Applying GPOs only to certain users on certain computers

Posted on 2004-10-12
Medium Priority
Last Modified: 2011-09-20
Maybe this is a simple question, maybe not.  

How can I go about creating and implementing a GPO such that it employs user policy, but only applies the user policy on certain computers.

I have User1 and User2 and Workstation1 and Workstation2.  I want to create a GPO that causes My Documents folder redirection (a User configuration for a GPO) for User1 and User2, but I ONLY want this GPO applied to Workstation1.  On Workstation2, both users should log in and access the local My Documents folder.

Question by:JeffN825
LVL 20

Expert Comment

ID: 12295957
You should be able to use loopback poilcy processing to achieve what you want. You'll need to put the Workstation in its own OU, set up the policies on that OU that you require, and enable loopback policy. This should then ensure that the policy is only applied to users of that workstation,
Loopback Processing of Group Policy

Deb :))

Expert Comment

ID: 12297344
Hi Jeff,

right i came across this problem a few months back and to be honest i still have not got round to finishing it.

you cant apply GPO to certain users, but you can apply them to security groups, which your users can be members off, or you can apply GPO locally on the computers.

Do you know how to go about setting up GPO?,
if you need help i will post a quick step by step guide...


LVL 15

Expert Comment

ID: 12299903
You can create custom OUs, and put computers, workstations, and groups into them.  Then you can create GPOs at the OU level and everything  within that OU will process the Group Policy by default.  You can then make further adjustments by modifying the "Apply Group Policy" premission on the security tab of the GPO.

When implementing Group Policies on the OU level, you must start concerning yourself with inheiretance.
Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.


Author Comment

ID: 12301371
I understand well the ideas involved in GPO inheritance.  I also know perfectly well how to set up GPOs and apply and enforce them.

There is already a fairly sophisticated set of heirarchical OUs and GPOs that I have set up.

My question, however, is how to apply User group policy, but only on a specific workstation.  My understanding is that if I set that a specific Group Policy in "Apply Group Policy" should apply only to a certain computer, that will NOT affect whether USER policy in that GPO applies on that computer.

Maybe I am wrong, if so, please let me know.
LVL 20

Accepted Solution

Debsyl99 earned 500 total points
ID: 12301443
That's right - unless you apply loopback policy on that gpo - did you read my link?
Contained in the link:
"""Group Policy applies to the user or computer in a manner that depends on where both the user and the computer objects are located in Active Directory. However, in some cases, users may need policy applied to them based on the location of the computer object alone. ""

You can use the Group Policy loopback feature to apply Group Policy Objects (GPOs) that depend only on which computer the user logs on to."""

Author Comment

ID: 12301508
Deb, sorry, I missed your post up top until just now.  You hit the answer right on the head.
LVL 20

Expert Comment

ID: 12301884
No probs! Just glad to help :))

Best wishes,

Deb :))

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Downtime reduced, data recovered by utilizing an Experts Exchange Business Account Challenge The United States Marine Corps employs more than 200,000 active-duty Marines with operations in four continents, all requiring complex networking system…
This article is in response to a question (http://www.experts-exchange.com/Networking/Network_Management/Network_Analysis/Q_28230497.html) here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
In response to a need for security and privacy, and to continue fostering an environment members can turn to for support, solutions, and education, Experts Exchange has created anonymous question capabilities. This new feature is available to our Pr…

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question