Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Group Policy WMI Filter for User Field Value

Posted on 2011-02-14
4
Medium Priority
?
1,191 Views
Last Modified: 2012-05-11
I need to filter a Group Policy that denies local logon to a specific group of users because there are certain users that must be in that group which I do not want the policy to be enforced upon.  The one variable that differentiates between the users is the "Company" field under the "Organization" tab in the A.D. profiles.  The ones that I want the policy to be enforced upon MUST have "Student" in that field.  Anything else results in the policy being ignored.  I know how to pull that field through a full-blown script, but WMI Filters can't be a full script.  They have to be a direct output of a WMI Class's values.  Please help.  Thank you in advance.
0
Comment
Question by:Infinetwork
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 3

Expert Comment

by:laughelemental
ID: 34889714
Hello

You do not need any WMI filterto do that. It's achieved via Group Policy security settings/ Make desired permissions to apply that GP only to specific user (or computer) group
see http://www.windowsnetworking.com/articles_tutorials/Group-Policy-Security-Filtering.html
0
 

Author Comment

by:Infinetwork
ID: 34889810
There are too many users to add them individually, since you can't add the ones NOT to apply the policy to (you can only list who you DO want it applied to). And, as I said, there are users in the group that I don't want the policy applied to (so, I can't apply it to the group). Also, just so you know, this is an auto-generated group, so making a new group through the system that created this group would not be an option as I would run into the same problem at some point all over again. One more thing: manually moving around users/groups is not an option as the groups would be in constant change and it would be too much overhead. That's why it needs to be a WMI filter - so that it only let's the policy work when certain criteria is met.
0
 
LVL 3

Accepted Solution

by:
laughelemental earned 1500 total points
ID: 34889988
since you can't add the ones NOT to apply the policy to (you can only list who you DO want it applied to)

you CAN do that by setting DENY flag in security.
0
 

Author Closing Comment

by:Infinetwork
ID: 34890120
Thanks.  Sometimes I forget the obvious and basic answers.
0

Featured Post

Enroll in October's Free Course of the Month

Do you work with and analyze data? Enroll in October's Course of the Month for 7+ hours of SQL training, allowing you to quickly and efficiently store or retrieve data. It's free for Premium Members, Team Accounts, and Qualified Experts!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question