filtering specific computers from policy

I

Ilya

Hi all,

I have a lot of sites and several domains. It is purely
Windows 2000 environment.

I am going to set up Group Policy at site level. It will
manage site-related software installation, drive mapping,
and other site-related options.

I don't want to make geographically based OUs, because
it's easer to use natural existing object like site.

I need to exclude servers from computer policy part of
site GPO. I think that I can do it by placing all servers
in security group and use GPO's permissions to denying
this group from apply policy.

Is this solution correct? I've searched the Internet but
could not manage to find if someone did the same thing.

Thank you,
Ilya.
 
S

Steven L Umbach

I have done that once on a test OU to deny computer policy to a computer by the
computer name and it worked as shown by Gpresult so it may work for you but be sure
to test it out. Computers by default get permissions to a GPO because they are
members of the authenticated users group. --- Steve
 
G

Guest

Thank you. It works well already. But it seems strange
that nobody or few admins use it... Sites are so natural
for using for location-related policies!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top