To pre-stage GPOs for use with DirectAccess, follow these steps:
- In your Domain Controller, launch the Group Policy Management Console.
- Navigate to Forest | Domains | Your Domain Name. There should be a listing here called Group Policy Objects. Right-click on that and choose New.
- Name your new GPO something like DirectAccess Server Settings.
- Click on the new DirectAccess Server Settings GPO and it should open up automatically to the Scope tab. We need to adjust the Security Filtering section so that this GPO only applies to our DirectAccess server. This is a critical step for each GPO to ensure the settings that are going to be placed here do not get applied to the wrong computers.
- Remove Authenticated Users that are prepopulated ...