You configure a Group Policy Object for the Marketing organizational unit (OU) to prevent users from accessing My Network Places

admin2009-05-19  42

问题 You configure a Group Policy Object for the Marketing organizational unit (OU) to prevent users from accessing My Network Places and from running System in Control Panel. You want the Managers domain local group to be able to access My Network Places, but you still want to prevent them from running System in Control Panel.

What should you do?

选项 A、Add the managers group to the access control list of the GPO.
Disable the permission of the managers group to read and apply the group policy.
B、Add the managers group to the access control list of the GPO.
Deny the permission of the managers group to read and apply the group policy.
C、Create a second GPO in the OU.
Add the managers group to the access control list.
Allow the managers group to apply the group policy.
Deny the authenticated users group permission to read and apply group policy. Configure the new GPO to deny the ability to run System in Control Panel.
Give the original GPO a higher priority than the new GPO.
D、Create a second GPO in the OU.
Add the managers group to the access control list.
Allow the managers group to read and apply the group policy.
Disable the permission of the authenticated user group to read and apply the group policy.
Configure the new GPO to allow access to My Network Places.
Give the new GPO a higher priority than the original GPO.

答案D

解析 Explanation: In this scenario we need to create a second GPO and apply it only to the Managers. We must allow access to My Network Places in the new GPO. Then we give the GPO higher priority than the original one.

Incorrect answers:
A: We still require the original GPO to apply to the managers, as we want to prevent them from running System in Control Panel. Therefore we should not disable the permission of the managers group to read and apply the Group Policy, as this will result in the GPO not being applied to the Managers.

B: We still require the original GPO to apply to the managers, as we want to prevent them from running System in Control Panel. Therefore we should not deny the permission of the managers group to read and apply the Group Policy, as this will result in the GPO not being applied to the Managers.

C: We need to allow the Managers access to My Network Places. That must be configured in the second GPO.
转载请注明原文地址:https://kaotiyun.com/show/2rhZ777K
0

最新回复(0)