?
Solved

Group Policy WMI Filter for User Field Value

Posted on 2011-02-14
4
Medium Priority
?
1,192 Views
Last Modified: 2012-05-11
I need to filter a Group Policy that denies local logon to a specific group of users because there are certain users that must be in that group which I do not want the policy to be enforced upon.  The one variable that differentiates between the users is the "Company" field under the "Organization" tab in the A.D. profiles.  The ones that I want the policy to be enforced upon MUST have "Student" in that field.  Anything else results in the policy being ignored.  I know how to pull that field through a full-blown script, but WMI Filters can't be a full script.  They have to be a direct output of a WMI Class's values.  Please help.  Thank you in advance.
0
Comment
Question by:Infinetwork
  • 2
  • 2
4 Comments
 
LVL 3

Expert Comment

by:laughelemental
ID: 34889714
Hello

You do not need any WMI filterto do that. It's achieved via Group Policy security settings/ Make desired permissions to apply that GP only to specific user (or computer) group
see http://www.windowsnetworking.com/articles_tutorials/Group-Policy-Security-Filtering.html
0
 

Author Comment

by:Infinetwork
ID: 34889810
There are too many users to add them individually, since you can't add the ones NOT to apply the policy to (you can only list who you DO want it applied to). And, as I said, there are users in the group that I don't want the policy applied to (so, I can't apply it to the group). Also, just so you know, this is an auto-generated group, so making a new group through the system that created this group would not be an option as I would run into the same problem at some point all over again. One more thing: manually moving around users/groups is not an option as the groups would be in constant change and it would be too much overhead. That's why it needs to be a WMI filter - so that it only let's the policy work when certain criteria is met.
0
 
LVL 3

Accepted Solution

by:
laughelemental earned 1500 total points
ID: 34889988
since you can't add the ones NOT to apply the policy to (you can only list who you DO want it applied to)

you CAN do that by setting DENY flag in security.
0
 

Author Closing Comment

by:Infinetwork
ID: 34890120
Thanks.  Sometimes I forget the obvious and basic answers.
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Here's a look at newsworthy articles and community happenings during the last month.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question