I was looking at the GPOs because new surface pro 3 with windows 10 are not having the GPOs applied. While investigating this problem I came across the fact that the Default Domain Controllers Policy is not link enabled or enforced. See below
The environment was upgraded from server 2003 to server 2012 R2 last year. I do not know how this happened but I can not believe that it is correct. I am inclined to just enable the link but I do wonder if there will be any bad or disastrous effects.
I would appreciate and comments or insights.
Is there any reason why the GPO should not be enabled?
Am I missing something?
Thanks for any comments
Paul