I have an existing AD Structure with GPOs at the root domain. I am enforcing a new Password Policy on Friday and I'd like to know the best way to launch to my users. All users except admins and specific universal user accounts will not need this GPO applied to them.
Group Policy Management is setup by Domain, Location OUs with Department OUs underneath. The specific Universal accounts that I do not want this new GPO to be apply to are listed in almost each location OU and then under department OU, so I'm not sure what the best way to deny these user accounts the new GPO. These users are not in a single Group their user account is located within the OU.