04 Feb

After MS16-072 is installed, user group policies are retrieved by using the machines security context.The policy rules are specified in JSON format and the file is called .The syntax and format of this file is discussed in the Configuration Reference.If it is commonplace for multiple users to be modifying the same set of data, you should consider implementing some form of concurrency control.There are two flavors of concurrency control: optimistic and pessimistic.

If you have a security filtered group policy that are applied to users AND you have also removed "Authenticated Users" group from the GPO then this GPO will no longer apply to the user.To workaround this problem you can either remove the patch or add "read" permissions to the "Authenticated Users" group back to the GPO.This is a PSA for all Group Policy administrator about MS16-072 that was release yesterday.This patch fixed a man in the middle attack using Group Policy Update however it appears that it has also changed the behavior that Group Policy is applied.