Link to home
Start Free TrialLog in
Avatar of shanna1017
shanna1017

asked on

Using a security group to deny access to default domain policy

I have automatic updates configured in our default domain policy and i'd like to exclude our production servers from it.  I set up a security group and added all the computer accounts for the servers I want excluded.  Then I added that security group to the group policy and checked deny apply policy.  When I doa gpupdate and gpresult it still shows that it's applying the default domain policy.  on the other hand, if I add just a single machine account to the ACL of the default domain policy and check the deny apply group policy it works as expected.  when I run gpresult it shows that it's been blocked by the ACL.  

Why won't this work with a security group containing the machine accounts?
ASKER CERTIFIED SOLUTION
Avatar of jss1199
jss1199

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of shanna1017
shanna1017

ASKER

I'm not trying to apply a group policy to a security group, I'm trying to filter based on a security group.  I thought that was allowed.  

I will give your suggestion a try.