Apply GP to Groups ONLY

  • Thread starter Thread starter Jason
  • Start date Start date
J

Jason

Is there a way to apply a group policy to a group only?
How do I do this? I am trying to setup a schema in which
I can apply policies to users in different groups in
different locations on different machines depending upon
group membership in the same domain. For example,

Joe belongs to the Billing Group in the Chichago OU and
has explorer access privlages to any computer in that OU.
Joe also also belongs to the Safety Group in the Boston
OU, he should NOT have access to explorer on any of thses
computers in that OU. Mary belongs to the Billing group
in the Boston OU and should have access to explorer for
this OU. Each of these OU's are part of the same domain.
Both Mary and Joe need to have differnt access privlages
to the same machines depending upon group membership in
the same domain. In other words, each user can belong to
multiple groups and the group dictates the policy applied
when the user logs in.

Any help provided would be greatly appreciated. Thank you.
 
You can't assign a GPO to a group, only to security principals as Users and
Computers. But you can use groups to filter the GPO, you do this by setting
permission on the GPO itself. In order to see the Security tab in the GPO
properties dialog you must enable Advance view in the MMC.
In order for a GPO to affect an object it must have both Read and Apply
permissions set.

Regards,
/Jimmy
 
Back
Top