question

Yankee30 avatar image
0 Votes"
Yankee30 asked FanFan-MSFT commented

Impact of Group policies when moving between OU's

GPO 1(Domain Member Server Policy) with computer settings A,B,C,D & registries1 -> linked to OU 1
GPO 2(Domain Controller Policy) with computer settings X,Y,C,D & registries2 -> linked to Domain Controllers OU



  • Test 1



So we added the server A to domain in OU1 and as expected it got the settings A,B,C,D & registries 1 from GPO1.
Now we promoted this member server A to a Domain controller which moved it to Domain Controllers OU & now the settings are A,B,X,Y,C,D, registries 1 & registries 2.
Now X,Y,C,D & registries 2 being applied is understandable from GPO2
But it retained the settings as a local group policy from previously applied GPO 1 which is A,B & registries 2.
Is that the correct behavior to retain all previous settings & registries ?



  • Test 2



So we added the server B to domain in OU1 and as expected it got the settings A,B,C,D & registries 1 from GPO1.
I moved it to workgroup & I no longer see any of those A,B,C & D settings but only registries applied.
Will the registries won't delete when moving to workgroup?




windows-serverwindows-server-2019windows-group-policywindows-server-security
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

FanFan-MSFT avatar image
0 Votes"
FanFan-MSFT answered FanFan-MSFT commented

Hi,

I tried to do a test in my environment.
OU1 client
Deploy GPOs to OU1, configured the settings based on the registry and not based on registry.
Refresh the GPO on the client
Check all the settings are applied to the client
108279-6233.jpg
108280-6232.jpg
Remove client from OU1 to OU2
Restart the clients, all the settings applied from GPO1 was moved.
108353-6234.jpg
108343-6235.jpg

Not sure what settings did you deployed, if possible, please share a screenshot of the output of the command: gpresult /h report.html before and after the computer was moved.

Best Regards,



6233.jpg (125.9 KiB)
6232.jpg (112.0 KiB)
6234.jpg (105.5 KiB)
6235.jpg (72.6 KiB)
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
Welcome to share your current situation if there are any updates.
Please feel free to let us know if you need further assistance.


Best Regards,

0 Votes 0 ·

Hi,
I am checking to see if the problem has been resolved.
If there's anything you'd like to know, don't hesitate to ask.
Best Regards,

0 Votes 0 ·
ParvezGadhia-1089 avatar image
0 Votes"
ParvezGadhia-1089 answered

I believe the gpo leaves Group Policy Preferences (GPP) on the machine and that could be those registry settings you would be seeing on your domain controller which was a member server and residing under different ou before getting promoted as a domain controllers, and moved under domain controllers ou

GPP will be retained though the respective gpo is removed / unlinked.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.