What Are The Two Different Types Of Gpo Filtering?ã¢â‚¬â€¹
question
gpo security filter
How-do-you-do,
I have a question regarding gpo that is existence practical to an OU.
I have an OU that users are in it, this OU has a sub OU that users PCs are in information technology.
We have a Policy that linked to the Root OU and to the sub OU. This policy has both user and computer configuration. and Policy is practical to a security group called goup1, and users and computers in toor OU and sub OU are both member group1.Policy appied and works.
Now I accept created a 2nd policy that has some dissimilar settings then the first policy. This new policy it besides have user and computer configuration and applied to a new security grouping, group2
My question,
Can I link the new policy to the same root and sub OU, and apply group2 to filter the new policy and move the users and computers that need this new policy from the first security group? I dont desire to create a new OU for this policy.
The users that become member of the group2 dont need the any of the first policy settings.
windows-grouping-policy
Hello @ShahinMortazave-1426,
Give thanks you lot for posting here.
Here are the answers for your references.
Co-ordinate to the description, we want to filter the new policy to group2 and the users that go fellow member of the group2 don't demand the any of the first policy settings.
I did the following experiments in the lab and then that I can provide more than intuitive suggestions.
-
I created two new groups in the domain, named 0 and 2. There is an OU named Text in the domain, and at that place is a subOU, and there is a computer in the sub-OU. I added the computers to the ii groups. Similarly, the user named text1 in Text is added to two groups, equally shown beneath.
-
I configured ii different GPOs for Text, Policy1 and Policy2, and linked the two GPOs to the sub-OU, added group 0 to the Security Filtering of Policy1, and also added group2 to the Security Filtering of Policy2.
-
In the exported gpresult, we tin can conspicuously run into that GPO takes effect and does not affect each other.
-
If yous only desire Policy2 to have outcome, you tin choose to disable Policy1, as shown below, merely Policy2 is left to take event.
Promise the information higher up is helpful. And look forward to your update of this upshot. If annihilation is unclear, please feel free to let us know.
All-time Regards,
Stephanie Yu
============================================
If the Reply is helpful, please click "Accept Reply" and upvote it.
Note: Please follow the steps in our documentation to enable email notifications if y'all want to receive the related e-mail notification for this thread.
Hi Stephanie,
Thanks for your detailed answer,
What we want to do is to eventually move all of the users and computers from policy1 to the policy 2. But we cannot exercise this at once.
Policy1 and policy2 both take the same setting, except policy1 has folder redirection to a network share and policy 2 has folder redirection to onedrive. becuase the binder redirection to network share and folder redirection to onedrive cannot exist in the same policy we did create copy of the Policy1 and called it Policy2 and removed the folder redirection to network and added the folder redirection to onedrive.
At present we volition link the Policy2 to the same OU and subOU as Policy1 and filter them accordingly and move users in groups of 10 from security group of policy1 and add together them to the security group of Policy2.
This would allow users in Policy1 be unaffected and users in Policy2 should get the settings of the Policy2.
Thanks
Hi Stephanie,
Cheers for your respond,
in the test surroundings I did non came across any outcome, users and computers in the aforementioned OU and sub OU did recieved the settings only from a Policy that they were member of policy's security group.
Users and computers that recieved the settings of the Policy2 thier binder redirection is to the OneDrive.
The simply issue that I came accross is when user is removed from first gpo and added to the 2d gpo and subsequently this user login to his/her PC the login procedure have a long fourth dimension, but afterward that the next login goes as information technology should.
Hi,
I am happy to receive the news that the GPO is working properly.
Because folder redirection is a user configuration, there will be a certain waiting fourth dimension to update the GPO when logging in to the figurer as a user to employ a new policy. The normal login time will be restored next time you log in, and yous won't expect likewise long. This is because the GPO has been applied, and the experiment I did will exist the same. This is normal. Don't worry nearly that.
Thanks and then much for your time and back up.
If the Answer is helpful, please click "Have Answer" and upvote it.
Best regards,
Stephanie Yu
ane Vote 1 ·
question details
2 people are following this question.
Related Questions
What Are The Two Different Types Of Gpo Filtering?ã¢â‚¬â€¹,
Source: https://docs.microsoft.com/answers/questions/88123/gpo-security-filter.html
Posted by: nishimuranaturawrove.blogspot.com
Hullo,
Thank you for your update. According to your latest description, GPO works as you wish. You can move users and computers from grouping 1 to group two. Are in that location any bug after doing the in a higher place operations?
If anything is unclear, please experience complimentary to let usa know.
Thank you lot so much for your time and support.
If the Answer is helpful, please click "Accept Answer" and upvote it.
Best regards,
Stephanie Yu
0 Votes 0 ·