Applying GPOs

  • Thread starter Thread starter Tony
  • Start date Start date
T

Tony

I want to be able to apply GPO to a user that will log on from any machine.
I do not have control or I cannot link a GPO for users. I can do it for OUs
for computers and groups.

What do I do to make sure the user gets the GPO everytime if he/she logs in
from different machines?
 
If you can place all the users for whom you want the GPO to work in a group,
you can then create a GPO object for the users' OU and only give that group
apply rights.
 
I thought GPOs dont apply to groups. only computers or users. I tried it it
does not work.
"Gabe Knuth" <[email protected] (not for legit emails, use my first name @
gabeknuth.com for those)> wrote in message
 
You are correct. GPOs apply to users and/or computers only. You can filter
the application of the GPO based on group membership.
The users must be in the OU or a sub OU where you link the group policy.
If the users are in the default "users" container, and you cannot move them,
then the only way to apply GPO to the user is to link it to the domain.
Then user security filtering to specifiy the desired users or groups it
should apply to.
 
When you mean "link it to the domain" Do you mean apply the GPO at the
Domain (root) level? I do not have rights to apply GPOs at the domain level
either.

Thanks
 
Then you will have to get the permission to move the user object into an OU
that you do control.
Then you can link a GPO to the OU so it will apply to the user.
 
Back
Top