Check what policies are being applied to a particular security group in ADUC

active-directorygroup-policy

I've been given the task to clean up ADUC/Group Policy.

Quite daunting due to the perplexing manner it was all put together. It appears to have been put together with a "try this, didn't work, don't worry about deleting it, just try this, rinse/repeat" method.

Moving on. I've got users organized the way I'd like it. But before I start removing/adding objects to the security groups I'd like to see what policies they are inheriting. I'm doing this with hope there is justification for some of this crud I'm seeing.

In other words: How can I tell what policies are being applied to a particular security group?

Best Answer

  • What you want is the GPMC - the Group Policy Management Console. It allows you to run reports on users & computers to see what the "RSOP" or Resultant Set of Policies is.

  • Related Question