You need to ensure that the users from the Engineering global group are able to access the Run commandon the Start menu

Your network consists of a single Active Directory domain. The relevant portion of the Active Directory domain
is configured as shown in the following diagram.

The Staff organizational unit (OU) contains all user accounts except for the managers’ user accounts.
The Managers OU contains the managers’ user accounts and the following global groups:
Sales
Finance
Engineering
You create a new Group Policy object (GPO) named GPO1, and then link it to the Employees OU.
Users from the Engineering global group report thatthey are unable to access the Run command on the Start
menu. You discover that the GPO1 settings are causing the issue.
You need to ensure that the users from the Engineering global group are able to access the Run commandon
the Start menu.
What should you do?

Your network consists of a single Active Directory domain. The relevant portion of the Active Directory domain
is configured as shown in the following diagram.

The Staff organizational unit (OU) contains all user accounts except for the managers’ user accounts.
The Managers OU contains the managers’ user accounts and the following global groups:
Sales
Finance
Engineering
You create a new Group Policy object (GPO) named GPO1, and then link it to the Employees OU.
Users from the Engineering global group report thatthey are unable to access the Run command on the Start
menu. You discover that the GPO1 settings are causing the issue.
You need to ensure that the users from the Engineering global group are able to access the Run commandon
the Start menu.
What should you do?

A.
Configure GPO1 to use the Enforce Policy option.

B.
Configure Block Inheritance on the Managers OU.

C.
Configure Group Policy filtering on GPO1 for the Engineering global group.

D.
Create a new child OU named Engineering under theEmployees OU. Move the Engineering global group to
the new Engineering child OU.

Explanation:
GROUP POLICY & SECURITY FILTERING
** Don’t simply set Security Filtering in the scopetab, or the specified group APPLIESthe GPO.
You should define your excluded group by adding it (e.g. Engineering group) in the Delegation tab. Andthen
modify its permission to “Deny” “Apply group policy”.
http://technet.microsoft.com/en-us/library/cc752992.aspx



Leave a Reply 0

Your email address will not be published. Required fields are marked *