Policy not applied to group of users in OU

X

X-man

I need help with a GP applied to an OU with a group of
users. Here's the scenario: All the user objects are in
the main Users container. I have created OUs with user
groups in them. I have applied a GPO to the OUs with the
user groups in them. However, when I log on as one of the
users in these user groups, the GPO applied to the OU is
not being applied. If I move the individual user objects
into the OU with the user group, the GPO is being applied
(this is confirmed using GPRESULT). Surely it is
possible to apply a GPO to the user group within a OU? I
don't want to place individual user accounts(or
computers) in the OU. Thank you for the help.
 
S

Steven L Umbach

The users or computers need to be in the scope of influence of the GPO and since this
GPO is applied to an OU the users must be in that OU hierarchy. GPO apply to users or
computers NOT groups. Groups however can be used to filter Group Policy. A user/group
needs read and apply permissions in order for the Group Policy to apply. Filtering
is explained in the KB below, but it should be used sparingly. -- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;322176
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top