GPO applied to security groups in OU?

K

Karen Rowland

I understand that a GPO assigned to an OU will not be applied to security
groups in that OU; however, I have read that this can be done using security
filters.

I have 3 global security groups in an OU. In the properties for the GPO on
the security tab, I have removed Authorized Users and added the 3 groups
with Allow for Read and Apply Group Policy. However, the GPO is still not
getting applied to users in these groups. I know it isn't the GPO, becuase
prior to configuring security filtering, it would always apply to users in
the OU, just not groups.

What am I missing?

Thanks,

Karen Rowland
(e-mail address removed)
 
O

Oli Restorick [MVP]

Hi there

A GPO will still only apply to machines or users in the OU. The permissions
filtering would enable you to apply a GPO to specific users or computers IN
THAT OU, that are members of the user or group you filtered on.

What I think you're trying to do is to apply a GPO to an OU and hoping to
hit a computer or user whose account is not in that OU, but who is a member
of a security group which does reside in the OU. It doesn't work like that.

Hope this helps

Oli
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top