Filter Group Policy Object Scope by Using Security Groups
Scenario/Problem: You
have a GPO linked to an OU. The OU contains user accounts. You need to
limit the GPO to be applied only to a subset of the user accounts
located in the OU.
|
Solution: Create an AD DS group. Place the user accounts in the AD DS group. Filter the GPO scope by the AD DS group.
To filter group policy scope by using security groups, perform the following steps:
1. | Log on to a domain controller or a member computer that has Windows Server 2008 RSAT installed.
|
2. | Click Start, click Administrative Tools, and then click Group Policy Management.
|
3. | In the console tree, select the Group Policy Objects node.
|
4. | In the details pane, select the GPO on which you want to use group filtering.
|
5. | On the Scope tab, shown in Figure 1, click Add.
|
6. | On
the Select User, Computer, or Group window, type the name of the group
with which you want to filter the GPO scope; then click OK.
|
7. | Select Authenticated Users under the Security Filtering section of the Scope tab, and click Remove.
|
8. | Click OK on the remove delegation privilege confirmation screen, as shown in Figure 2.
|
Disable User Settings in a Group Policy Object
Scenario/Problem: You
have a GPO linked to an OU. The GPO is used to apply computer
configuration. You want to prevent user configuration from being read
during group policy processing.
|
Solution: Disable user settings in a GPO.
To disable user settings in a GPO, perform the following steps:
1. | Log on to a domain controller or a member computer that has Windows Server 2008 RSAT installed.
|
2. | Click Start, click Administrative Tools, and then click Group Policy Management.
|
3. | In the console tree, select the Group Policy Objects node.
|
4. | Right-click
the GPO on which you want to disable user settings, select GPO Status,
and click User Configuration Settings Disabled, as shown in Figure 3.
|
Disable Computer Settings in a Group Policy Object
Scenario/Problem: You
have a GPO linked to an OU. The GPO is used to apply user
configuration. You want to prevent computer configuration from being
read during group policy processing.
|
Solution: Disable computer settings in a GPO.
To disable computer settings in a GPO, perform the following steps:
1. | Log on to a domain controller or a member computer that has Windows Server 2008 RSAT installed.
|
2. | Click Start, click Administrative Tools, and then click Group Policy Management.
|
3. | In the console tree, select the Group Policy Objects node.
|
4. | Right-click
the GPO on which you want to disable computer settings, select GPO
Status, and click Computer Configuration Settings Disabled, as shown in Figure 4.
|