GPO components
An AD domain GPO consists of the following two components:
- GPO Container: This is an AD object and is a metadata store for the GPOs. The Directory Replication Agent (DRA) provides replication between DCs.
- GPO Template: This is a store for a set of files for the GPO. Distributed File System Replication (DFSR) provides replication between DCs.
For a GPO to be applied to a user or a computer, it must be linked to a site, domain, or OU container that contains computer or user objects that require to be affected by the policy; a GPO cannot be applied directly to a group. GPOs provide two groups of configuration settings, one for computers and one for users; there are no configuration settings for groups. The configuration settings nodes in any policy are as follows:
- Computer Configuration: The policies defined in this section will only affect computer objects. These settings are evaluated and applied at computer boot time.
- User Configuration...