A warning on cross-domain policy linking

In our test lab, we have no plans to grow into a large enough environment where there would be multiple domains being hosted, but this is certainly a scenario that you could stumble into when doing IT work for a business. When multiple domains exist inside Active Directory, there is the opportunity to link GPOs from one domain to OUs in a different domain.

Don't do it!

This is called cross-domain policy linking and is generally a bad practice. It is very easy to lose track of these links, or for an administrator in one domain to mistakenly interfere with settings that another administrator in another domain put into place. Furthermore, you may have admin access to your own domain but not in other ...

Get Mastering Windows Group Policy now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.