• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 5493
  • Last Modified:

How to apply GPO to workstations ONLY

I have created several GPOs that I want to ONLY apply to workstations, not to domain controllers or member servers.   This GPO is currently linked to the domain so it applies to all systems.  I have read numerous articles about using WMI Filters to include but none describe how to exclude a particular class of machine.

My workstations are a mix of Windows XP, Vista, and 7 and are in the default "Computers" container.  My servers are Windows Server 2003, 2008, and 2008 R2.  Servers are in a custom "Servers" OU and DCs are in the default "Domain Controllers" container.

I appreciate any guidance you can provide, thanks!
0
AltaSens
Asked:
AltaSens
3 Solutions
 
snusgubbenCommented:
The "easiest" solution would to create a "Workstation" OU, move all workstation here, and link the GPO to this OU.
0
 
snusgubbenCommented:
If you want to the GPO only added to workstations, you can create a WMI filter like:

Select * from Win32_ComputerSystem where DomainRole = 1

and add the WMI filter to the GPO. WMI filters make GPO prcessing a little slower, so you have to decide if move them to a Workstation OU is sufficient.


1
 
thomasd04Commented:
Hi AltaSens. The GPO(s) over the whole domain tree should contain general settings for all objects; and separate GPOs linked to specific OUs should be created for more specific settings. But if you want to restrict them from affecting the server OUs, you can simply block inheritance on the GPO linked to the server OUs. WMI filtering would not be needed in this case. If for some reason you REALLY want to use WMI filtering for this purpose, you would be filtering using the Win32_OperatingSystem Class (http://msdn.microsoft.com/en-us/library/aa394239(v=vs.85).aspx).

Good luck!

0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
Donald StewartNetwork AdministratorCommented:
"My workstations are a mix of Windows XP, Vista, and 7 and are in the default "Computers" container"


The "Computers" container is not a OU, so no group policies you create will apply to them until you add the computers to an OU.
0
 
snusgubbenCommented:
... so no group policies you create will apply to them until you add the computers to an OU

You can't link a GPO to the Computers (or Users) container, but computer objects in this contatiner will inherit GPOs linked at the domain level.
0
 
AltaSensAuthor Commented:
Ultimately, it seemed easier to simply create an OU for all domain workstations and move the computer objects there.

However, I do appreciate the other two suggestions regarding WMI.

Thank you to everyone!
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now