3.2.1.3 Policy Source Mode

Policy Source Mode determines the policy sources used by the client to compute the Filtered GPO list (section 3.2.1.5), computed on the client by searching on the policy source's hierarchy in Active Directory to identify the associated set of GPOs.

Policy Source Mode is assigned one of the following values on the client. The client MUST choose policy sources as described for each Policy Source Mode:

Normal mode: The Filtered GPO list MUST be computed using the policy source of the policy target account.

Loopback replace mode: The Filtered GPO list MUST be computed using the policy source of the computer account and applied to the impersonated user.

Loopback merge mode: The Filtered GPO list MUST be computed using two policy sources: the one for the computer account and the one for the policy target account. The GPO list obtained for the computer is appended to the GPO list for the user, and the merged list is applied to the impersonated user. The GPO list for the computer is applied later and therefore has precedence if it conflicts with settings in the user's list.

The Policy Source Mode computation is as specified in section 3.2.5.1.