Consider the following scenario:
- In a Windows Server 2008 domain, you apply a “Restrict users to the explicitly permitted list of snap-ins” setting in a Group Policy object (GPO) to restrict users’ access to snap-ins.
- You allow access to the Group Policy Management snap-in and to the Group Policy Management Editor snap-in.
- You allow access to Administrative Templates (Computers) and to Administrative Templates (Users) in Group Policy Management or in Group Policy Management Editor.
- You link this GPO to an Organization Unit (OU) so that the users in this OU can apply the policy and be able to edit the Administrative Templates settings for the GPO.
When you log on by using an account in the OU to manage or to edit the Administrative Templates in Group Policy Management Editor, the nodes for Administrative Templates: Policy definitions (ADMX files) retrieved from the local machine are not displayed. Therefore, you cannot edit the Administrative Templates.