group policy for multiple groups

Posted on 2004-04-22
Medium Priority
Last Modified: 2010-04-13
I have a user that is a member of two different user groups. How do I get two different group policies from two different OU's to apply to her.
Question by:bluespringsit
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +2

Accepted Solution

Drizzt420 earned 375 total points
ID: 10892584
Can't you just link the GPO or recreate a similiar one in the users home OU? if you do not want the GPO to affect anyone in the OU but her, just edit the security settings of the GPO by going to its properties and remove all access control list entries and then add just her user account.

Author Comment

ID: 10892760
Their Home OU? I believe the user object can only belong to one OU. I'd hate to have to go into every OU that has a user that belongs to more then one User Group and create another group policy just for them. Theres got to be a bettter way to do it. (i hope)

Expert Comment

ID: 10892866
GPO's apply to user objects, not to groups.
every GPO that you need to apply to a user needs to be set above that user.
the only alternative to this is if you have specific machines where you want these users to have different settings

based on your requirements, it sounds like you have GPO's that apply to certain groups (not users)
apply all GPO's at the top level of the domain, and then restrict the ability to apply that GPO to the appropriate group
Then everyone part of that group (no matter what ou they are in) will apply the  policy, and all users that are not in that group will not apply it.

P.S.  I highly recommend GPMC for policy management.  Very helpful additions to the interface
Get real performance insights from real users

Key features:
- Total Pages Views and Load times
- Top Pages Viewed and Load Times
- Real Time Site Page Build Performance
- Users’ Browser and Platform Performance
- Geographic User Breakdown
- And more


Expert Comment

ID: 10893913
The group policies can only be applied to the OU or container that the user resides in. You can't apply GPO's to groups. Her group memberships should not effect what policies are applied to the Container or OU where her user account resides.

What policy wise does she need that is different in the 2 policies. The easiest solution to this may be to just move her User object to the OU that has a less restrictive policy.
LVL 15

Expert Comment

ID: 10895655
I believe it can be done with Nesting.

You can only assign GPOs to OUs and Sub OUs only.  If the user is in one group under one OU, then create another group and add the user to that group and have that group be nested in the appropriate group in the other OU.  I know you can do this across domains (so it should work across OUs).

Expert Comment

ID: 10902496
were you able to try applying the policies with security filtering  bluespringsit?
do you need more info on this?

Author Comment

ID: 10953236
Sorry it took so long to get back. I understand now how to nest the OU's to utilize the security settings, but I still have an issue. I am organizing active directory into OUs named after the departments. This particular lady is actually part of two departments, so she will need two different departmental drives mapped. What would you do in this case? I also have a set of internet explorer favorites that are set for one of the departments. Since you can only put a user object in one OU, and if those OU's are not nested, what would you do?

Expert Comment

ID: 10959577
(summary of comments above)
create a group for each department
create a GPO for each department
set each GPO to only apply to members of the department group
apply all GPO's at the top level of the domain

only GPO's where the user is part of the appropriate group will apply

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question