Environment: win2008 ( benet.com domain controller), +32 bit Win7 ( yy-pc have joined benent.com) +64 -bit win7(yyy-pc joined benet.com)
1,benet.com domain controller created inside OU user1 and the User2 , which create users separately UserA and the UserB , respectively, will be two units Win7 Join OU
650) this.width=650; "src=" Https://s5.51cto.com/oss/201711/17/f3fd06a70ed3c9905277cb4923ab8cca.png "title=" 0.png " alt= "F3fd06a70ed3c9905277cb4923ab8cca.png"/>
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/b36fafd83d7207b879641f0454166d9f.png "title=" 1.png " alt= "B36fafd83d7207b879641f0454166d9f.png"/>
650) this.width=650; "src=" Https://s4.51cto.com/oss/201711/17/490c96e3a2ab2d902e9d91f4a33e132e.png "title=" 2.png " alt= "490c96e3a2ab2d902e9d91f4a33e132e.png"/>
650) this.width=650; "src=" Https://s2.51cto.com/oss/201711/17/4ba6977b1a148432d52be7398288786e.png "title=" 3.png " alt= "4ba6977b1a148432d52be7398288786e.png"/>
650) this.width=650; "src=" Https://s4.51cto.com/oss/201711/17/dfddf41bec71a1035fec7305b00688c5.png "title=" 4.png " alt= "Dfddf41bec71a1035fec7305b00688c5.png"/>
650) this.width=650; "src=" Https://s1.51cto.com/oss/201711/17/fede2f16beb803ccadffd41d800c8120.png "title=" 5.png " alt= "Fede2f16beb803ccadffd41d800c8120.png"/>
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/5b97565d6adfabb28f241afdac187930.png "title=" 6.png " alt= "5b97565d6adfabb28f241afdac187930.png"/>
with UserA and the UserB Log in separately ou internal and ou external computer for verification.
at this yyy-pc A restart is required to apply Group Policy.
650) this.width=650; "src=" Https://s5.51cto.com/oss/201711/17/6c3f86cb219a5af097d811434d291bd5.png "title=" 0.png " alt= "6c3f86cb219a5af097d811434d291bd5.png"/>
650) this.width=650; "src=" Https://s1.51cto.com/oss/201711/17/a8be3f8d935f61a8af8e238f346d31b4.png "title=" 1.png " alt= "A8be3f8d935f61a8af8e238f346d31b4.png"/>
650) this.width=650; "src=" Https://s5.51cto.com/oss/201711/17/6d76b868a36331eca865930ba980844b.png "title=" 2.png " alt= "6d76b868a36331eca865930ba980844b.png"/>
650) this.width=650; "src=" Https://s5.51cto.com/oss/201711/17/140aefa75c34181f1aec3c4f9125c7f3.png "title=" 3.png " alt= "140aefa75c34181f1aec3c4f9125c7f3.png"/>
2 , configure Group Policy to apply to User1 on the user, to verify.
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/28b2b75f854986a67b796f0e98160642.png "title=" 0.png " alt= "28b2b75f854986a67b796f0e98160642.png"/>
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/eda48e9448df75995894871d1064b422.png "title=" 1.png " alt= "Eda48e9448df75995894871d1064b422.png"/>
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/63a82da2bb1ada4988027948df4e608e.png "title=" 2.png " alt= "63a82da2bb1ada4988027948df4e608e.png"/>
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/579a598ebea6760a60fc06d3eb0212cd.png "title=" 3.png " alt= "579a598ebea6760a60fc06d3eb0212cd.png"/>
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/650bada6faf1fca58faa534299a8c632.png "title=" 4.png " alt= "650bada6faf1fca58faa534299a8c632.png"/>
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/a6cc3d038850f76da147640d0ca71891.png "title=" 5.png " alt= "A6cc3d038850f76da147640d0ca71891.png"/>
In addition, the user Win7 ( + bit) When you log in, the black background is displayed, and when you view the desktop background settings, you will find that you have actually changed.
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/0f6fbf4cf519b1b3ee1f6092c32d3a90.png "title=" 0.png " alt= "0f6fbf4cf519b1b3ee1f6092c32d3a90.png"/>
Group Policy inheritance and blocking
User1 the child ou ( user1-1 : User AA ) is selected to block inheritance, and the child OU ( User1-2 : User BB ) for comparison.
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/3af24b33d958b5f8108aac933c480a8c.png "title=" 0.png " alt= "3af24b33d958b5f8108aac933c480a8c.png"/>
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/7f65cc47603c7b42c31e453e6bda8dfa.png "title=" 1.png " alt= "7f65cc47603c7b42c31e453e6bda8dfa.png"/>
650) this.width=650; "src=" Https://s2.51cto.com/oss/201711/17/1404edd359866350c3f8ba9253f5c4ea.png "title=" 2.png " alt= "1404edd359866350c3f8ba9253f5c4ea.png"/>
Unblock inheritance to see the effect:
650) this.width=650; "src=" Https://s4.51cto.com/oss/201711/17/959acc4812bf1a8675007fa92b68fd9e.png "title=" 0.png " alt= "959acc4812bf1a8675007fa92b68fd9e.png"/>
Then set the Domain Group Policy (global users) to see the accumulation and conflict situation
650) this.width=650; "src=" Https://s4.51cto.com/oss/201711/17/ddb84819ef0fc72a2d58c4d1965c6f4c.png "title=" 0.png " alt= "Ddb84819ef0fc72a2d58c4d1965c6f4c.png"/>
650) this.width=650; "src=" Https://s4.51cto.com/oss/201711/17/9f5b1a40c482bfdcfe73739273a0e6f1.png "title=" 1.png " alt= "9f5b1a40c482bfdcfe73739273a0e6f1.png"/>
650) this.width=650; "src=" Https://s1.51cto.com/oss/201711/17/5ee0ef521f20d614d225ea742ff03adb.png "title=" 2.png " alt= "5ee0ef521f20d614d225ea742ff03adb.png"/>
you can have the default Domain Group Policy enforce the user AA effective on
650) this.width=650; "src=" Https://s5.51cto.com/oss/201711/17/91edb5adb89c4f865832365d74724f33.png "title=" 0.png " alt= "91edb5adb89c4f865832365d74724f33.png"/>
650) this.width=650; "src=" Https://s5.51cto.com/oss/201711/17/1357aa2e9f9577fafc30a08f1ac3ba32.png "title=" 1.png " alt= "1357aa2e9f9577fafc30a08f1ac3ba32.png"/>
You can apply a filter mode to enable users AA do not apply Default Domain Group Policy
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/5417f83488c6aaf46cc93bc3561c7f82.png "title=" 0.png " alt= "5417f83488c6aaf46cc93bc3561c7f82.png"/>
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/39ddc97a2de3156e06f770a16d584bb4.png "title=" 1.png " alt= "39ddc97a2de3156e06f770a16d584bb4.png"/>
650) this.width=650; "src=" Https://s2.51cto.com/oss/201711/17/29e9833e6b32166c5bc69fe64e6eab0b.png "title=" 2.png " alt= "29e9833e6b32166c5bc69fe64e6eab0b.png"/>
Application software Distribution
650) this.width=650; "src=" Https://s4.51cto.com/oss/201711/17/f5da4e9911d45c651c031afd9cc1683d.png "title=" 0.png " alt= "F5da4e9911d45c651c031afd9cc1683d.png"/>
650) this.width=650; "src=" Https://s4.51cto.com/oss/201711/17/17e03e643954e9c3d2c267dfae0c3ae8.png "title=" 1.png " alt= "17e03e643954e9c3d2c267dfae0c3ae8.png"/>
650) this.width=650; "src=" Https://s5.51cto.com/oss/201711/17/5e0a0746327b5fb7643e264969d81454.png "title=" 2.png " alt= "5e0a0746327b5fb7643e264969d81454.png"/>
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/8f0af2b2278dfac2500675ff1f822e0c.png "title=" 3.png " alt= "8f0af2b2278dfac2500675ff1f822e0c.png"/>
Restart the Client for verification: (Requires Win7 bit)
650) this.width=650; "src=" Https://s1.51cto.com/oss/201711/17/ec1d866872877064a6604ca60011d2b1.png "title=" 4.png " alt= "Ec1d866872877064a6604ca60011d2b1.png"/>
650) this.width=650; "src=" Https://s3.51cto.com/oss/201711/17/d1500344ed85b4c7d0d33a1973351038.png "title=" 5.png " alt= "D1500344ed85b4c7d0d33a1973351038.png"/>
This article is from the "DY" blog, please be sure to keep this source http://guochenyong.blog.51cto.com/11367898/1982883
Windows Server R2 Active Directory Group Policy