Applying GPOs only to certain users on certain computers

Maybe this is a simple question, maybe not.  

How can I go about creating and implementing a GPO such that it employs user policy, but only applies the user policy on certain computers.

i.e.
I have User1 and User2 and Workstation1 and Workstation2.  I want to create a GPO that causes My Documents folder redirection (a User configuration for a GPO) for User1 and User2, but I ONLY want this GPO applied to Workstation1.  On Workstation2, both users should log in and access the local My Documents folder.

Thanks.
LVL 1
JeffN825Asked:
Who is Participating?
 
Debsyl99Connect With a Mentor Commented:
That's right - unless you apply loopback policy on that gpo - did you read my link?
Contained in the link:
"""Group Policy applies to the user or computer in a manner that depends on where both the user and the computer objects are located in Active Directory. However, in some cases, users may need policy applied to them based on the location of the computer object alone. ""

You can use the Group Policy loopback feature to apply Group Policy Objects (GPOs) that depend only on which computer the user logs on to."""
0
 
Debsyl99Commented:
Hi
You should be able to use loopback poilcy processing to achieve what you want. You'll need to put the Workstation in its own OU, set up the policies on that OU that you require, and enable loopback policy. This should then ensure that the policy is only applied to users of that workstation,
Loopback Processing of Group Policy
http://support.microsoft.com/default.aspx?scid=kb;EN-US;231287

Deb :))
0
 
ziwez0Commented:
Hi Jeff,

right i came across this problem a few months back and to be honest i still have not got round to finishing it.

you cant apply GPO to certain users, but you can apply them to security groups, which your users can be members off, or you can apply GPO locally on the computers.

Do you know how to go about setting up GPO?,
if you need help i will post a quick step by step guide...

-
David

0
Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

 
adamdrayerCommented:
You can create custom OUs, and put computers, workstations, and groups into them.  Then you can create GPOs at the OU level and everything  within that OU will process the Group Policy by default.  You can then make further adjustments by modifying the "Apply Group Policy" premission on the security tab of the GPO.

When implementing Group Policies on the OU level, you must start concerning yourself with inheiretance.
0
 
JeffN825Author Commented:
I understand well the ideas involved in GPO inheritance.  I also know perfectly well how to set up GPOs and apply and enforce them.

There is already a fairly sophisticated set of heirarchical OUs and GPOs that I have set up.

My question, however, is how to apply User group policy, but only on a specific workstation.  My understanding is that if I set that a specific Group Policy in "Apply Group Policy" should apply only to a certain computer, that will NOT affect whether USER policy in that GPO applies on that computer.

Maybe I am wrong, if so, please let me know.
0
 
JeffN825Author Commented:
Deb, sorry, I missed your post up top until just now.  You hit the answer right on the head.
0
 
Debsyl99Commented:
No probs! Just glad to help :))

Best wishes,

Deb :))
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.