Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 5861
  • Last Modified:

How to apply GPO to workstations ONLY

I have created several GPOs that I want to ONLY apply to workstations, not to domain controllers or member servers.   This GPO is currently linked to the domain so it applies to all systems.  I have read numerous articles about using WMI Filters to include but none describe how to exclude a particular class of machine.

My workstations are a mix of Windows XP, Vista, and 7 and are in the default "Computers" container.  My servers are Windows Server 2003, 2008, and 2008 R2.  Servers are in a custom "Servers" OU and DCs are in the default "Domain Controllers" container.

I appreciate any guidance you can provide, thanks!
0
AltaSens
Asked:
AltaSens
3 Solutions
 
snusgubbenCommented:
The "easiest" solution would to create a "Workstation" OU, move all workstation here, and link the GPO to this OU.
0
 
snusgubbenCommented:
If you want to the GPO only added to workstations, you can create a WMI filter like:

Select * from Win32_ComputerSystem where DomainRole = 1

and add the WMI filter to the GPO. WMI filters make GPO prcessing a little slower, so you have to decide if move them to a Workstation OU is sufficient.


1
 
thomasd04Commented:
Hi AltaSens. The GPO(s) over the whole domain tree should contain general settings for all objects; and separate GPOs linked to specific OUs should be created for more specific settings. But if you want to restrict them from affecting the server OUs, you can simply block inheritance on the GPO linked to the server OUs. WMI filtering would not be needed in this case. If for some reason you REALLY want to use WMI filtering for this purpose, you would be filtering using the Win32_OperatingSystem Class (http://msdn.microsoft.com/en-us/library/aa394239(v=vs.85).aspx).

Good luck!

0
Easily Design & Build Your Next Website

Squarespace’s all-in-one platform gives you everything you need to express yourself creatively online, whether it is with a domain, website, or online store. Get started with your free trial today, and when ready, take 10% off your first purchase with offer code 'EXPERTS'.

 
DonNetwork AdministratorCommented:
"My workstations are a mix of Windows XP, Vista, and 7 and are in the default "Computers" container"


The "Computers" container is not a OU, so no group policies you create will apply to them until you add the computers to an OU.
0
 
snusgubbenCommented:
... so no group policies you create will apply to them until you add the computers to an OU

You can't link a GPO to the Computers (or Users) container, but computer objects in this contatiner will inherit GPOs linked at the domain level.
0
 
AltaSensAuthor Commented:
Ultimately, it seemed easier to simply create an OU for all domain workstations and move the computer objects there.

However, I do appreciate the other two suggestions regarding WMI.

Thank you to everyone!
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Get 10% Off Your First Squarespace Website

Ready to showcase your work, publish content or promote your business online? With Squarespace’s award-winning templates and 24/7 customer service, getting started is simple. Head to Squarespace.com and use offer code ‘EXPERTS’ to get 10% off your first purchase.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now