Solved

Group Policy WMI Filter for User Field Value

Posted on 2011-02-14
4
1,176 Views
Last Modified: 2012-05-11
I need to filter a Group Policy that denies local logon to a specific group of users because there are certain users that must be in that group which I do not want the policy to be enforced upon.  The one variable that differentiates between the users is the "Company" field under the "Organization" tab in the A.D. profiles.  The ones that I want the policy to be enforced upon MUST have "Student" in that field.  Anything else results in the policy being ignored.  I know how to pull that field through a full-blown script, but WMI Filters can't be a full script.  They have to be a direct output of a WMI Class's values.  Please help.  Thank you in advance.
0
Comment
Question by:Infinetwork
  • 2
  • 2
4 Comments
 
LVL 3

Expert Comment

by:laughelemental
ID: 34889714
Hello

You do not need any WMI filterto do that. It's achieved via Group Policy security settings/ Make desired permissions to apply that GP only to specific user (or computer) group
see http://www.windowsnetworking.com/articles_tutorials/Group-Policy-Security-Filtering.html
0
 

Author Comment

by:Infinetwork
ID: 34889810
There are too many users to add them individually, since you can't add the ones NOT to apply the policy to (you can only list who you DO want it applied to). And, as I said, there are users in the group that I don't want the policy applied to (so, I can't apply it to the group). Also, just so you know, this is an auto-generated group, so making a new group through the system that created this group would not be an option as I would run into the same problem at some point all over again. One more thing: manually moving around users/groups is not an option as the groups would be in constant change and it would be too much overhead. That's why it needs to be a WMI filter - so that it only let's the policy work when certain criteria is met.
0
 
LVL 3

Accepted Solution

by:
laughelemental earned 500 total points
ID: 34889988
since you can't add the ones NOT to apply the policy to (you can only list who you DO want it applied to)

you CAN do that by setting DENY flag in security.
0
 

Author Closing Comment

by:Infinetwork
ID: 34890120
Thanks.  Sometimes I forget the obvious and basic answers.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Installing a printer using group policy preferences is not that hard let’s take a look at it. First lets open up your group policy console and edit the policy you want to add it to. I recommend creating a new policy for each printer makes it a l…
Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now