Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , ,

Sponsored Links



Applying group policy only to members of a domain local securitygroup

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 07-03-2010
Drazen
 
Posts: n/a
Applying group policy only to members of a domain local securitygroup


So there is domain ABC.local with various OUs and sub-OUs defined.
There is also domain local security group (placed in ABC\Users)
defined whose members are users from various OUs/subOus. If I wanted
to apply group policy only to that securiy group, how would I do that?

I tried to link group policy object at the ABC.local domain level and
then apply security filtering by removing Authenticated users group
and adding domain local security group containing users from various
OUs.
However the policy did not apply to the users. When I linked group
policy object to OUs where users reside, it got applied. How is this
explained?

Regards,
Drazen
Reply With Quote
  #2  
Old 07-03-2010
Meinolf Weber [MVP-DS]
 
Posts: n/a
Re: Applying group policy only to members of a domain local security group

Hello Drazen,

A GPO can only be applied to users or computers, NOT to security groups.
You can use security filtering only if the user accounts/computer accounts
are in the OU where you apply the security filtering.

See also:
http://technet.microsoft.com/en-us/l...88(WS.10).aspx

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> So there is domain ABC.local with various OUs and sub-OUs defined.
> There is also domain local security group (placed in ABC\Users)
> defined whose members are users from various OUs/subOus. If I wanted
> to apply group policy only to that securiy group, how would I do that?
>
> I tried to link group policy object at the ABC.local domain level and
> then apply security filtering by removing Authenticated users group
> and adding domain local security group containing users from various
> OUs.
> However the policy did not apply to the users. When I linked group
> policy object to OUs where users reside, it got applied. How is this
> explained?
> Regards,
> Drazen



Reply With Quote
  #3  
Old 07-03-2010
Drazen
 
Posts: n/a
Re: Applying group policy only to members of a domain local securitygroup


Thanks Meinolf, that clears it.

Regards,
Drazen

On Mar 6, 11:46*pm, Meinolf Weber [MVP-DS] <meiweb@(nospam)gmx.de>
wrote:
> Hello Drazen,
>
> A GPO can only be applied to users or computers, NOT to security groups.
> You can use security filtering only if the user accounts/computer accounts
> are in the OU where you apply the security filtering.
>
> See also:http://technet.microsoft.com/en-us/l...88(WS.10).aspx
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and confers
> no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!!http://www.blakjak.demon.co.uk/mul_crss.htm
>
> > So there is domain ABC.local with various OUs and sub-OUs defined.
> > There is also domain local security group (placed in ABC\Users)
> > defined whose members are users from various OUs/subOus. If I wanted
> > to apply group policy only to that securiy group, how would I do that?

>
> > I tried to link group policy object at the ABC.local domain level and
> > then apply security filtering by removing Authenticated users group
> > and adding domain local security group containing users from various
> > OUs.
> > However the policy did not apply to the users. When I linked group
> > policy object to OUs where users reside, it got applied. How is this
> > explained?
> > Regards,
> > Drazen


Reply With Quote
  #4  
Old 07-03-2010
Meinolf Weber [MVP-DS]
 
Posts: n/a
Re: Applying group policy only to members of a domain local security group

Hello Drazen,

You're welcome.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Thanks Meinolf, that clears it.
>
> Regards,
> Drazen
> On Mar 6, 11:46 pm, Meinolf Weber [MVP-DS] <meiweb@(nospam)gmx.de>
> wrote:
>
>> Hello Drazen,
>>
>> A GPO can only be applied to users or computers, NOT to security
>> groups. You can use security filtering only if the user
>> accounts/computer accounts are in the OU where you apply the security
>> filtering.
>>
>> See
>> also:http://technet.microsoft.com/en-us/l...88(WS.10).aspx
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers
>> no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!!http://www.blakjak.demon.co.uk/mul_crss.htm
>>> So there is domain ABC.local with various OUs and sub-OUs defined.
>>> There is also domain local security group (placed in ABC\Users)
>>> defined whose members are users from various OUs/subOus. If I wanted
>>> to apply group policy only to that securiy group, how would I do
>>> that?
>>>
>>> I tried to link group policy object at the ABC.local domain level
>>> and
>>> then apply security filtering by removing Authenticated users group
>>> and adding domain local security group containing users from various
>>> OUs.
>>> However the policy did not apply to the users. When I linked group
>>> policy object to OUs where users reside, it got applied. How is this
>>> explained?
>>> Regards,
>>> Drazen



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Applying group policy only to members of a domain local securitygroup"
Thread Thread Starter Forum Replies Last Post
using local group policy to override domain group policy inenewbl Active Directory 4 28-09-2011 05:20 AM
Applying Group Policy in AD LDS rajeevrautela Active Directory 1 11-05-2011 06:52 AM
Use group policy to change local administrator password in Domain coady Active Directory 4 29-12-2010 11:20 AM
Group policy still applying even though disable on domain Boe Window 2000 Help 5 02-05-2008 05:50 PM
Override the local Group Policy by domain policy or delete the RSOP gchandrujs via WindowsKB.com Windows Security 0 04-07-2007 09:20 PM


All times are GMT +5.5. The time now is 06:57 PM.