[Samba] Is Server-side GPO Configuration possible? (for logon script)
mmuehlfeld at samba.org
Fri Feb 27 12:16:08 MST 2015
Am 27.02.2015 um 20:11 schrieb John:
>> Should the logon script be part of the Default Domain policy? This one
>> always has the same GUID (31B2F340-016D-11D2-945F-00C04FB984F9). You can
>> configure your stuff and then copy the content from one DC to a new one.
>> But reset the ACLs afterwards!
> It is that GUID indeed. I am not sure how I would copy the content from
> the DC, however.
Tar the sysvol content below the domain directory and ship it with your
script. After the provision your script unpacks it and resets the ACLs.
If you don't change the ACLs on the Default Domain Policy, there's
nothing stored inside the AD, if I'm right.
More information about the samba