Assigning GP's to OU's

G

Guest

I want to be able to assign a Group Policy to an OU, but prefer to put a
Security Group into that OU rather than all of the individual users. Can
Group Policies be assigned that way or does the user object need to be within
the OU to be assigned the policy?
 
M

Mark Renoden [MSFT]

Hi

GPO's only apply to user or computer objects. You can't apply them based on
the OU membership of groups. You can however filter the application of
these GPO's to users by changing the security on the GPO to deny "Apply
Group Policy". For example, you may have a domain level policy that you'd
like to have applying to all users except Domain Admins. In this case you'd
set security so that Domain Admins are denied "Apply Group Policy".

Kind regards
--
Mark Renoden [MSFT]
Windows Platform Support Team
Email: (e-mail address removed)

Please note you'll need to strip ".online" from my email address to email
me; I'll post a response back to the group.

This posting is provided "AS IS" with no warranties, and confers no rights.
 
O

Oli Restorick [MVP]

Another way to filter with security groups is to deselect the default "Apply
Group Policy" for authenticated users, add the group you actually want to
apply it to and tick the box for this group.

Oli



Mark Renoden said:
Hi

GPO's only apply to user or computer objects. You can't apply them based
on the OU membership of groups. You can however filter the application of
these GPO's to users by changing the security on the GPO to deny "Apply
Group Policy". For example, you may have a domain level policy that you'd
like to have applying to all users except Domain Admins. In this case
you'd set security so that Domain Admins are denied "Apply Group Policy".

Kind regards
--
Mark Renoden [MSFT]
Windows Platform Support Team
Email: (e-mail address removed)

Please note you'll need to strip ".online" from my email address to email
me; I'll post a response back to the group.

This posting is provided "AS IS" with no warranties, and confers no
rights.

kevdmcse said:
I want to be able to assign a Group Policy to an OU, but prefer to put a
Security Group into that OU rather than all of the individual users. Can
Group Policies be assigned that way or does the user object need to be
within
the OU to be assigned the policy?
 
G

Guest

I was afraid that would be the answer. I have a domain with hundreds of users
and I wanted to organize them into seperate OU's based on Job function But
than some users might need to have a policy applied that is from a different
OU. It just makes it a little more complicated than it would be if you could
assign policy at th group level.

Oli Restorick said:
Another way to filter with security groups is to deselect the default "Apply
Group Policy" for authenticated users, add the group you actually want to
apply it to and tick the box for this group.

Oli



Mark Renoden said:
Hi

GPO's only apply to user or computer objects. You can't apply them based
on the OU membership of groups. You can however filter the application of
these GPO's to users by changing the security on the GPO to deny "Apply
Group Policy". For example, you may have a domain level policy that you'd
like to have applying to all users except Domain Admins. In this case
you'd set security so that Domain Admins are denied "Apply Group Policy".

Kind regards
--
Mark Renoden [MSFT]
Windows Platform Support Team
Email: (e-mail address removed)

Please note you'll need to strip ".online" from my email address to email
me; I'll post a response back to the group.

This posting is provided "AS IS" with no warranties, and confers no
rights.

kevdmcse said:
I want to be able to assign a Group Policy to an OU, but prefer to put a
Security Group into that OU rather than all of the individual users. Can
Group Policies be assigned that way or does the user object need to be
within
the OU to be assigned the policy?
 
O

Oli Restorick [MVP]

That shouldn't be a problem. If you use filtering on security groups and
link the GPO as high up in the OU structure as it needs to be to affect all
the users, it should be fine. You can also link the GPO to multiple OUs
(although this is a bit messy). In this case, the security filtering
applies to the actual GPO and not to each individual link.

Regards

Oli


kevdmcse said:
I was afraid that would be the answer. I have a domain with hundreds of
users
and I wanted to organize them into seperate OU's based on Job function But
than some users might need to have a policy applied that is from a
different
OU. It just makes it a little more complicated than it would be if you
could
assign policy at th group level.

Oli Restorick said:
Another way to filter with security groups is to deselect the default
"Apply
Group Policy" for authenticated users, add the group you actually want to
apply it to and tick the box for this group.

Oli



Mark Renoden said:
Hi

GPO's only apply to user or computer objects. You can't apply them
based
on the OU membership of groups. You can however filter the application
of
these GPO's to users by changing the security on the GPO to deny "Apply
Group Policy". For example, you may have a domain level policy that
you'd
like to have applying to all users except Domain Admins. In this case
you'd set security so that Domain Admins are denied "Apply Group
Policy".

Kind regards
--
Mark Renoden [MSFT]
Windows Platform Support Team
Email: (e-mail address removed)

Please note you'll need to strip ".online" from my email address to
email
me; I'll post a response back to the group.

This posting is provided "AS IS" with no warranties, and confers no
rights.

I want to be able to assign a Group Policy to an OU, but prefer to put
a
Security Group into that OU rather than all of the individual users.
Can
Group Policies be assigned that way or does the user object need to be
within
the OU to be assigned the policy?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top