Default GPO Permissions

  • Section(s): Active Directory , Security
  • Published on Jul 13, 2006.
  • Last Modified on Jul 13, 2006.
  • Last Modified by Chris Sanders.
  • Rated 4.1 out of 5 based on 11 votes.
It is very important to assign appropriate permissions to every GPO you create. Here I list the default permissions given to a new GPO.
I cannot stress enough how important it is to correctly set permissions for the Group Policy Objects you create. In this sense, it is very important that you know what permissions are assigned to a Group Policy Object by default. They are as follows:

Authenticated Users – Read, Apply Group Policy, Special Permissions
Creator Owner – Special Permissions
Domain Administrators – Read, Write, Create All Child Objects, Delete All Child Objects, Special Permissions
Enterprise Administrators – Read, Write, Create All Child Objects, Delete All Child Objects, Special Permissions
Enterprise Domain Controllers – Read, Special Permissions
System – Read, Write, Create All Child Objects, Delete All Child Objects, Special Permissions


It is also important to know that only the Domain Administrators, Enterprise Administrators, and Group Policy Creator Owner groups have permission to create new GPO’s be default. Any user who needs the ability to create GPO’s will need to be added to one of these groups. It is generally best practice to add these users to the Group Policy Creator Owner group so that they have fill administrative permissions over only the GPO’s they create.

***

Chris Sanders is the network administrator for one of the largest public school systems in the state of Kentucky. Chris's specialties include general network administration, windows server 2003, wireless networking, and security. You can view Chris' personal website at www.chrissanders.org.

About Chris Sanders

Chris Sanders is a network security analyst for EWA Government Systems Inc. Chris is the author of the book Practical Packet Analysis as well as several technical articles. His personal website at www.chrissanders.org contains a great deal of information, articles, and guides related to network administration, network security, packet analysis, and general information technology.


Article not looking right or info is missing? Let us know so that we can fix it: .


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowsNetworking.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowsNetworking.com member!

Discuss your network issues with thousands of other network administrators. Click here to join!

Community Area

Log in | Register

Readers' Choice

Which is your preferred network administration tool?