I thought that if you added a user/group under the scope tab of the GPMC it would set the 'read (from security filtering)' right by default (which should include 'read' and 'apply group policy'). Were you adding the user/group in the delegation tab? By the way, I just figured out that you can get to the same detailed security listing (as you get editing the GPO) by clicking the advanced button on the delegation tab in the GPMC. Tony "Jason Benway" <benwayj@xxxxxxxx> Sent by: thin-bounce@xxxxxxxxxxxxx 02/27/2007 12:57 PM Please respond to thin@xxxxxxxxxxxxx To <thin@xxxxxxxxxxxxx> cc Subject [THIN] Re: GPO's using loop back I used a computer that didn't have the GPMC and checked the security on the GPO and I have a checkbox for apply group policy. Checked it, did a gpupdate and its working now. Thank you very much. I wonder where the option of "apply group policy" is in the GPMC jb From: thin-bounce@xxxxxxxxxxxxx [mailto:thin-bounce@xxxxxxxxxxxxx] On Behalf Of Jason Benway Sent: Tuesday, February 27, 2007 12:51 PM To: thin@xxxxxxxxxxxxx Subject: [THIN] Re: GPO's using loop back using the GPMC my only options seem to be read edit settings edit settings,delete, modify security jb From: thin-bounce@xxxxxxxxxxxxx [mailto:thin-bounce@xxxxxxxxxxxxx] On Behalf Of Anthony_Baldwin@xxxxxxxxx Sent: Tuesday, February 27, 2007 12:01 PM To: thin@xxxxxxxxxxxxx Subject: [THIN] Re: GPO's using loop back Jason, Did you give the group and/or test user the "Apply group policy" right also? Tony "Jason Benway" <benwayj@xxxxxxxx> Sent by: thin-bounce@xxxxxxxxxxxxx 02/27/2007 11:12 AM Please respond to thin@xxxxxxxxxxxxx To <thin@xxxxxxxxxxxxx> cc Subject [THIN] GPO's using loop back I'm running my citrix server in loop back merged mode. I have the IE home page setup in my main GPO for citrix. But now I'm trying to add another GPO in loop back merge so users from another domain that log in have a differen home page. On the new GPO I removed authenicated users and add jsjdist\domain users with read access. But when I run gpresult I get: jsjdist Intranet Site Filtering: Denied (Security) I even directly added a test user with read access to the policy and get the same thing. The servers have been rebooted and gpupdate has been ran. I created the policy a week ago, so I doubt its any replication type issue. Please help. Thanks,jb SBC SITES ONLY GOOGLE SEARCH: http://www.F1U.com ************************************************ For Archives, RSS, to Unsubscribe, Subscribe or set Digest or Vacation mode use the below link: //www.freelists.org/list/thin ************************************************