This is a 2003 domain...
Main Topics
Browse All TopicsIs there a way to create a GPO that makes the Administrators and the administrators only exempt from all GPO's on the domain? I understand the Software Restrictions Enforcement but that's a bit confusing because it states all users except local administrators... Does that mean only administrators or anyone in the local administrators group of the local machine? If the answer to that is anyone in the local administrators group of the local machine then that does not accomplish what I need. I need for the administrator to be able to logon to any machine regardless of the applied user/machine GPO and be exempt from that GPO. Is there a way to accomplish this????
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
There is no specific group policy that enables you to make admins exempt from all other policies.
You can use security filtering on the GPOs more on that here
http://adisfun.blogspo
NOTE -- read the comments from Rick (great discussion) as I'm going to update that article just for this sort of questions (deny for admins)
Instead of Deny Read and Deny Apply
For the admins just check Deny Apply Group Policy -- continue to let them have the read access.
Thanks
Mike
If a GPO is linked to where your computers are it will only affect machines (assuming computer settings are defined in that GPO)
If you want a computer to not receive the settings you can use security filtering for the computer or more the computer to a different OU that doesn't inherit that GPO (if the GPO is linked at the OU level)
Thanks
Mike
That's what I'm trying to accomplish. I've inherated a mess. All the GPOs are linked to the Domain with user's and groups in the GPO I'm trying to move everything around to the corresponding OU. I'm trying to make sure that my administrators will be able to log into any machine and not have the GPO applied to them. I working with about 600 plus machines.
If the GPO is meant for only users, create a Group of those users ( in the Properties disable computer object),give read and apply policy permission for that group, Administrators only Write/Read permission, and remove Apply policy.
You can aswell Add Admins in a group to Manage the Group policy
Authenticated users need to removed from Apply policy
As you told , the state is messed up, best option is Security Filtering, See the MS Articles explain on the same
http://technet.microsoft.c
Business Accounts
Answer for Membership
by: ram_keralaPosted on 2009-09-22 at 07:50:47ID: 25393457
In the security tab of Group policy object, select apply policy permission only for the group which is indent for. Always creating group and applying policy is a best practice.
Remember to remove apply policy , authenticated users , otherwise all users - regardless admin, policy will get applied