that was a new option with Exchange 2003...you would need to build a recovery server...was mailbox retention not set? "RP" <RP@discussions.microsoft.com> wrote in message news:59A59F92-A8A9-4477-8625-6F093D6416C7@microsoft.com... > Is there any way to implement a Rec...

Grouping Improperly Impacting Printing
When printing today's daily calendar all works well, including printing of grouped tasks where they are expanded. When printing a daily calendar for any day other than the current day, grouped tasks that are expanded do not print. Irregardless of the settings, it prints a collapsed bar, showing the field name I have grouped by. If I ungroup the tasks, and print a daily calendar tasks print fine. In both instances I have print tasks select within the page set up area. I am running WinXP home, and Outlook 2002 SP-2. All updates are current. On another computer running Win2000...

option group not registering selection
I have a form with 12 option groups, each a field in a table. The table formats each of the fields (Ambulation, Transfer, ADL, etc.) as a number with a default of 0. The user selects an option, 1, 2, or 3, via the option group. A command button runs this function: Private Sub cmdCalculate_Click() CountLow =3D 0 CountModerate =3D 0 CountComplex =3D 0 CountZero =3D 0 If Ambulation =3D 0 Then CountZero =3D CountZero + 1 Else If Ambulation =3D 1 Then CountLow =3D CountLow + 1 Else If Ambulation =3D 2 Then ...