Software Installation GPO

  • Thread starter Thread starter Joe
  • Start date Start date
J

Joe

Hi,

Simple question time....

I would like to know how I can apply Software
Installation to individual computers rather than the
whole Computers OU.

My stumbling point is that a computer can only be
contained within one OU.

Thanks,
Joe
 
Take a look at Security Groups being used as a filter. When you create a
GPO and link it to an OU, by default the 'Authenticated Users' group is used
and given the READ and APPLY POLICY rights. Simply remove the
'Authenticated Users' group, create your own security group, populate it
with the computer account objects that need to have this GPO and give that
security group the READ and APPLY POLICY rights.

This way, you can keep all of your computer account objects in one OU and
apply this GPO to only those computer account objects that need it.

However, I will say that this is typically not a very good idea when someone
is first learning GPOs as it can be a bit more difficult to troubleshoot six
months down the road.

Is there a reason that all of your computer accounts M U S T be in the one
OU?

HTH,

Cary
 
Thanks Cary,

That works a treat.

Sorry, I didn't mean that the computers were in one OU,
just that an individual computer can reside in only one
OU.

At the mo all our computers are in OUs grouped by OS. We
still have a mix desktops and that seems to work well for
us.

Cheers,
Joe
 
Glad to help.

Cary

joe said:
Thanks Cary,

That works a treat.

Sorry, I didn't mean that the computers were in one OU,
just that an individual computer can reside in only one
OU.

At the mo all our computers are in OUs grouped by OS. We
still have a mix desktops and that seems to work well for
us.

Cheers,
Joe
 
Back
Top